System and method for authentication in a client-server connection using challenge applied to a secret key
A method for managing an authentication includes establishing, by a server device, a secured network channel with a client, providing, via the secured network channel, a private key to the client, after the providing, obtaining, from the client, a request for establishing a session with the client via a second network channel, in response to the request: sending a challenge request to the client, obtaining a challenge response associated with the challenge request, wherein the challenge response specifies a first challenge answer, performing a challenge processing using a private key to generate a second challenge answer, making a determination, using the first challenge answer and the second challenge answer, that the client is authenticated, and based on the determination, initiating the session with the client.
1 . A method for managing an authentication, the method comprising:
establishing, by a server device, a secured network channel with a client;
providing, via the secured network channel, a private key to the client;
after the providing, obtaining, from the client, a request for establishing a session with the client via a second network channel;
in response to the request:
sending a challenge request to the client, wherein the challenge request specifies a question to be answered,
wherein the question is associated with a month of a date, and
wherein the date corresponds to a point in time in which the request is obtained;
obtaining a challenge response associated with the challenge request,
wherein the challenge response specifies a first challenge answer,
wherein the first challenge answer is generated by applying a function using both an answer to the question and the private key, and
wherein the function is an addition of values associated with the secret key and the first challenge answer;
performing a challenge processing using the private key to generate a second challenge answer;
making a determination, using the first challenge answer and the second challenge answer, that the client is authenticated; and
based on the determination, initiating the session with the client,
wherein the session is associated with services used by the client device for a stateful application programming interface (API) for an application executing on the server device, and
wherein at least one stateful API is used to initiate the session.
2 . The method of claim 1 , wherein the secured network channel is provided via a first network, and wherein the second network channel is provided via a second network.
3 . The method of claim 1 , wherein the secured network channel and the second network channel are provided via a network.
4 . The method of claim 1 , wherein the challenge response does not comprise the private key.
5 . The method of claim 1 , further comprising:
obtaining a second request for establishing a second session;
in response to the second request:
sending a second challenge request to the client;
obtaining a second challenge response associated with the second challenge request, wherein the second challenge response specifies a third challenge answer;
performing the challenge processing using the private key to generate a fourth challenge answer;
making a second determination that the third challenge answer and the fourth challenge answer do not match;
based on the second determination, sending a third challenge request to the client;
obtaining a third challenge response associated with the third challenge request, wherein the third challenge response specifies a fifth challenge answer;
performing the challenge processing using the private key to generate a sixth challenge answer;
making a third determination that the fifth challenge answer and the sixth challenge answer do match; and
based on the third determination, initiating the second session with the client.
6 . The method of claim 1 ,
wherein the question is in a natural language,
wherein the answer is in the natural language, and
wherein the first challenge answer is an alphanumeric value that is not in the natural language.
7 . The method of claim 1 , wherein the question is associated with one answer that was determined by the user, and wherein the question has already been stored by the server.
8 . A non-transitory computer readable medium comprising computer readable program code, which when executed by a computer processor enables the computer processor to perform a method for managing an authentication, the method comprising:
establishing, by a server device, a secured network channel for communication with a client;
providing, via the secured network channel, a private key to the client;
after the providing, obtaining, from the client, a request for establishing a session with the client via a second network channel;
in response to the request:
sending a challenge request to the client, wherein the challenge request specifies a question to be answered,
wherein the question is associated with a month of a date, and
wherein the date corresponds to a point in time in which the request is obtained;
obtaining a challenge response associated with the challenge request,
wherein the challenge response specifies a first challenge answer,
wherein the first challenge answer is generated by applying a function using both an answer to the question and the private key, and
wherein the function is an addition of values associated with the secret key and the first challenge answer;
performing a challenge processing using the private key to generate a second challenge answer;
making a determination, using the first challenge answer and the second challenge answer, that the client is authenticated; and
based on the determination, initiating the session with the client,
wherein the session is associated with services used by the client device for a stateful application programming interface (API) for an application executing on the server device, and
wherein at least one stateful API is used to initiate the session.
9 . The non-transitory computer readable medium of claim 8 , wherein the secured network channel is provided via a first network, and wherein the second network channel is provided via a second network.
10 . The non-transitory computer readable medium of claim 8 , wherein the secured network channel and the second network channel are provided via a network.
11 . The non-transitory computer readable medium of claim 8 , wherein the challenge response does not comprise the private key.
12 . The non-transitory computer readable medium of claim 8 , the method further comprising:
obtaining a second request for establishing a second session;
in response to the second request:
sending a second challenge request to the client;
obtaining a second challenge response associated with the second challenge request, wherein the second challenge response specifies a third challenge answer;
performing the challenge processing using the private key to generate a fourth challenge answer;
making a second determination that the third challenge answer and the fourth challenge answer do not match;
based on the second determination, sending a third challenge request to the client;
obtaining a third challenge response associated with the third challenge request, wherein the third challenge response specifies a fifth challenge answer;
performing the challenge processing using the private key to generate a sixth challenge answer;
making a third determination that the fifth challenge answer and the sixth challenge answer do match; and
based on the third determination, initiating the second session with the client.
13 . The non-transitory computer readable medium of claim 12 , wherein the second request is obtained via a third network channel.
14 . A system for managing authentication, the system comprising:
a processor comprising circuitry;
memory comprising instructions, which when executed perform a method, the method comprising:
establishing, by a server device, a secured network channel for communication with a client;
providing, via the secured network channel, a private key to the client;
after the providing, obtaining, from the client, a request for establishing a session with the client via a second network channel;
in response to the request:
sending a challenge request to the client, wherein the challenge request specifies a question to be answered,
wherein the question is associated with a month of a date, and
wherein the date corresponds to a point in time in which the request is obtained;
obtaining a challenge response associated with the challenge request,
wherein the challenge response specifies a first challenge answer,
wherein the first challenge answer is generated by applying a function using both an answer to the question and the private key, and
wherein the function is an addition of values associated with the secret key and the first challenge answer;
performing a challenge processing using the private key to generate a second challenge answer;
making a determination, using the first challenge answer and the second challenge answer, that the client is authenticated; and
based on the determination, initiating the session with the client,
wherein the session is associated with services used by the client device for a stateful application programming interface (API) for an application executing on the server device, and
wherein at least one stateful API is used to initiate the session.
15 . The system of claim 14 , wherein the secured network channel is provided via a first network, and wherein the second network channel is provided via a second network.
16 . The system of claim 14 , wherein the secured network channel and the second network channel are provided via a network.
17 . The system of claim 14 , the method further comprising:
obtaining a second request for establishing a second session;
in response to the second request:
sending a second challenge request to the client;
obtaining a second challenge response associated with the second challenge request, wherein the second challenge response specifies a third challenge answer;
performing the challenge processing using the private key to generate a fourth challenge answer;
making a second determination that the third challenge answer and the fourth challenge answer do not match;
based on the second determination, sending a third challenge request to the client;
obtaining a third challenge response associated with the third challenge request, wherein the third challenge response specifies a fifth challenge answer;
performing the challenge processing using the private key to generate a sixth challenge answer;
making a third determination that the fifth challenge answer and the sixth challenge answer do match; and
based on the third determination, initiating the second session with the client.