WO2008024362A3 - Procédés d'authentification avancée à multiples facteurs - Google Patents
Procédés d'authentification avancée à multiples facteurs Download PDFInfo
- Publication number
- WO2008024362A3 WO2008024362A3 PCT/US2007/018506 US2007018506W WO2008024362A3 WO 2008024362 A3 WO2008024362 A3 WO 2008024362A3 US 2007018506 W US2007018506 W US 2007018506W WO 2008024362 A3 WO2008024362 A3 WO 2008024362A3
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- identifier
- codebook
- user
- keystone
- image challenge
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1483—Countermeasures against malicious traffic service impersonation, e.g. phishing, pharming or web spoofing
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q30/00—Commerce
- G06Q30/06—Buying, selling or leasing transactions
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q40/00—Finance; Insurance; Tax strategies; Processing of corporate or income taxes
- G06Q40/02—Banking, e.g. interest calculation or account maintenance
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
- H04L9/3228—One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3271—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0861—Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Business, Economics & Management (AREA)
- Finance (AREA)
- Accounting & Taxation (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Development Economics (AREA)
- Physics & Mathematics (AREA)
- Computing Systems (AREA)
- Computer Hardware Design (AREA)
- Economics (AREA)
- Marketing (AREA)
- Strategic Management (AREA)
- General Engineering & Computer Science (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Technology Law (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
- Facsimiles In General (AREA)
- User Interface Of Digital Computer (AREA)
Abstract
L'invention concerne des procédés, un logiciel et des systèmes pour authentifier des sites électroniquement accessibles. En général, le développement met en jeu l'interrogation d'un utilisateur identifié, connecté à un site de vendeur tiers électroniquement accessible (par exemple, un site Internet) pour un identifiant de livre de code qui correspond à un livre de code doté d'une pluralité d'unités d'identification, dont chacune comporte un premier identifiant, un second identifiant et un identifiant de clé de voûte. Après réception de l'identifiant de livre de code, l'utilisateur est interrogé au moyen d'un procédé d'identification d'image variable composé de la clé de voûte et du premier identifiant pour au moins une unité d'identification dans le livre de code ; puis, l'utilisateur est invité à entrer le second identifiant pour chaque unité d'identification affichée dans le procédé d'identification d'image pour former un mot de passe à un seul usage. Après l'entrée d'un mot de passe qui correspond au procédé d'identification d'image, l'authenticité de l'utilisateur est confirmée au site de vendeur.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US83996506P | 2006-08-23 | 2006-08-23 | |
| US60/839,965 | 2006-08-23 |
Publications (3)
| Publication Number | Publication Date |
|---|---|
| WO2008024362A2 WO2008024362A2 (fr) | 2008-02-28 |
| WO2008024362A9 WO2008024362A9 (fr) | 2008-04-17 |
| WO2008024362A3 true WO2008024362A3 (fr) | 2008-06-19 |
Family
ID=39107362
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2007/018506 Ceased WO2008024362A2 (fr) | 2006-08-23 | 2007-08-21 | Procédés d'authentification avancée à multiples facteurs |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2008024362A2 (fr) |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9589298B2 (en) | 2013-02-21 | 2017-03-07 | Yodlee, Inc. | Financial account authentication |
| CN107147675A (zh) * | 2017-06-25 | 2017-09-08 | 深圳市成星自动化系统有限公司 | 基于特征码的身份验证方法和系统 |
| US11310217B2 (en) | 2018-09-07 | 2022-04-19 | Paypal, Inc. | Using ephemeral URL passwords to deter high-volume attacks |
| US11080385B1 (en) * | 2018-09-24 | 2021-08-03 | NortonLifeLock Inc. | Systems and methods for enabling multi-factor authentication for seamless website logins |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20030014360A1 (en) * | 2000-02-09 | 2003-01-16 | David Arditti | Service activation by virtual prepaid card |
