IP Library Granted Patent US 7,730,321
Granted Patent B2
US 7,730,321 · App. 11/050,549 · Granted Jun 1, 2010

System and method for authentication of users and communications received from computer systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,730,321
App. No.
11/050,549
Granted
Jun 1, 2010
Kind
B2
Abstract

A system and method allows a user to authenticate a communication from a computer system, a computer system to authenticate a user, or both. When a user requests a web page from the web site, customization information that is recognizable to the user is provided to allow the user to authenticate the web site. A signed, encrypted persistent file stored on the user's computer system or installed on a different computer system, or a trusted computing subsystem allows the web site to authenticate the user. If the user is using a system that will not allow that user to be authenticated, the user may instruct the system to continue providing information without the user's customization information. The system and method may be used to allow the user to authenticate an e-mail message or its source, and Flash movies or other computer code may be used if the user's e-mail client does not employ cookies.

Claims (70)

1. A method of receiving information useful for logging a user into a computer system, comprising:

causing a user identifier to be stored in a persistent file of a client system;

receiving from the user a request to log into the computer system;

responsive to the request received;

receiving the persistent file including the user identifier from the client system;

providing from the computer system to the user a prompt for the user identifier;

receiving a response from the user responsive to the prompt for the user identifier; and

determining if the response received from the user matches the user identifier received in the persistent file; and

responsive to a determination that the response received matches the user identifier received:

providing from the computer system to the user a prompt for confidential information; and

presenting to the user customization information corresponding to the user identifier received that is perceptible to the user and can allow the user to authenticate the computer system if the customization information presented matches customization information expected by the user;

said customization information being presented to the user before or during the providing from the computer system to the user the prompt for confidential information step;

said customization information not being presented to the user between the receiving the request step and the determination that the response received matches the user identifier received; and

the correspondence of the customization information with the user identifier not ordinarily being publicly known.

2. The method of claim 1 wherein the customization information was identified by the user prior to the receiving the request step.

3. The method of claim 2 wherein the customization information was identified by the user providing the customization information to the computer system.

4. The method of claim 1 wherein the customization information for the user may be different from customization information for at least one other user who may log into the computer system.

5. The method of claim 4 , wherein the customization information for the user may be different from customization information for all other users who may log into the computer system.

6. The method of claim 1 wherein the presenting to the user customization information step is additionally responsive to at least a portion of the persistent file received from the client system other than the user identifier.

7. The method of claim 1 wherein the presenting to the user customization information step is additionally responsive to at least a portion of an identifier corresponding to the client system.

8. The method of claim 1 wherein the user identifier in the persistent file is encrypted in the persistent file.

9. The method of claim 1 wherein the persistent file comprises a local shared object capable of being used by a Flash movie.

10. A system for receiving information useful for logging a user into a computer system, comprising:

at least one storage; and

a processor operatively coupled to the at least one storage, the processor being operative to perform the steps of:

causing a user identifier to be stored in a persistent file of a client system;

receiving from the user a request to log into the computer system;

responsive to the request received;

receiving the persistent file including the user identifier from the client system;

providing from the computer system to the user a prompt for the user identifier;

receiving a response from the user responsive to the prompt for the user identifier, and

determining if the response received from the user matches the user identifier received in the persistent file; and

responsive to a determination that the response received matches the user identifier received:

providing from the computer system to the user a prompt for confidential information; and

presenting to the user customization information corresponding to the user identifier received that is perceptible to the user and can allow the user to authenticate the computer system if the customization information presented matches customization information expected by the user;

said customization information being presented to the user before or during the providing from the computer system to the user the prompt for confidential information step;

said customization information not being presented to the user between the receiving the request step and the determination that the response received matches the user identifier received; and

the correspondence of the customization information with the user identifier not ordinarily being publicly known.

11. The system of claim 10 wherein the processor is further operative to perform the step of:

receiving from the user, prior to a time at which the customization information is presented to the user, an identification of the customization information to be presented to the user.

12. The system of claim 11 wherein the customization information is identified by the user providing the customization information.

13. The system of claim 10 wherein the customization information for the user may be different from customization information for at least one other user who may log into the computer system.

14. The system of claim 13 , wherein the customization information for the user may be different from customization information for all other users who may log into the computer system.

15. The system of claim 10 wherein the processor is further operative to perform the step of

presenting the customization information additionally responsive to at least one portion of a persistent file other than the user identifier.

16. The system of claim 10 wherein the customization information is presented to the user additionally responsive to a portion of an identifier corresponding to the client system.

17. The system of claim 10 wherein the user identifier is encrypted in the persistent file.

18. The system of claim 10 wherein the persistent file comprises a local shared object capable of being used by a Flash movie.

19. A computer program product comprising a computer useable medium having computer readable program code embodied therein for receiving information useful for logging a user into a computer system, the computer program product comprising computer readable program code devices configured to cause a computer system to:

cause a user identifier to be stored in a persistent file of a client system;

receive from the user a request to log into the computer system;

responsive to the request received;

receive the persistent file including the user identifier from the client system;

provide from the computer system to the user a prompt for the user identifier;

receive a response from the user responsive to the prompt for the user identifier; and

determine if the response received from the user matches the user identifier received in the persistent file; and

responsive to a determination that the response received matches the user identifier received:

provide from the computer system to the user a prompt for confidential information; and

present to the user customization information corresponding to the user identifier received that is perceptible to the user and can allow the user to authenticate the computer system if the customization information presented matches customization information expected by the user;

said customization information being presented to the user before or during the providing from the computer system to the user the prompt for confidential information step;

said customization information not being presented to the user between the receiving the request step and the determination that the response received matches the user identifier received; and

the correspondence of the customization information with the user identifier not ordinarily being publicly known.

20. The computer program product of claim 19 wherein the customization information was identified by the user prior to the receiving the request step.

21. The computer program product of claim 20 wherein the customization information was identified by the user providing the customization information to the computer system.

22. The computer program product of claim 19 wherein the customization information for the user may be different from customization information for at least one other user who may log into the computer system.

23. The computer program product of claim 22 , wherein the customization information for the user may be different from customization information for all other users who may log into the computer system.

24. The computer program product of claim 19 wherein the computer readable program code devices configured to cause the computer system to present to the user customization information are additionally responsive to at least a portion of the persistent file received from the client system other than the user identifier.

25. The computer program product of claim 19 wherein the computer readable program code devices configured to cause the computer system to present to the user customization information are additionally responsive to at least a portion of an identifier corresponding to the client system.

26. The computer program product of claim 19 wherein the user identifier in the persistent file is encrypted in the persistent file.

27. The computer program product of claim 19 wherein the persistent file comprises a local shared object capable of being used by a Flash movie.

Assignments (14)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023975/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023975/0453 →
MERGER Recorded Jan 27, 2010
From: RSA SECURITY INC
To: RSA SECURITY LLC
Reel/Frame 023852/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023824/0729 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023825/0109 →