IP Library Granted Patent US 7,596,701
Granted Patent B2
US 7,596,701 · App. 11/340,376 · Granted Sep 29, 2009

Online data encryption and decryption

Assignee: Oracle International Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,596,701
App. No.
11/340,376
Granted
Sep 29, 2009
Kind
B2
Abstract

Systems and methods for providing encryption and decryption of data transmitted on a computer implemented network, preferably user authentication identifier data, such as a password, at the point of entry into the user's computer. The systems and methods enable an end user to mentally select a marker from one of the randomly arranged elements on a first portion of a graphical image. A second portion of the graphical image includes an arrangement of possible elements of any individual authentication identifier sequence, and is positioned adjacent to the first portion. The systems and methods prompt a user to enter each element of the identifier by moving the selected marker and the first portion as necessary to substantially align the selected marker with a chosen element of the authentication identifier appearing on the outer portion. According to one embodiment, the image portions are concentric wheels. According to another embodiment, the image portions are arranged in adjacent rows.

Claims (60)

1. An authentication system comprising:

a server computer communicatively coupled with one or more user computers via a computer network, wherein the server computer is configured to:

receive, from a user computer in the one or more user computers, an identifier that uniquely identifies a user;

retrieve, based on the identifier, a first image associated with the user, wherein the first image was previously selected by the user;

retrieve a second image that represents an entry interface;

modify the second image to generate a third image, wherein the second and third images are visually substantially similar but have different file sizes;

generate a personalized graphical interface that includes the first image and the third image; and

transmit the personalized graphical interface to the user computer.

2. The authentication system of claim 1 , wherein the second image is superimposed on the first image.

3. The authentication system of claim 1 , wherein the personalized graphical interface further includes a text element previously selected by the user.

4. The authentication system of claim 1 , wherein the entry interface is in the form of a keypad or a keyboard.

5. The authentication system of claim 1 , wherein the first image includes animated elements or a photograph.

6. The authentication system of claim 1 , wherein the third image is check-sum encrypted by the server.

7. The authentication system of claim 1 , wherein the third image is shift encrypted by the server.

8. An authentication system comprising:

a server computer communicatively coupled with one or more user computers via a computer network, wherein the server computer is configured to:

receive, from a user computer in the one or more user computers, a user identifier that uniquely identifies a user and a user computer identifier that uniquely identifies the user computer;

compare the user computer identifier with a predefined list of user computer identifiers associated with the user identifier;

if the user computer identifier is included in the predefined list:

retrieve, based on the user identifier, a first image associated with the user, wherein the first image was previously selected by the user;

generate a personalized graphical interface that includes the first image and a second image, the second image representing an entry interface; and

transmit the personalized graphical interface to the user computer;

else if the user computer identifier is not included in the predefined list:

transmit a set of challenge questions to the user computer.

9. The authentication system of claim 1 , wherein the personalized graphical interface further includes a fourth image of a document associated with the user.

10. The authentication system of claim 9 , wherein at least part of the fourth image is initially obscured, and wherein the obscured portions of the fourth image become visible in response an entry of a specific identifier via the entry interface of the personalized graphical interface.

11. The authentication system of claim 10 , wherein the entry interface is in the form of a keyboard, and wherein the personalized graphical interface further includes one or more text elements previously selected by the user.

12. An authentication system comprising:

a server computer communicatively coupled with one or more user computers via a computer network, wherein the server computer is configured to:

receive, from a user computer in the one or more user computers, an identifier that uniquely identifies a user;

retrieve, based on the identifier, a first image associated with the user, wherein the first image was previously selected by the user;

retrieve a second image that represents an entry interface and shift encrypt the second image to generate a third image;

generate a personalized graphical interface that includes the first image and the third image; and

transmit the personalized graphical interface to the user computer.

13. The authentication system of claim 12 , wherein the personalized graphical interface further includes a text element that was previously selected by the user.

14. The authentication system of claim 12 , wherein the personalized graphical interface is encrypted by the server computer prior to being transmitted to the user computer.

15. The authentication system of claim 1 , wherein the first image was previously selected by the user at a time of registering an account with a service provider operating the server computer.

16. The authentication system of claim 1 , wherein altering the second image to generate the third image comprises padding extra values to the second image in a random fashion.

17. A method performed by a server computer for authenticating one or more users, the method comprising:

receiving, by the server computer from a user computer, an identifier that uniquely identifies a user;

retrieving, by the server computer based on the identifier, a first image associated with the user, wherein the first image was previously selected by the user;

retrieving, by the server computer, a second image that represents an entry interface;

modifying, by the server computer, the second image to generate a third image, wherein the second and third images are visually substantially similar but have different file sizes;

generating, by the server computer, a personalized graphical interface that includes the first image and the third image; and

transmitting, by the server computer, the personalized graphical interface to the user computer.

18. A method performed by a server computer for authenticating one or more users, the method comprising:

receiving, by the server computer from a user computer, a user identifier that uniquely identifies a user and a user computer identifier that uniquely identifies the user computer;

comparing, by the server computer, the user computer identifier with a predefined list of user computer identifiers associated with the user identifier;

if the user computer identifier is included in the predefined list:

retrieving, by the server computer based on the user identifier, a first image associated with the user, wherein the first image was previously selected by the user;

generating, by the server computer, a personalized graphical interface that includes the first image and a second image, the second image representing an entry interface; and

transmitting, by the server computer, the personalized graphical interface to the user computer;

else if the user computer identifier is not included in the predefined list:

transmitting, by the server computer, a set of challenge questions to the user computer.

19. A method performed by a server computer for authenticating one or more users, the method comprising:

receiving, by the server computer from a user computer, an identifier that uniquely identifies a user;

retrieving, by the server computer based on the identifier, a first image associated with the user, wherein the first image was previously selected by the user;

retrieving, by the server computer, a second image that represents an entry interface and shift encrypting the second image to generate a third image;

generating, by the server computer, a personalized graphical interface that includes the first image and the third image; and

transmitting, by the server computer, the personalized graphical interface to the user computer.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2008
From: ORACLE SYSTEMS CORPORATION
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 020459/0057 →
MERGER Recorded Jan 30, 2008
From: BHAROSA, INC.
To: ORACLE SYSTEMS CORPORATION
Reel/Frame 020439/0067 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2006
From: FISHER, JON BRYAN; HARRIS, STEVEN LUCAS; VARGHESE, THOMAS EMMANUAL; DURAI, DON BOSCO
To: BHAROSA INC.
Reel/Frame 017397/0264 →
Continuity (3)
Continuation In Part 1116956400 · Jun 29, 2005
Provisional Application 6058581800 · Jul 7, 2004
Related Publication 20070192615A1 · Aug 16, 2007