| US20030191947A1 (en) * | 2003-04-30 | 2003-10-09 | Microsoft Corporation | System and method of inkblot authentication |
| US6931538B1 (en) * | 1999-09-24 | 2005-08-16 | Takashi Sawaguchi | Portable personal authentication apparatus and electronic system to which access is permitted by the same |
-
2007
- 2007-08-21 WO PCT/US2007/018506 patent/WO2008024362A2/fr not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6931538B1 (en) * | 1999-09-24 | 2005-08-16 | Takashi Sawaguchi | Portable personal authentication apparatus and electronic system to which access is permitted by the same |
| US20030014360A1 (en) * | 2000-02-09 | 2003-01-16 | David Arditti | Service activation by virtual prepaid card |
| US20030191947A1 (en) * | 2003-04-30 | 2003-10-09 | Microsoft Corporation | System and method of inkblot authentication |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2008024362A9 (fr) | 2008-04-17 |
| WO2008024362A2 (fr) | 2008-02-28 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2009112693A3 (fr) | Procede d'authentification et de signature d'un utilisateur aupres d'un service applicatif, utilisant un telephone mobile comme second facteur en complement et independamment d'un premier facteur | |
| JP2009500913A5 (fr) | ||
| WO2008127430A3 (fr) | Accès sécurisé à une ressource restreinte | |
| WO2006096862A3 (fr) | Systemes de verification electroniques | |
| WO2017160660A3 (fr) | Cryptogramme de validation pour interaction | |
| WO2009031056A3 (fr) | Fourniture de services à un dispositif invité dans un réseau personnel | |
| WO2009102915A3 (fr) | Systèmes et procédés de manipulation sécurisée de séquences d’authentification | |
| EP2456121A3 (fr) | IEnregistrement de fonctions physiques non clonable mettant en oeuvre un procédé de challenge-response | |
| WO2009031159A3 (fr) | Procédé et système pour authentification sécurisée | |
| MY149495A (en) | Authenticating an application | |
| WO2007121190A3 (fr) | procédé et appareil pour lier des authentifications multiples | |
| TW200723145A (en) | Prescription authentication | |
| TW200635319A (en) | User authentication system | |
| WO2009158086A3 (fr) | Techniques permettant d'assurer une authentification et une intégrité de communications | |
| WO2014138430A3 (fr) | Inscription simple sécurisée | |
| TWI347769B (en) | Three way validation and authentication of boot files transmitted from server to client | |
| WO2008064013A3 (fr) | Options d'authentification adaptative | |
| WO2006050152A3 (fr) | Authentification d'identite terminal collaborative securisee entre un dispositif de communication sans fil et un operateur sans fil | |
| WO2011106769A3 (fr) | Liaison dynamique et cryptographique d'identité entre un abonné et un périphérique pour la mobilité de l'abonné | |
| EP2355447A3 (fr) | Mécanisme sécurisé et automatique de transfert d'informations d'authentification | |
| WO2010060704A3 (fr) | Authentification d’un canal de communication secondaire à base de jeton de client à serveur à travers des canaux de communication principaux authentifiés | |
| WO2007092080A3 (fr) | Authentification d'équipement de fournisseur de réseau mobile | |
| WO2006093561A3 (fr) | Methode et systeme de communications securisees par logiciel | |
| WO2008126460A1 (fr) | Procédé d'authentification de données électroniques, programme d'authentification de données électroniques, et système d'authentification de données électroniques | |
| WO2009118502A3 (fr) | Authentification déléguée |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 07837163 Country of ref document: EP Kind code of ref document: A2 |
|
| DPE1 | Request for preliminary examination filed after expiration of 19th month from priority date (pct application filed from 20040101) | ||
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| NENP | Non-entry into the national phase |
Ref country code: RU |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 07837163 Country of ref document: EP Kind code of ref document: A2 |
|
| DPE1 | Request for preliminary examination filed after expiration of 19th month from priority date (pct application filed from 20040101) |