System, Method of Generation and Use of Bilaterally Generated Variable Instant Passwords.
In Bilaterally Generated Variable Instant Password system, Variable character sets or Master Variable Character Set with Sub Variable Character Sets of any level containing Character Units are used as means of generating Passwords. Password is a random combination of Character Units of Variable Character Set/derivatives, which is generated by a call of random numbers from SERVICE PROVIDER and corresponding response of USER. Bilaterally Generated Variable Instant Passwords and Non Repeating Bilaterally Generated Variable Instant Passwords are the two types of passwords that can be generated in this system. Font properties differentiation provides high password variability. Transformation of Variable Character Sets is also used to safeguard passwords. This system can authenticate persons, objects, individual actions initiated by USERs through separate passwords. Authentication of individual Internet Contract Transactions, Authenticated Dialogue Initiation, Automatic classification of USERs on access are special uses. This system can substitute all existing password systems including Biometric authentication.
1 . I claim a System for authenticating concurrently securing Internet transactions providing one Password cum symmetric encryption key for each lap of a transaction, two Password cum symmetric encryption keys for two laps of each transaction and a Plurality of Password cum symmetric encryption keys for a session, further enabling authenticated dialogue initiation and USER classification on access, including authentication devices printed on a physical medium such as paper, digital form and/or similar means, a memory device, a data processor loaded with software implementing the system for USER and SERVICE PROVIDER, connected by communication network or not, wherein, authenticating user using a single variable Password at the beginning of a session having a plurality of transactions, securing a session having a plurality of transactions using a single encryption key characterized in that (a) providing protocol for continuous mutual authentication of USER/Previously Unknown USER and SERVICE PROVIDER for every single transaction from beginning to end of session, employing one variable Password for each lap of a transaction, two variable Passwords per transaction of two consecutive laps, one lap from USER to SERVICE PROVIDER, the other lap from SERVICE PROVIDER to USER and a plurality of variable Passwords for a session having a plurality of transactions; (b) using the said plurality of variable Passwords and Calls for said plurality of variable Passwords as symmetric encryption keys; (c) securing every single object exchanged between USER/Previously Unknown USER and SERVICE PROVIDER employing one encryption key for each object, the said single object include all communications arising from one lap of a transaction between USER/Previously Unknown USER and SERVICE PROVIDER, such as files, message packets, Call, Password/encryption keys bundled in to single folder; (d) securing every single transaction between USER/Previously Unknown USER and SERVICE PROVIDER employing two encryption keys per transaction of two consecutive laps, one lap from USER to SERVICE PROVIDER, the other lap from SERVICE PROVIDER to USER; (e) the first of the said two encryption keys per transaction, furnished by USER/Previously Unknown USER as Password, the second of the said two encryption keys per transaction generated by concatenating the ‘Call’ excluding the first Call of session, available from the system; (f) employing a plurality of Passwords per session, half the number of the said plurality of Passwords provided by at least one method of (g) generating a plurality of Passwords from single initial Password furnished by USER/Previously Unknown USER in step (e), using a software termed as USER AGENT SOFTWARE and (h) direct keying in by USER/Previously Unknown USER for every transaction, (i) the second half the number of the said plurality of Passwords generated by concatenating the ‘Call’ available from the system; (j) initiating secure session of plurality of transactions making a Call termed as the first Call of session, in open network, the said first Call identifying the first encryption key to be used for securing the first object of the first transaction between USER and SERVICE PROVIDER, the said Call decipherable only between USER and SERVICE PROVIDER, whereby secure communication link is established only with the authorized, preventing unauthorized substitutions and clandestine diversions of the said secure communication; (k) continuously changing encryption keys integrated in to the system, dispensing with the effort for prior communication of encryption keys (l) the said continuously changing encryption keys decipherable only at the Internet Protocol address wherefrom the USER/Previously Unknown USER/SERVICE PROVIDER commenced transaction and upon furnishing valid Password for each object: (m) steps (j) to (l), ensuring continuous link between USER/Previously Unknown USER and SERVICE PROVIDER from the first to the last transaction preventing attacks such as intrusions, spoofing, substitutions, diversions and remote operations by unauthorized (n) USERs of the system include objects and Previously Unknown USERs; (o) the said system providing proof of transactions of USERs and Previously Unknown USERs as direct means of tracing source of objects received by USERs and SERVICE PROVIDERs in a computationally non intensive manner for identification of source of internet crimes and settlement of claims arising in internet; (p) the said system providing dialogue initiation, the means of identification of attempted access by parties including unknown parties as to whether the party attempting to access is invited or not and prevent from uninvited/undesired access by parties; (q) the said system dispensing with repeated furnishing of details at every access to the controlled sub domains of SERVICE PROVIDERs, reducing at least one step of communication; (r) the said system usable as independent symmetric encryption key system continuously changing encryption keys for each object exchanged; (s) the said system comprising (s1) a second system of authentication devices; (s2) font/distinguishing property modification of printed authentication devices; (s3) transformation of the authentication devices; (s4) authentication including using Call as Password; (s5) Bilaterally Generated Variable Instant Passwords and Non Repeating Bilaterally Generated Variable Instant Passwords; (s6) authentication and access restriction of USERs to protect Networks, computer systems, data, software, hardware, camera, mobile phone, and similar systems to the level of specified sector of data storage media; (s7) authentication and securing transactions with one Password furnished by USER for every transaction; (s8) USER agent software; (s9) generating multiple Passwords from single Password (s10) authentication and securing transactions by generating multiple Passwords from single Password of USER; (s11) authentication and securing transactions by generating multiple Passwords from single Password furnished from a temporary authentication device by a Previously Unknown USER; (s12) authenticated dialogue initiation and (s13) automatic classification of USERs on access.
