IP Library Patent Application 10872354
Patent Application
App. No. 10/872,354

Method and apparatus for authenticating to a remote server

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
10/872,354
Abstract

A method and apparatus for authenticating a user is disclosed. The method uses a portable I/O device to display a challenge from a kiosk or other multi-user computer and to enter a response to the challenge and transmit that response to the multi-user computer. The portable I/O device interfaces with a hardware security device, which generates the response using data securely stored in therein.

Claims (96)

1 . A method of authenticating a user to a remote computer via a client computer, comprising the steps of:

transmitting an authentication request from the client computer to the remote computer;

generating a challenge from the authentication request;

transmitting the challenge from the remote computer to the client computer;

providing the challenge to an input/output (I/O) device communicatively coupled to a hardware security device (HSD);

transmitting the challenge from the I/O device to the HSD;

generating a response to the challenge using the challenge and data selected from the group comprising a shared secret and a private key, wherein the response is generated in the HSD;

providing the response to the client computer;

transmitting the response from the client computer to the remote computer; and

granting access if the response compares favorably with an expected response computed by the remote computer from the challenge.

2 . The method of claim 1 , wherein the I/O device comprises a personal data assistant (PDA).

3 . The method of claim 1 , wherein the challenge is provided from the client computer to the I/O device and the response is provided from the I/O device to the client computer via an interface selected from the group comprising serial interface, a parallel interface, an IR interface, and an RF interface.

4 . The method of claim 1 , wherein:

the step of providing the challenge to the I/O device comprises the steps of:

displaying the challenge on a display communicatively coupled to the client computer; and

entering the challenge into the I/O device;

the step of providing the response to the client computer comprises the steps of

displaying the response on the I/O device;

accepting entry of the response in a keyboard communicatively coupled to the client computer.

5 . The method of claim 1 , further comprising the step of:

before generating the response to the challenge using the data, accepting a user-entered personal identification number (PIN) in the HSD, and verifying the user-entered PIN.

6 . The method of claim 5 , wherein the PIN is entered into the I/O device.

7 . An apparatus for authenticating a user to a remote computer via a client computer, comprising:

means for transmitting an authentication request from the client computer to the remote computer;

means for generating a challenge from the authentication request;

means for transmitting the challenge from the remote computer to the client computer;

means for providing the challenge to an input/output (I/O) device communicatively coupled to a hardware security device (HSD);

means for transmitting the challenge from the I/O device to the HSD;

means for generating a response to the challenge using the challenge and data selected from the group comprising a shared secret and a private key, wherein the response is generated in the HSD;

means for providing the response to the client computer;

means for transmitting the response from the client computer to the remote computer; and

means for granting access if the response compares favorably with an expected response computed by the remote computer from the challenge.

8 . The apparatus of claim 7 , wherein the I/O device comprises a personal data assistant (PDA).

9 . The apparatus of claim 7 , wherein the challenge is provided from the client computer to the I/O device and the response is provided from the I/O device to the client computer via a PDA/client computer compatible serial, parallel, infrared (IR), or radio frequency (RF) interface.

10 . The apparatus of claim 7 , wherein:

the means for providing a challenge to the I/O device comprises:

means for displaying the challenge on a display communicatively coupled to the client computer; and

means for entering the challenge into the I/O device;

the means for providing the response to the client computer comprises the steps of

means for displaying the response on the I/O device;

means for accepting entry of the response in a keyboard communicatively coupled to the client computer.

11 . The apparatus of claim 7 , further comprising the steps of:

means for accepting a user-entered personal identification number (PIN) in the HSD, and means for verifying the user-entered PIN before generating the response to the challenge using the data.

12 . The apparatus of claim 11 , wherein the PIN is entered into the I/O device.

13 . An apparatus for supporting authentication of a user to a remote computer via a client computer, comprising:

an input/output (I/O) interface compatible with a hardware security device (HSD), for transmitting a challenge to the HSD and for receiving a response to the challenge from the HSD;

an I/O device, comprising

a data presentation device communicatively coupled to the I/O interface, for presenting the response from the HSD; and

a data input device communicatively coupled to the I/O interface, for accepting the challenge.

14 . The apparatus of claim 13 , wherein the HSD comprises a processor implementing instructions for driving the data presentation device and the data input device.

15 . The apparatus of claim 13 , further comprising a processor, communicatively coupled to the I/O interface, the data presentation device, and the data input device, for implementing instructions for driving the data presentation device and the data input device.

