EA201892109A1 - Способ и система для аутентификации пользователя с повышенной безопасностью - Google Patents

Способ и система для аутентификации пользователя с повышенной безопасностью

Info

Publication number
EA201892109A1
EA201892109A1 EA201892109A EA201892109A EA201892109A1 EA 201892109 A1 EA201892109 A1 EA 201892109A1 EA 201892109 A EA201892109 A EA 201892109A EA 201892109 A EA201892109 A EA 201892109A EA 201892109 A1 EA201892109 A1 EA 201892109A1
Authority
EA
Eurasian Patent Office
Prior art keywords
authentication
session
user
processing unit
authentication data
Prior art date
Application number
EA201892109A
Other languages
English (en)
Inventor
Энтони Смейлз
Original Assignee
Фортикод Лимитед
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from AU2016901019A external-priority patent/AU2016901019A0/en
Application filed by Фортикод Лимитед filed Critical Фортикод Лимитед
Publication of EA201892109A1 publication Critical patent/EA201892109A1/ru

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/34User authentication involving the use of external additional devices, e.g. dongles or smart cards
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/45Structures or tools for the administration of authentication
    • G06F21/46Structures or tools for the administration of authentication by designing passwords or checking the strength of passwords
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/606Protecting data by securing the transmission between two devices or processes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0861Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • H04L9/3228One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • H04L9/3231Biological data, e.g. fingerprint, voice or retina
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3271Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3297Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving time stamps, e.g. generation of time stamps
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/63Location-dependent; Proximity-dependent
    • H04W12/64Location-dependent; Proximity-dependent using geofenced areas
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/71Hardware identity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/72Subscriber identity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/73Access point logical identity
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2103Challenge-response
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/082Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying multi-factor authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Health & Medical Sciences (AREA)
  • Biomedical Technology (AREA)
  • Life Sciences & Earth Sciences (AREA)
  • Biodiversity & Conservation Biology (AREA)
  • Computing Systems (AREA)
  • Bioethics (AREA)
  • Telephonic Communication Services (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Collating Specific Patterns (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Computer And Data Communications (AREA)
  • Burglar Alarm Systems (AREA)
  • Information Retrieval, Db Structures And Fs Structures Therefor (AREA)

Abstract

Способ аутентификации пользователя в распределенной системе обработки начинается с приема на первом блоке (108) обработки запроса (1004) для инициирования сеанса аутентификации, причем запрос включает в себя уникальный идентификатор пользователя, требующего аутентификации. Первый блок обработки получает по меньшей мере один элемент данных (412, 1712) аутентификации, действительных в течение сеанса аутентификации. Данные аутентификации передаются (1006) на второй блок (106) обработки, который связан с оконечным устройством, эксплуатируемым пользователем. Второй блок обработки преобразует данные аутентификации с использованием алгоритма преобразования на основании одного или более зависящих от сеанса факторов (404, 1704) аутентификации для генерации преобразованных данных аутентификации, которые являются характеристикой сеанса аутентификации и пользователя. Преобразованные данные аутентификации передаются (1008) на третий блок (108) обработки, который удостоверяется, что преобразованные данные аутентификации соответствуют пользователю и заранее определенным значениям одного или более зависящих от сеанса факторов аутентификации. Третий блок обработки генерирует результат (1010) аутентификации сеанса аутентификации на основании проверки.
EA201892109A 2016-03-18 2017-03-17 Способ и система для аутентификации пользователя с повышенной безопасностью EA201892109A1 (ru)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
AU2016901019A AU2016901019A0 (en) 2016-03-18 Method and system for user authentication with improved security
PCT/AU2017/050240 WO2017156590A1 (en) 2016-03-18 2017-03-17 Method and system for user authentication with improved security

Publications (1)

Publication Number Publication Date
EA201892109A1 true EA201892109A1 (ru) 2019-02-28

Family

ID=59850010

Family Applications (1)

Application Number Title Priority Date Filing Date
EA201892109A EA201892109A1 (ru) 2016-03-18 2017-03-17 Способ и система для аутентификации пользователя с повышенной безопасностью