2 . The system claimed as claim 1 , (a) USER is a person or a process or software or specified sector(s) of data storage media or a system or server or a Network or any thing that uses a Password for authentication; (b) a Previously Unknown USER is a USER having an USER account with a Internet SERVICE PROVIDER or Network server but is yet to establish an USER account with a SERVICE PROVIDER with whom such USER wants to transact and includes first time/temporary USERs/short duration USERs excused from having an USER account such as participants in auctions; (c) SERVICE PROVIDER is a person or a process or software or specified sector(s) of data storage media or a system or server or a Network or any thing who/which provides access to the USER upon furnishing of valid Password for authentication.
3 . The system claimed as claim 1 , (a) authentication device is any one of Variable Character Set system of authentication device pre agreed between USER and SERVICE PROVIDER; (b) temporary authentication device is an authentication device generated from Variable Character Set system of authentication device by SERVICE PROVIDER and sent to a Previously Unknown USER through Internet Service Provider/Network Server
4 . The system claimed as claim 1 , (a) Call is step of the authentication process of the system made by SERVICE PROVIDER to USER or vice versa, in terms of serial numbers of Character Units, requiring a Response to furnish Character Units of the authentication device, made of instantly generated random numbers, each of which is equal to or less than the total number of Character Units of authentication device; (b) Response is the answer furnished for a Call, in terms of Character Units of the authentication device, whose serial numbers of Character Units are the numbers called in the order of Call, typed as continuous string of Character Units; (c) Passwords generated using the system include Bilaterally Generated Variable Instant Passwords, Non Repeating Bilaterally Generated Variable Instant Passwords and random numbers of Call, concatenated, wherein all Calls except the session initiating Call are made within secure session; (d) two Passwords per transaction is using either Bilaterally Generated Variable Instant Password or Non Repeating Bilaterally Generated Variable Instant Password and the random numbers of Call, concatenated.
5 . The system claimed as claim 1 , (a) a transaction comprise of two consecutive laps, one lap from USER to SERVICE PROVIDER, the other lap from SERVICE PROVIDER to USER, each lap involving exchange of single object between USER and SERVICE PROVIDER, wherein objects are exchanged using one Password per object, wherein the said object is a folder containing communication, such as files, message packets, Calls, Passwords, the said folder is encrypted and access restricted between USER and SERVICE PROVIDER; (b) Internet Contract transaction is an Internet transaction between USER and SERVICE PROVIDER which has a monetary or other value wherein USER transacts using an USER name and authenticated by Passwords.
6 . The system claimed as claim 1 , continuous mutual authentication is verification of identity of USER and SERVICE PROVIDER mutually for every single object exchanged, using different Passwords/Calls linked to the identity of USER.
7 . The system claimed as claim 1 , providing proof for a transaction is to preserve the Call and Pass word of each transaction along with Internet Protocol address wherefrom USER and SERVICE PROVIDER transacted, date, time and USER details, including Internet Protocol address of Internet Service Provider/Network Server who forwarded the request of Previously Unknown USER, as means of tracing source of objects in a direct and computationally non intensive manner.
