WO02065697A2

Apparatus and method for authenticating access to a network resource

Abstract

A device (101) for providing access to a remote site (105) is disclosed. Access to the device is gained through an authentication process during which a user password and biometrics (310) are provided to the device. The device also includes a security feature such that only authorized users of the specific device can gain access to it. Once authenticated (502), the device authorizes access to a remote site (e.g., a web site or a server on a local area network). The communications from the device to the remote site is encrypted and further the hand-held device uses a computer generated password to gain access to the site. In this way, user generated passwords, which are typically simple and infrequently changed, are avoided in favor of a more complex and frequently changed computer generated passwords for site access. A device for providing access to a remote site is disclosed. Access to the device is gained through an authentication process during which a user password and biometrics are provided to the device. The device also includes a security feature such that only authorized users of the specific device can gain access to it. Once authenticated, the device authorizes access to a remote site (e.g., a web site or a server on a local area network). The communications from the device to the remote site is encrypted and further the hand-held device uses a computer generated password to gain access to the site. In this way, user generated passwords, which are typically simple and infrequently changed, are avoided in favor of a more complex and frequently changed computer generated passwords for site access.

WO02065697A2, drawing sheet 1
Sheet 1 of 8

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

18 claims: 1 independent, 17 dependent

  1. 1
    WHAT IS CLAIMED IS :1. A device (101) for providing a user with secure access to a network resource, (105) comprising: a first module (308, 310) for authenticating a user to said device (101);a second module (314) responsive to said first module for providing the user with access to the network resource using a network resource password unknown to the user.
  2. 4
    The device of claim 4 including a duress database (406) and an accounts database (404), wherein entry of a correct duress password to authenticate to the device (101) permits user access only to network resources (105) set forth in said duress database, (406) and wherein entry of a correct user password to authenticate to the device permits access to only network resources (105) set forth in said accounts database (404).
  3. 18
    A method for authenticating a user to a device (101) for contacting a network resource (105), said method comprising the steps of:(a) a user providing a user password;(606) (b) a user providing biometrics;(604) (c) determining if the user password and the user biometrics match the password and the biometrics of an authorized user;(605 & 607) (d) retrieving from device memory a randomly generated password for the network resource;(702, 704) and (e) transmitting the randomly generated password to the network resource to gain access thereto. (705) 19. The method of claim 45 further comprising a step (f6) on a predetermined schedule, changing the randomly generated password for the network resource. (706) 20. A method for authenticating to a device (101) for accessing a network resource (105), wherein certain operational code or data of the device (101) is stored in encrypted form, and wherein the device includes a device dependent key (414), said method comprising the steps of: (a) a user providing a user password;(606) (b) a user providing biometrics;(604) (c) determining if the user password and the user biometrics match the password and the biometrics of an authorized user;(605 & 607) (d) using the device dependent key, decrypting the certain operational code or data stored in encrypted form;(e) retrieving from the device memory the randomly generated password etwork resource;and (702, 704) (f) transmitting the randomly generated password to the network resource access thereto. (705)