Country Status (16)

Country Link
US (2) US11017067B2 (ru)
EP (1) EP3430554A4 (ru)
JP (1) JP2019512961A (ru)
KR (1) KR20180117715A (ru)
CN (1) CN109074437A (ru)
AU (1) AU2017233545A1 (ru)
BR (1) BR112018068884A2 (ru)
CA (1) CA3017533A1 (ru)
EA (1) EA201892109A1 (ru)
HK (1) HK1258980A1 (ru)
IL (1) IL261810B2 (ru)
MA (1) MA45323A (ru)
PH (1) PH12018501983A1 (ru)
SG (1) SG11201807995TA (ru)
WO (1) WO2017156590A1 (ru)
ZA (1) ZA201806243B (ru)

Families Citing this family (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2565282B (en) * 2017-08-02 2021-12-22 Vnc Automotive Ltd Remote control of a computing device
US10834170B2 (en) * 2018-03-19 2020-11-10 Citrix Systems, Inc. Cloud authenticated offline file sharing
US10693648B2 (en) * 2018-03-26 2020-06-23 Ca, Inc. System and method for dynamic grid authentication
US10999081B2 (en) * 2018-04-12 2021-05-04 Microsoft Technology Licensing, Llc Dynamic certificate management for a distributed authentication system
CN108833117B (zh) * 2018-07-25 2020-11-10 海南新软软件有限公司 一种私钥存储和读取方法、装置及硬件设备
US11134084B1 (en) * 2018-08-22 2021-09-28 Hid Global Corporation Diversified authentication and access control
US11336430B2 (en) * 2018-09-07 2022-05-17 Sap Se Blockchain-incorporating distributed authentication system
US11582608B2 (en) 2018-11-09 2023-02-14 Carrier Corporation Geographically secure access to container controller
CN111865870B (zh) * 2019-04-24 2022-01-11 华为技术有限公司 一种参数发送方法及装置
KR102259764B1 (ko) * 2019-09-06 2021-06-02 주식회사 엘핀 멀티팩터 인증 수행 장치 및 그 동작 방법
CN114503105A (zh) * 2019-09-25 2022-05-13 联邦科学和工业研究组织 用于浏览器应用的密码服务
US11146954B2 (en) 2019-10-08 2021-10-12 The Toronto-Dominion Bank System and method for establishing a trusted session
US11722312B2 (en) * 2020-03-09 2023-08-08 Sony Group Corporation Privacy-preserving signature
CN112615834B (zh) * 2020-12-08 2023-04-07 北京北信源软件股份有限公司 一种安全认证方法及系统
CN112579566B (zh) * 2020-12-14 2023-03-31 浪潮云信息技术股份公司 分布式id的生成方法及装置
US11539689B2 (en) 2021-01-19 2022-12-27 Visa International Service Association System, method, and apparatus for authenticating a user device
CN113014386B (zh) * 2021-03-30 2023-06-02 宋煜 基于多方协同计算的密码系统
GB2622177A (en) * 2021-08-10 2024-03-06 Keyless Tech Srl Authentication processing services for generating high-entropy cryptographic keys
US20240005312A1 (en) * 2022-07-01 2024-01-04 Bank Of America Corporation Multi-Factor User Authentication Using Blockchain Tokens
WO2024108281A1 (pt) * 2022-11-25 2024-05-30 Clovis Golfetto Sistema e método para autenticação única de usuário
KR20240132642A (ko) * 2023-02-27 2024-09-04 삼성전자주식회사 생체 정보를 암호화하는 전자 장치 및 그 동작 방법