8 . The system claimed as claim 1 independent symmetric encryption key system comprising: (a) USER/SERVICE PROVIDER making the first Call in a session, wherein the said first Call is made in open network before start of encrypted session and is the inverse key which identifies the encryption key to be used; (b) SERVICE PROVIDER/USER using the Password to the said first Call as the first encryption key to start a secure session; (c) SERVICE PROVIDER communicating further Calls within encrypted session (d) USER and SERVICE PROVIDER using a Password for a transaction and random numbers of Call, concatenated, for the said transaction as two encryption keys for each transaction (e) USER and SERVICE PROVIDER continuously changing encryption keys at the rate of one per object exchanged in each lap of every single transaction.
9 . I claim a second system of authentication devices termed as Variable Character Set system of authentication devices used as means of generating variable and instant Passwords and authenticating USERs and SERVICE PROVIDERs in Bilaterally Generated Variable Instant Password System, the said authentication devices printed on a physical medium such as paper, digital form and/or similar means, stored in a memory device with data processor, comprising: (a) Variable Character Sets {VCS 1 to VCS 6 }, (b) Master Variable Character Sets {MVCS 1 }, (c) Sub Variable Character Sets and (d) Sub Variable Character Sets of Level 2 or below; wherein the functional combinations comprising: (e) both SERVICE PROVIDER and USER using Variable Character Set; (f) SERVICE PROVIDER using Master Variable Character Set with a Sub Variable Character Set expressed in brief form and USER using Sub Variable Character Set; (g) SERVICE PROVIDER using Master Variable Character Set with a Sub Variable Character Set of Level 2 or below expressed in brief form and USER using a Sub Variable Character Set of Level 2 or below, wherein at least one of the said combinations given herein as (e), (f) and (g) are used as the authentication device, wherein an authentication device of the said system further comprising: (h) an arrangement of a plurality of Character Units in which the Character Units are identified using unique Serial Number of Character Units; (i) the Character Unit consist of either one or a permutation of more than one Basic Character wherein the said random permutation includes repeating a Basic Character within same Character Unit; (j) the Basic Characters are selected from a plurality of characters including alphanumeric characters chosen from a plurality of languages/scripts/numbers/symbol systems including non familiar languages/scripts/numbers/symbol and graphical characters chosen from a plurality of representation of objects including diagrams, drawings, images, photos, pictures and sketches; (k) the characters are further differentiated by font/distinguishing properties; characterized in that (l) memorization is dispensed with; (m) the Character Units of the said arrangement comprise of completely random characters; (n) the total number of Character Units in the authentication device is unrestricted by human memorizable level removing the corresponding limit on Serial Number of Character Units imposable by memorization; (o) the Serial Number of Character Units identify corresponding Character Unit; no further relationship exists between Character Units and Serial Number of Character Units and no relation ship exists among the Character Units in the said arrangement; (p) the said arrangement is free from algorithms/pattern forming methods, requiring recalling and implementation of the said algorithms/pattern forming methods to produce Password; (q) the authentication devices produce Passwords of chosen level of safety; (r) the functional combinations given herein as (f) and (g), facilitating single authentication device providing required number of related sub authentication devices for assigning to a plurality of USERs/USER groups/uses, reducing data storage requirement of SERVICE PROVIDER, providing ease of identifying Character Units in programs in terms of Serial Number of Character Units of Master Variable Character Set; (s) facilitating classification of USERs and generation of several Passwords from single Password initially furnished by a USER linking with identity of USER.
10 . The system claimed as claim 9 , method of generating and using a Variable Character Set comprising the steps of (a) selecting the required number of Character Units; (b) arranging the Character Units in any one form of lists, tables, arrays and matrices, in which each of the Character Unit is distinctly identifiable and easily readable; (c) assigning unique Serial Number of Character Unit to identify each Character Unit in Variable Character Set; (d) specifying the method of identifying/calculating the Serial Number of Character Unit, facilitating USER to read the Character Units corresponding to the Serial Number of Character Units; (e) ensuring that the Character Units and the Serial Number of Character Units are unrelated and the Character Units of a Variable Character Set are unrelated to each other; (f) printing the said arrangement in a physical medium such as paper, digital form optionally in encrypted file form and/or similar means; (g) SERVICE PROVIDER and USER storing the arrangement securely in a memory device; (h) optionally, SERVICE PROVIDER validating USER generated Variable Character Set for compliance of the above steps (a) to (g); wherein (i) USER upon being a Previously Unknown USER to a SERVICE PROVIDER but known to another SERVICE PROVIDER passing the said Variable Character Set to the said Previously Unknown USER through the said known SERVICE PROVIDER and (j) USER upon being an Unknown USER, publishing the said Variable Character Set.