16 . The apparatus of claim 13 , wherein the HSD is a USB-compliant token and the I/O interface is a USB-compliant interface.

17 . The apparatus of claim 13 , wherein the HSD is a smartcard and the I/O interface is a smart card compliant interface.

18 . The apparatus of claim 13 , wherein the I/O device is a personal data assistant (PDA).

19 . The apparatus of claim 13 , wherein the response is generated using the challenge and data selected from the group comprising a shared secret and a private key, wherein the response is generated in the HSD

20 . An apparatus for providing input to and receiving output from a hardware security device (HSD), comprising:

an HSD-compliant I/O interface;

a data presentation device communicatively coupled to the HSD-compliant I/O interface, for presenting data received from the HSD; and

a data input device, communicatively coupled to the HSD-compliant I/O interface, for accepting data entry;

wherein the data presentation device and the data input device are driven by a driver of the HSD.

21 . The apparatus of claim 20 , wherein the HSD comprises an HSD processor and an HSD memory communicatively coupled to the processor, and the driver is implemented by the HSD processor performing instructions stored in the HSD memory.

22 . The apparatus of claim 20 , wherein the HSD-compliant I/O interface is selected from the group comprising:

a universal serial bus (USB) interface;

an infrared (IR) interface; and

a radio frequency (RF) interface;

a smart card interface.

23 . A method of authenticating a user to a remote computer via a client computer, comprising the steps of:

transmitting an authentication request from the client computer to the remote computer;

receiving a challenge in the client computer, the challenge generated by the remote computer in response to the authentication request;

providing the challenge to a input/output (I/O) device communicatively coupled to a hardware security device (HSD);

transmitting the challenge from the I/O device to the HSD;

receiving a response to the challenge from the HSD, the response generated in the HSD;

transmitting the response from the client computer to the remote computer; and

receiving a message indicating successful authentication from the remote computer if the response compares favorably with an expected response generated by the remote computer from the challenge.

24 . The method of claim 23 , wherein the response is generated using data selected from the group comprising a shared secret and a private key.

25 . The method of claim 23 , wherein the I/O device comprises a personal data assistant (PDA).

26 . The method of claim 23 , wherein the challenge is provided from the client computer to the I/O device and the response is provided from the I/O device to the client computer via an interface selected from the group comprising a serial interface, a parallel interface, an infrared (IR) interface, and a radio frequency (RF) interface.

27 . The method of claim 23 , wherein:

the step of providing a challenge to the I/O device comprises the steps of:

displaying the challenge on a display communicatively coupled to the client computer; and

entering the challenge into the I/O device; the step of receiving the response to the challenge from the HSD comprises the steps of

displaying the response on the I/O device;

accepting entry of the response in a keyboard communicatively coupled to the client computer.

28 . The method of claim 23 , further comprising the step of

before transmitting the challenge from the I/O device to the HSD, accepting a user-entered personal identification number (PIN) in the HSD, and verifying the user-entered PIN.

29 . A method of authenticating a user to a remote computer via a client computer, comprising the steps of:

receiving a challenge in a hardware security device (HSD), the challenge obtained from an input/output (I/O) device communicatively coupled to the client computer and computed in the remote computer in response to an authentication request from the client computer;

generating a response in the HSD using the challenge and data selected from the group comprising a shared secret and a private key; and

providing the response from the HSD to the client computer, the response permitting successful authentication upon transmittal to the remote computer if the response compares favorably with an expected response computed by the remote computer from the challenge.

30 . The method of claim 29 , wherein the I/O device comprises a personal data assistant (PDA).

31 . The method of claim 29 , wherein the challenge is received from the I/O device and the response is transmitted to the I/O device via a wireless interface.

32 . The method of claim 29 , wherein the wireless interface is selected from the group comprising a radio frequency (RF) interface and an infrared (IR) interface.

33 . The method of claim 29 , wherein the step of providing the response from the HSD to the client computer comprises the steps of:

transmitting the response from the HSD to the I/O device;

presenting the response on the I/O device;

entering the presented response in an input device communicatively coupled to the computer

Assignments (3)
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Apr 19, 2007
From: SAFENET, INC.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL AGENT
Reel/Frame 019181/0012 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 16, 2007
From: SAFENET, INC.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL AGENT
Reel/Frame 019161/0506 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2004
From: GROVE, BRIAN D.
To: SAFENET, INC.
Reel/Frame 015880/0330 →