WO2008024362A3 - Procédés d'authentification avancée à multiples facteurs - Google Patents

Procédés d'authentification avancée à multiples facteurs Download PDF

Info

Publication number
WO2008024362A3
WO2008024362A3 PCT/US2007/018506 US2007018506W WO2008024362A3 WO 2008024362 A3 WO2008024362 A3 WO 2008024362A3 US 2007018506 W US2007018506 W US 2007018506W WO 2008024362 A3 WO2008024362 A3 WO 2008024362A3
Authority
WO
WIPO (PCT)
Prior art keywords
identifier
codebook
user
keystone
image challenge
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2007/018506
Other languages
English (en)
Other versions
WO2008024362A9 (fr
WO2008024362A2 (fr
Inventor
Richard Love
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
AcuPrint Inc
Original Assignee
AcuPrint Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by AcuPrint Inc filed Critical AcuPrint Inc
Publication of WO2008024362A2 publication Critical patent/WO2008024362A2/fr
Publication of WO2008024362A9 publication Critical patent/WO2008024362A9/fr
Publication of WO2008024362A3 publication Critical patent/WO2008024362A3/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1483Countermeasures against malicious traffic service impersonation, e.g. phishing, pharming or web spoofing
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce
    • G06Q30/06Buying, selling or leasing transactions
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q40/00Finance; Insurance; Tax strategies; Processing of corporate or income taxes
    • G06Q40/02Banking, e.g. interest calculation or account maintenance
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • H04L9/3228One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3271Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0861Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Business, Economics & Management (AREA)
  • Finance (AREA)
  • Accounting & Taxation (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Development Economics (AREA)
  • Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Computer Hardware Design (AREA)
  • Economics (AREA)
  • Marketing (AREA)
  • Strategic Management (AREA)
  • General Engineering & Computer Science (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Technology Law (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Facsimiles In General (AREA)
  • User Interface Of Digital Computer (AREA)

Abstract

L'invention concerne des procédés, un logiciel et des systèmes pour authentifier des sites électroniquement accessibles. En général, le développement met en jeu l'interrogation d'un utilisateur identifié, connecté à un site de vendeur tiers électroniquement accessible (par exemple, un site Internet) pour un identifiant de livre de code qui correspond à un livre de code doté d'une pluralité d'unités d'identification, dont chacune comporte un premier identifiant, un second identifiant et un identifiant de clé de voûte. Après réception de l'identifiant de livre de code, l'utilisateur est interrogé au moyen d'un procédé d'identification d'image variable composé de la clé de voûte et du premier identifiant pour au moins une unité d'identification dans le livre de code ; puis, l'utilisateur est invité à entrer le second identifiant pour chaque unité d'identification affichée dans le procédé d'identification d'image pour former un mot de passe à un seul usage. Après l'entrée d'un mot de passe qui correspond au procédé d'identification d'image, l'authenticité de l'utilisateur est confirmée au site de vendeur.
PCT/US2007/018506 2006-08-23 2007-08-21 Procédés d'authentification avancée à multiples facteurs Ceased WO2008024362A2 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US83996506P 2006-08-23 2006-08-23
US60/839,965 2006-08-23

Publications (3)

Publication Number Publication Date
WO2008024362A2 WO2008024362A2 (fr) 2008-02-28
WO2008024362A9 WO2008024362A9 (fr) 2008-04-17
WO2008024362A3 true WO2008024362A3 (fr) 2008-06-19

Family

ID=39107362

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2007/018506 Ceased WO2008024362A2 (fr) 2006-08-23 2007-08-21 Procédés d'authentification avancée à multiples facteurs

Country Status (1)

Country Link
WO (1) WO2008024362A2 (fr)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9589298B2 (en) 2013-02-21 2017-03-07 Yodlee, Inc. Financial account authentication
CN107147675A (zh) * 2017-06-25 2017-09-08 深圳市成星自动化系统有限公司 基于特征码的身份验证方法和系统
US11310217B2 (en) 2018-09-07 2022-04-19 Paypal, Inc. Using ephemeral URL passwords to deter high-volume attacks
US11080385B1 (en) * 2018-09-24 2021-08-03 NortonLifeLock Inc. Systems and methods for enabling multi-factor authentication for seamless website logins