11 . The system claimed as claim 9 , method of generating and using a Master Variable Character Set comprising the steps of (a) generating a Variable Character Set and designating it as the Master Variable Character Set; (b) upon-generation of Sub Variable Character Sets by USERs, generating the Master Variable Character Set by combining the said USER generated Sub Variable Character Sets of all USERs of a SERVICE PROVIDER, as continuous and non-overlapping lists or tables or arrays or matrices; (c) storing and using the arrangement securely by SERVICE PROVIDER
12 . The system claimed as Claim 9 , method of generating and using Sub Variable Character Set comprising the steps of (a) selecting the total number of Character Units of the Sub Variable Character Set; (b) identifying Serial Number of Character Units of the Master Variable Character Set, the method of identifying the said Serial Number of Character Units adopting at least one of the following ways: (b1) specifying rules of selection such as criteria for filtering data, (b2) specifying discrete numbers, (b3) specifying continuous numbers and (b4) specifying random sequences; the Character units corresponding to the identified Serial Number of Character Units constituting the Sub Variable Character Set (c) selecting Character Units including a limited number of Character Units of other Sub Variable Character Sets, duly ensuring that no specific relationship exists, between Character Units of Sub Variable Character Sets of same origin (d) arranging Character Units selected as per steps (a) to (c) herein, to any one of the form of lists, tables, arrays and matrices, in which each of the Character Unit is distinctly identifiable and easily readable; (e) assigning unique Serial Number of Character Units, independent of Serial Number of Character Units of Master Variable Character Set to identify each Character Unit in the Sub Variable Character Set; (f) specifying the method of identifying/calculating the Serial Number of Character Unit, facilitating USER to read the Character Units corresponding to the Serial Number of Character Units; (g) ensuring Character Units and Serial Number of Character Units are unrelated and the Character Units of a Sub Variable Character Set are unrelated to each other; (h) assigning a Serial Number/identification number to each Sub Variable Character Set, (i) optionally USER generating Variable Character Set and using it as Sub Variable Character Set (j) SERVICE PROVIDER storing Sub Variable Character Sets in brief form as in step (b); (k) USERs storing Sub Variable Character Sets in complete form (l) wherein when using Sub Variable Character Sets, (m) the Password Calls are in Serial Number of Character Units of Sub Variable Character Sets and SERVICE PROVIDER compares with Character Units of Master Variable Character Set corresponding to the called Serial Number of Character Units of Sub Variable Character Sets; (n) prefixing or suffixing identification number of Sub Variable Character Sets with Password, is used to identify any Password specific to a particular Sub Variable Character Set, which in turn is used for identification of groups and classification of USERs; (o) replacing with another Sub Variable Character Set generated from the same Master Variable Character Set upon suspected compromise of a Sub Variable Character Set.
13 . The system claimed as claim 9 , where method of generating and using Sub Variable Character Sets of level 2 or below comprising steps of (a) selecting the total number of Character Units of the Sub Variable Character Set of level 2 or below, (b) identifying Serial Number of Character Units of the of one level up Sub Variable Character Set, the method of identifying the said Serial Number of Character Units adopting at least one of the following ways: (b1) specifying rules of selection such as criteria for filtering data, (b2) specifying discrete numbers, (b3) specifying continuous numbers and (b4) specifying random sequences; the Character units corresponding to the identified Serial Number of Character Units constituting the Sub Variable Character Set of level 2 or below; (c) selecting Character Units including a limited number of Character Units of one level up Sub Variable Character Sets/Master Variable Character Set, duly ensuring that no specific relationship exists, between Character Units of Sub Variable Character Sets any level of same origin; (d) arranging Character Units selected as per steps (a) to (c) of this claim in to any one of the form of lists, tables, arrays and matrices, in which each of the Character Unit is distinctly identifiable and easily readable; (e) assigning unique Serial Number of Character Unit, independent of Serial Number of Character Units of one level up Sub Variable Character Set/Master Variable Character Set to identify each Character Unit in the Sub Variable Character Set of Level 2 or below; (f) specifying the method of identifying/calculating the Serial Number of Character Unit, facilitating USER to read the Character Units corresponding to the Serial Number of Character Units; (g) ensuring the Character Units and the Serial Number of Character Units are unrelated and the Character Units of a Sub Variable Character Set of Level 2 or below are unrelated to each other; (h) assigning a Serial Number/identification number to each Sub Variable Character Set of Level 2 or below, (i) optionally, USER generating Sub Variable Character Set of level 2 or below duly selecting randomly the Character Units provided by SERVICE PROVIDERs from one level up Sub Variable Character Sets; (j) SERVICE PROVIDERs storing Sub Variable Character Sets of level 2 or below in brief form duly identifying Serial Number of Character Units of Sub Variable Character Sets of level 2 or below in terms of Serial Number of Character Units the Master Variable Character Set, the method of identifying the said Serial Number of Character Units, adopting at least one of the following ways: (j1) specifying rules of selection such as criteria for filtering data, (j2) specifying discrete numbers, (j3) specifying continuous numbers and (j4) specifying random sequences; (k) USERs storing Sub Variable Character Sets of Level 2 or below in complete form; wherein when using Sub Variable Character Sets of level 2 or below, (l) the Password Calls are in Serial Number of Character Units of Sub Variable Character Sets of level 2 or below and SERVICE PROVIDER compares with Character Units of Master Variable Character Set corresponding to the called Serial Number of Character Units of Sub Variable Character Sets of level 2 or below; (m) prefixing or suffixing identification number of Sub Variable Character Sets of level 2 or below with Password, is used to identify any Password specific to a particular Sub Variable Character Set of level 2 or below, which in turn is used for identification of groups and classification of USERs; (n) replacing with another Sub Variable Character Set of level 2 or below, generated from the same one level up Sub Variable Character Set upon suspected compromise of a Sub Variable Character Set of level 2 or below.
