IP Library Granted Patent US 7,085,931
Granted Patent B1
US 7,085,931 · App. 09/389,540 · Granted Aug 1, 2006

Virtual smart card system and method

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,085,931
App. No.
09/389,540
Granted
Aug 1, 2006
Kind
B1
Abstract

A public key authentication system and method for use in a computer system having a plurality of users. The system includes a virtual smart card server, storage connected to the virtual smart card server, and a virtual smart card agent connected to the virtual smart card server. The storage includes a plurality of virtual smart cards, wherein each virtual smart card is associated with a user and wherein each smart card includes a private key. The virtual smart card agent authenticates the user and accesses the authenticated user's virtual smart card to obtain the user's private key.

Claims (25)

1. A public key authentication system for use in a computer system having a plurality of users, the system comprising:

a virtual smart card server;

storage connected to the virtual smart card server, wherein the storage includes a plurality of virtual smart cards, wherein each virtual smart card is associated with a user and wherein each smart card includes a private key; and

a virtual smart card agent connected to the virtual smart card server, wherein the virtual smart card agent includes a user authentication interface for use by a user in entering a one-time password, wherein the virtual smart card agent authenticates the user using the one-time password and accesses the authenticated user's virtual smart card to obtain the user's private key.

2. The public key authentication system according to claim 1 , wherein the virtual smart card agent includes an interface to a smart-card-enabled application.

3. The public key authentication system according to claim 2 , wherein the virtual smart card server performs encryption in response to a remote call from the interface.

4. The public key authentication system according to claim 2 , wherein the virtual smart card server performs signing in response to a remote call from the interface.

5. The public key authentication system according to claim 2 , wherein the virtual smart card server performs key management functions in response to a remote call from the interface.

6. The public key authentication system according to claim 1 , wherein the public key authentication system further includes an authentication server connected to the virtual smart card agent and wherein the virtual smart card agent authenticates the user through interaction with the authentication server.

7. The public key authentication system according to claim 1 , wherein the public key authentication system further includes an authentication server connected to the virtual smart card server, wherein the authentication server includes means for authenticating a user using a one-time password authentication token.

8. The public key authentication system according to claim 1 , wherein the virtual smart card agent communicates with the virtual smart card server over an agent-server transport layer.

9. The public key authentication system according to claim 1 , wherein the virtual smart card agent communicates with the virtual smart card server over a secure TCP/IP session.

10. The method of claim 1 , wherein entering a one-time password includes displaying the one-time password on an authentication token.

11. A method of authenticating users, including a first user, attempting to access a computer system, the method comprising:

assigning first and second keys to each user, wherein the first and second key form a public/private key pair;

issuing a digital certificate to the first user, wherein the digital certificate is associated with the second key assigned to the first user;

entering a one-time password;

encrypting the one-time password with the first key assigned to the first user to form an encrypted one-time password;

verifying that the digital certificate issued to the first user was signed by a recognized certificate authority;

accessing, via the digital certificate, the second key assigned to the first user;

decrypting the encrypted one-time password with the second key associated with the digital certificate to recover the one-time password; and

comparing the one-time password against an expected one-time password.

12. The method according to claim 11 , wherein the first key is a private key and the second key is a public key.

13. The method according to claim 11 , wherein verifying that the digital certificate issued to the first user was signed by a recognized certificate authority includes accessing a CRL to determine if the certificate has been revoked.

14. A computer-readable medium comprising program code which executes the method of claim 11 .

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 021523 FRAME: 0713. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF PATENT SECURITY AGREEMENT. Recorded Apr 11, 2022
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 059690/0187 →
FIRST LIEN PATENT SECURITY AGREEMENT RELEASE Recorded Mar 12, 2014
From: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL AGENT
To: ALADDIN KNOWLEDGE SYSTEMS LTD
Reel/Frame 032437/0257 →
SECOND LIEN PATENT SECURITY AGREEMENT RELEASE Recorded Mar 12, 2014
From: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL AGENT
To: ALADDIN KNOWLEDGE SYSTEMS LTD
Reel/Frame 032437/0341 →
CHANGE OF NAME Recorded Feb 23, 2011
From: ALADDIN KNOWLEDGE SYSTEMS LTD.
To: SAFENET DATA SECURITY (ISRAEL) LTD.
Reel/Frame 025848/0923 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Aug 30, 2010
From: ALLADDIN KNOWLEDGE SYSTEMS LTD.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL AGENT
Reel/Frame 024900/0702 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 27, 2010
From: ALLADDIN KNOWLEDGE SYSTEMS LTD.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL AGENT
Reel/Frame 024892/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2008
From: SECURE COMPUTING CORPORATION
To: ALADDIN KNOWLEDGE SYSTEMS
Reel/Frame 021773/0050 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2008
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 021523/0713 →
SECURITY AGREEMENT Recorded Sep 14, 2006
From: SECURE COMPUTING CORPORATION; CIPHERTRUST, INC.
To: CITICORP USA, INC. AS ADMINISTRATIVE AGENT
Reel/Frame 018247/0359 →