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030014360A1 (en) * 2000-02-09 2003-01-16 David Arditti Service activation by virtual prepaid card
US20030191947A1 (en) * 2003-04-30 2003-10-09 Microsoft Corporation System and method of inkblot authentication
US6931538B1 (en) * 1999-09-24 2005-08-16 Takashi Sawaguchi Portable personal authentication apparatus and electronic system to which access is permitted by the same

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6931538B1 (en) * 1999-09-24 2005-08-16 Takashi Sawaguchi Portable personal authentication apparatus and electronic system to which access is permitted by the same
US20030014360A1 (en) * 2000-02-09 2003-01-16 David Arditti Service activation by virtual prepaid card
US20030191947A1 (en) * 2003-04-30 2003-10-09 Microsoft Corporation System and method of inkblot authentication

Also Published As

Publication number Publication date
WO2008024362A9 (fr) 2008-04-17
WO2008024362A2 (fr) 2008-02-28

Similar Documents

Publication Publication Date Title
WO2009112693A3 (fr) Procede d'authentification et de signature d'un utilisateur aupres d'un service applicatif, utilisant un telephone mobile comme second facteur en complement et independamment d'un premier facteur
JP2009500913A5 (fr)
WO2008127430A3 (fr) Accès sécurisé à une ressource restreinte
WO2006096862A3 (fr) Systemes de verification electroniques
WO2017160660A3 (fr) Cryptogramme de validation pour interaction
WO2009031056A3 (fr) Fourniture de services à un dispositif invité dans un réseau personnel
WO2009102915A3 (fr) Systèmes et procédés de manipulation sécurisée de séquences d’authentification
EP2456121A3 (fr) IEnregistrement de fonctions physiques non clonable mettant en oeuvre un procédé de challenge-response
WO2009031159A3 (fr) Procédé et système pour authentification sécurisée
MY149495A (en) Authenticating an application
WO2007121190A3 (fr) procédé et appareil pour lier des authentifications multiples
TW200723145A (en) Prescription authentication
TW200635319A (en) User authentication system
WO2009158086A3 (fr) Techniques permettant d'assurer une authentification et une intégrité de communications
WO2014138430A3 (fr) Inscription simple sécurisée
TWI347769B (en) Three way validation and authentication of boot files transmitted from server to client
WO2008064013A3 (fr) Options d'authentification adaptative
WO2006050152A3 (fr) Authentification d'identite terminal collaborative securisee entre un dispositif de communication sans fil et un operateur sans fil
WO2011106769A3 (fr) Liaison dynamique et cryptographique d'identité entre un abonné et un périphérique pour la mobilité de l'abonné
EP2355447A3 (fr) Mécanisme sécurisé et automatique de transfert d'informations d'authentification
WO2010060704A3 (fr) Authentification d’un canal de communication secondaire à base de jeton de client à serveur à travers des canaux de communication principaux authentifiés
WO2007092080A3 (fr) Authentification d'équipement de fournisseur de réseau mobile
WO2006093561A3 (fr) Methode et systeme de communications securisees par logiciel
WO2008126460A1 (fr) Procédé d'authentification de données électroniques, programme d'authentification de données électroniques, et système d'authentification de données électroniques
WO2009118502A3 (fr) Authentification déléguée

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 07837163

Country of ref document: EP

Kind code of ref document: A2

DPE1 Request for preliminary examination filed after expiration of 19th month from priority date (pct application filed from 20040101)
NENP Non-entry into the national phase

Ref country code: DE

NENP Non-entry into the national phase

Ref country code: RU

122 Ep: pct application non-entry in european phase

Ref document number: 07837163

Country of ref document: EP

Kind code of ref document: A2

DPE1 Request for preliminary examination filed after expiration of 19th month from priority date (pct application filed from 20040101)