14 . The method of repeated variation of font/distinguishing properties such as font colour, as means of differentiation between same characters of Password, in printed Variable Character Set system of Authentication Devices, including implementing the method by means of a transparent sheet and a memory device with data processor loaded with software, characterized in that (a) generating new Character Units and new authentication devices while retaining original characters, enhancing security against breach of Passwords, enhancing life of authentication Devices and ability of use with any number of SERVICE PROVIDERs, comprising steps of: (b) USER, proposing variation to font/distinguishing properties of characters of Password/Character Units of Variable Character Sets/Sub Variable Character Sets of any level; (c) optionally SERVICE PROVIDER proposing said variation of font/distinguishing properties at regular intervals and USER agreeing to such variations; (d) SERVICE PROVIDER registering the changes; (e) USER using a separate transparent sheet to the size of printed Variable Character Sets/Sub Variable Character Sets of any level, indicating font/distinguishing property variation (f willing USER memorizing the changes; (g) furnishing font/distinguishing properties varied characters for Password.
15 . The method of transformation of Variable Character Set system of authentication devices to derive new Character Units including implementing the method by means a memory device with data processor loaded with software comprising steps of: (a) USER proposing at least one rule of transformation of characters of Password/Character Units of authentication device such as shifting Serial number of Character Units of authentication device by a specified number/shifting characters from natural order by a specified number; (b) USER keeping the said rule of transformation separate from authentication device; (c) willing USER memorizing the said rule of transformation on the Character Units or Basic Characters of the authentication device; (d) SERVICE PROVIDER registering the rules; (e) USER furnishing the transformed characters/Character Units for Password.
16 . Method of authentication by generating Bilaterally Generated Variable Instant Passwords including a memory device, a data processor loaded with software implementing the method for USER and SERVICE PROVIDER, connected by communication network or not comprising the steps of: (a) USER and SERVICE PROVIDER using a pre agreed authentication device of Variable Character Set system of authentication devices; (b) the Password comprising of a permutation of selected number of Character Units of the authentication device wherein optionally same Character Units are repeated in Password on repetition of same random number within a Call; (c) USER approaching the SERVICE PROVIDER with opening the website or dialogue window or switching on the SERVICE PROVIDER system; (d) SERVICE PROVIDER requesting the USER to furnish USER name or identification number; (e) USER furnishing USER name or identification number; (f) SERVICE PROVIDER (f1) verifying USER name, and refusing the unregistered USER; (f2) identifying and referring to the authentication device of particular USER; (f3) generating a specified number of random numbers wherein the said specified number is at least two; (f4) ensuring each of the generated random number is less than or equal to the total number of Character Units in the authentication device, further validating the said random numbers for compliance of rules preagreed between SERVICE PROVIDER and USER; (f5) sending the random numbers to the USER, termed as Call; (g) USER responding with a continuous-string of Character Units of the authentication device, wherein the serial numbers of Character Units, are the random numbers of Call, in the order of Call, termed as Response, wherein the said continuous string is making Basic Characters indistinguishable as belonging to particular Character Unit; (h) SERVICE PROVIDER when required, requesting the identification number of Sub Variable Character Set of any level as part of Password, along with Call and the USER complying with such request; (i) SERVICE PROVIDER (i1) verifying the Response to the Call with the respective authentication device and authenticating the USER when the Response furnished is correct; (i2) allowing the USER up to preagreed number of chances to furnish the correct Password when the Response furnished in step (i1) is incorrect; (i3) denying access and advising the USER to make subsequent attempt only after preagreed time when USER fails to furnish the correct Password within preagreed number of chances; (i4) making a Call to furnish two Passwords simultaneously/successively in only one single chance to the USER reaching step (i3); (i5) denying access to the USER, who failed to provide correct Password in step (i4) advising such USER to establish authenticity to the satisfaction of the SERVICE PROVIDER through other means, characterized in that (j) dispensing with memorization; (k) enhancing the limit on maximum value of random numbers in Call, imposable by memorization from up to human memorizable level to the total number of Character Units in the authentication device; (l) free from algorithms/pattern forming methods involving multi step procedures to produce Password (m) Call to furnish two Passwords simultaneously/successively prevents breaking and automatically notifies the authentic USER on failed attempts (n) enabling USER verifying authenticity of SERVICE PROVIDER for every transaction.