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3053527B2 (ja) * 1993-07-30 2000-06-19 インターナショナル・ビジネス・マシーンズ・コーポレイション パスワードを有効化する方法及び装置、パスワードを生成し且つ予備的に有効化する方法及び装置、認証コードを使用して資源のアクセスを制御する方法及び装置
US9768963B2 (en) * 2005-12-09 2017-09-19 Citicorp Credit Services, Inc. (Usa) Methods and systems for secure user authentication
WO2012014231A1 (en) * 2010-07-29 2012-02-02 Nirmal Juthani System and method for generating a strong multi factor personalized server key from a simple user password
US8869255B2 (en) * 2010-11-30 2014-10-21 Forticom Group Ltd Method and system for abstracted and randomized one-time use passwords for transactional authentication
EP2885904B1 (en) * 2012-08-03 2018-04-25 Vasco Data Security International GmbH User-convenient authentication method and apparatus using a mobile authentication application
US9398050B2 (en) * 2013-02-01 2016-07-19 Vidder, Inc. Dynamically configured connection to a trust broker
CN104517094A (zh) * 2013-09-30 2015-04-15 阿里巴巴集团控股有限公司 一种身份验证方法和身份验证装置
US9949115B2 (en) * 2014-06-10 2018-04-17 Qualcomm Incorporated Common modulus RSA key pairs for signature generation and encryption/decryption

Also Published As

Publication number Publication date
IL261810A (en) 2018-10-31
BR112018068884A2 (pt) 2019-01-22
US20190034612A1 (en) 2019-01-31
HK1258980A1 (zh) 2019-11-22
US20210264010A1 (en) 2021-08-26
US11017067B2 (en) 2021-05-25
CA3017533A1 (en) 2017-09-21
AU2017233545A1 (en) 2018-10-04
MA45323A (fr) 2019-01-23
EP3430554A4 (en) 2019-09-04
WO2017156590A1 (en) 2017-09-21
SG11201807995TA (en) 2018-10-30
EP3430554A1 (en) 2019-01-23
ZA201806243B (en) 2019-07-31
IL261810B2 (en) 2023-06-01
PH12018501983A1 (en) 2019-07-01
KR20180117715A (ko) 2018-10-29
JP2019512961A (ja) 2019-05-16
CN109074437A (zh) 2018-12-21

Similar Documents

Publication Publication Date Title
EA201892109A1 (ru) Способ и система для аутентификации пользователя с повышенной безопасностью
PH12019501715A1 (en) Digital certificate management method and apparatus, and electronic device
GB2579976A8 (en) Identity verification using biometric data and non-invertible functions via blockchain
MX2018002190A (es) SISTEMA Y Mí‰TODO PARA ESTíNDARES DE PROTOCOLO BIOMí‰TRICO.
EA201790385A1 (ru) Способ цифровой подписи электронного файла и способ аутентификации
GB2573666A (en) Verifying authenticity of computer readable information using the blockchain
MX2019012571A (es) Sistemas y metodos para verificacion y autenticacion de dispositivos.
MX356039B (es) Sistema y metodo para autorizar el acceso a ambientes de acceso controlado.
EP4343591A3 (en) Authentication system using secure multi-party computation
GB2552435A (en) Screen-analysis based device security
EE201800028A (et) Plokiahelal põhinev isikusarnasuse mitmikkontrolli süsteem ja meetod
MX2017014141A (es) Dispositivos y metodos para autenticacion de dispositivos de cliente.
MX2016014461A (es) Aprovisionamiento de licencias de gestion de derechos digitales (drm) en un dispositivo cliente que utiliza un servidor de actualizaciones.
GB201213279D0 (en) Identity generation mechanism
MX2018007332A (es) Metodo, dispositivo, servidor y sistema para autenticar a un usuario.
WO2016126052A3 (ko) 인증 방법 및 시스템
PH12019501168A1 (en) Service control and user identity authentication based on virtual realtiy
SG10201810422SA (en) Dual channel identity authentication
TWI347769B (en) Three way validation and authentication of boot files transmitted from server to client
IN2014MU00771A (ru)
MX2015014587A (es) Método y sistema para activar credenciales.
GB2565662A (en) Method and system for authenticating a session on a communication device
GB2598669A8 (en) Server-based setup for connecting a device to a local area network
PH12016501866B1 (en) Systems and methods for identity validation and verification
GB2549631A (en) Method and apparatus for enabling a single sign-on enabled application to enforce an application lock