17 . In the method of authentication by generating of Bilaterally Generated Variable Instant Passwords as claimed in claim 16 , further comprising the steps of: (a) after the initial identification/authentication, the USER desiring to ascertain the authenticity of SERVICE PROVIDER, by pre arrangement, (b) issuing a Call; (c) SERVICE PROVIDER responding; (d) USER verifying the Response, with the authentication device and authenticating the SERVICE PROVIDER, whereby USER and SERVICE PROVIDER are mutually authenticated.
18 . In the method of authentication by generating of Bilaterally Generated Variable Instant Passwords as claimed in claim 16 , the valid Response to the Call in step (g) of claim 16 is Bilaterally Generated Variable Instant Password.
19 . In the method of authentication by generating of Bilaterally Generated Variable Instant Passwords as claimed in claim 16 , the method of generating Non Repeating Bilaterally Generated Variable Instant Passwords comprising of the steps of (a) SERVICE PROVIDER in step (f4) of claim 16 , verifying for compliance of the rule according to which, at least one Character Unit constituting a Password occurs for the first time in the said Password, wherein compliance of the said rule making the Passwords never repeat (b) wherein the said rule is observed till all Character Units of pre agreed authentication device are exhausted (c) wherein all the said Character Units of pre agreed authentication device are revived by transformation/font/distinguishing property change to the authentication device.
20 . In the method of authentication by generating of Bilaterally Generated Variable Instant Passwords as claimed in claim 16 , further comprising the steps of: using the random numbers of Call, concatenated, as Password, in addition to USER furnished Password, thereby generating two Passwords for a transaction.
21 . The method of authentication and access restriction of USERs to protect Networks, computer systems, data, software, hardware, camera, mobile phone, and similar systems to the level of specified sector of data storage media using Bilaterally Generated Variable Instant Password system, characterized by ability to control access object wise and access restriction of USER to the level of specified sector of data storage media including the system programs executable by SERVICE PROVIDER systems to which access is controlled, comprising steps of: (a) defining at least one authentication device of Variable Character Set system of authentication devices for each access control module and optionally a second authentication device to provide for eventualities, such as loss of Variable Character Set, transfer of ownership and similar situations for the owner/manufacturer/system administrator to bypass the USER's Password wherein the said second authentication device is used after the owner/manufacturer/system administrator is legally permitted; (b) incorporating a software to form authentication devices initially and modify optionally; (c) providing for SERVICE PROVIDER issuing a Call and USER providing Response; (d) optionally providing for USER requiring authentication of SERVICE PROVIDER issuing a Call and SERVICE PROVIDER providing Response; (e) wherein access is granted for USERs to a session/individual transaction/object after authentication and the said access is restricted to specified sector of SERVICE PROVIDER.
22 . The method of authenticating and securing of Internet Contract/Network transactions using one Password for each transaction furnished by a USER, including a memory device, a data processor loaded with software implementing the system for USER and SERVICE PROVIDER, connected by communication network, connected by communication network, { FIG. 1 }, using Bilaterally Generated Variable Instant Password System, the method comprising steps of (a) SERVICE PROVIDER and USER (a1) recording their mutual Internet Protocol/Network addresses at the beginning of a session; (a2) placing all unexposed Calls, Passwords, file and message packets in to folders, exchanging the folders after encrypting and access restricting utilizing any one of unexposed Calls/Passwords as Passwords and encryption keys, using a pre agreed cryptographic algorithm to encrypt; wherein all the unexposed Calls/Passwords generated up to a transaction in a session are available for encrypting and access restricting a specific folder by prior agreement; (a3) access restriction and maintaining continuity of link by ensuring IP address from which USER or SERVICE PROVIDER are transacting remains the one and the same from beginning to end of session and by obtaining a variable Password known only to USER and SERVICE PROVIDER for each object exchanged; (a4) confirming correctness of Calls, Passwords and allowing pre agreed number of chances to rectify; exiting upon occurrence of at least one of the following events: failure to furnish valid information, lapse of time, inability to open and inability to decrypt folders; (a5) checking objects exchanged before accepting, the said checks are for compliance of regulations, contract conditions and freedom from undesirable programs like virus; (b) USER furnishing USER Name and issuing a Call termed as ‘initial Call of the session’ to SERVICE PROVIDER; (c) SERVICE PROVIDER creating a folder containing Password for initial Call of the session, a Call, termed as ‘SERVICE PROVIDER's first Call’ and optional message, encrypting and access restricting the folder as detailed in step (a); sending the folder to USER; (d) USER opening and decrypting the folder, checking Password; creating a folder containing Password for SERVICE PROVIDER's first Call, any message, encrypting and access restricting the folder as detailed in step (a); sending the folder to SERVICE PROVIDER; (e) SERVICE PROVIDER opening and decrypting the folder, verifying Password from USER; creating a folder containing next Call, authentication message, encrypting and access restricting the folder as detailed in step (a); sending the folder to USER; (f) USER opening and decrypting the folder, getting the next Call; (g) after an Internet Contract/Network Transaction is created, USER, creating a folder containing Password for the Call received in previous step, and the file or message packet containing the USER's Internet Contract/Network Transaction; encrypting and access restricting the folder as detailed in step (a); sending the folder to SERVICE PROVIDER; (h) SERVICE PROVIDER opening and decrypting the folder, verifying Password furnished by USER, checking and processing the contents of file or message packet; responding by creating a folder containing Call for the next transaction and the file or message packet containing the SERVICE PROVIDER's Internet Contract/Network Transaction; encrypting and access restricting the folder as detailed in step (a); sending the folder to USER; (i) USER opening and decrypting the folder from SERVICE PROVIDER, checking and processing the contents of file or message packet; (j) Repeating steps (g) to (i), till the transactions are completed and (k) exiting after advising SERVICE PROVIDER (l) wherein SERVICE PROVIDER keeping proof for every transaction of USERs including the USER name, the IP address of USER system, the date and time, the details of Internet Contract/Network Transaction, the Call and the Password for each transaction providing direct and computationally non intensive means of tracing all actions/objects of a USER from access to exit.
23 . Method of generating multiple Passwords from single Password using User agent software wherein generating multiple passwords from single PIN/equivalent one at a time, user directly performing a plurality of steps of creating a password, upon directing user to furnish password for every transaction, inconveniencing user, software implementation to generate multiple passwords feasibly compromising PIN/equivalent, characterized in that: generating multiple Passwords from single Password in two steps, using software dispensing with effort from USER excepting furnishing first Password, securely within, system provided encryption, comprising steps of (a) USER Agent Software (b) collecting the Call and Password for initial access of USER; (c) determining the total number of Character Units and Character Units from said Call and Password collected in step (b); (d) forming a Sub Variable Character Sets of any level termed as ‘authentication device of the session’ using all Character Units determined in step (c); (e) assigning Serial Number of Character Units to the said Character Units; (f) communicating the assigned Serial Number of Character Units to SERVICE PROVIDER in encrypted folder using the Password for initial access of USER as encryption key; (g) SERVICE PROVIDER making Call from Serial Number of Character Units communicated in step (f); (h) USER Agent Software furnishing Response; (i) Repeating the steps (g) to (h) till end of session; (j) whereby a plurality of Passwords are generated; (k) wherein the first unexposed Call from SERVICE PROVIDER is optionally used as Serial Number of Character Units, dispensing with the need of communicating Serial Number of Character Units in step (f); wherein all Character Units of the USER's authentication device has equal number of characters and SERVICE PROVIDER's Calls for at least 4 Character Units from USER, providing at least 60 unique permutations from the said 4 Character Units.
24 . USER Agent Software, integrated with USER system connected through communication network to SERVICE PROVIDER system, the said software combined with Internet Contract/Network Transaction software optionally an independent software comprising modules to perform steps/functions of (a) USER Agent Software adopting to USER name as Internet Protocol/Network address of the computer, wherefrom, USER accesses SERVICE PROVIDER; (b) functioning from the USER Terminal representing USER, transacting with SERVICE PROVIDER; (c) recording Internet Protocol/Network address of SERVICE PROVIDER; (d) forming the authentication device of the session; (e) generating multiple Passwords from a single Password furnished by USER; (f) authenticating USER for individual transactions comprising: (f1) seeking Call (f2) furnishing Response, (f3) confirming correctness of Calls, Passwords and allowing specified number of chances to rectify; (g) exchanging objects after securing and access restricting the said objects to Internet Protocol/Network address of SERVICE PROVIDER; (h) checking for origination of USER's message from USER's system by (h1) ensuring continuity of connection with SERVICE PROVIDER; (h2) ensuring the integrity of command to do the Internet Contract/Network Transaction, through checking the keyboard and other input entries; (i) passing on the objects received from Service Provider to USER after checks such as presence of virus; (j) upon authentication failure, informing the USER to decide corrective action; (k) allowing USER doing authentications directly; (l) denying access to unauthorized user created Internet Contract/Network Transactions; (m) blocking the unauthorized user, from substituting the USER/USER Agent Software/SERVICE PROVIDER, through any other computer; (n) rejecting the attempts to originate Internet Contract/Network Transaction from the USER's Computer, through remote commands; (o) advising SERVICE PROVIDER upon end of transactions and exiting.
25 . The method of authenticating and securing of every individual Internet Contract/Network transaction with different Passwords, generating said different Passwords from single Password furnished at the beginning of a session by a known USER using USER Agent Software { FIG. 2 }, using Bilaterally Generated Variable Instant Password System, a memory device, a data processor loaded with software implementing the method for USER and SERVICE PROVIDER, connected by communication network, comprising steps of: (a) SERVICE PROVIDER and USER/USER Agent Software (a1) recording their mutual Internet Protocol/Network addresses at the beginning of a session; (a2) placing all unexposed Calls, Passwords, file and message packets in to folders, exchanging the folders after encrypting and access restricting using any one of unexposed Calls/Passwords as Passwords and encryption keys, using a pre agreed cryptographic algorithm to encrypt; wherein all the unexposed Calls/Passwords generated up to a transaction in a session is available for encrypting and access restricting a specific folder by prior agreement; (a3) access restriction and maintaining continuity of link by ensuring IP address from which USER or SERVICE PROVIDER are transacting remains the one and the same from beginning to end of session and by obtaining a variable Password known only to USER and SERVICE PROVIDER, from the respective systems, for each object exchanged; (a4) confirming correctness of Calls, Passwords and allowing pre agreed number of chances to rectify; exiting upon occurrence of at least one of the following events: failure to furnish valid information, lapse of time, inability to open and inability to decrypt folders; (a5) checking objects exchanged before accepting, the checks are for compliance of regulations, contract conditions, and freedom from undesirable programs like virus; (b) USER furnishing USER Name and issuing a Call termed as ‘initial Call of the session’ to SERVICE PROVIDER; (c) SERVICE PROVIDER creating a folder containing Password for initial Call of the session, a Call, termed as ‘SERVICE PROVIDER's first Call’ and optional message, encrypting and access restricting the folder as detailed in step (a); sending the folder to USER; (d) USER opening and decrypting the folder, checking Password; creating a folder containing Password for SERVICE PROVIDER's first Call, any message, encrypting and access restricting the folder as detailed in step (a); sending the folder to SERVICE PROVIDER; (e) SERVICE PROVIDER opening and decrypting the folder, verifying Password from USER; creating a folder containing authentication message, encrypting and access restricting the folder as detailed in step (a); sending the folder to USER; (f) USER opening and decrypting the folder, upon being authenticated, authorizing USER Agent Software for doing transactions passing on Password furnished in step (f) and Call received in step (e); (f) USER Agent Software forming a Sub Variable Character Set of any Level, using all Character Units of the Password furnished in step (f), assigning Serial Number of Character Units as Call received in step (e) or in a different manner and using it as the authentication device of that session.
26 . In the method claimed in claim 25 , (a) USER Agent Software creating a folder containing assigned Serial Number of Character Units and request for a Call; encrypting and access restricting the folder as in step (a) of claim 25; sending it to SERVICE PROVIDER; (b) SERVICE PROVIDER upon confirming the Internet Protocol/Network address of the USER Agent Software and USER are same, opening and decrypting the folder, registering Serial Number of Character Units, creating a folder containing Call within the authentication device of the session, encrypting and access restricting the folder as in step (a) of claim 25 , sending it to USER Agent Software; USER Agent Software opening and obtaining the Call for next transaction; (c) USER creating Internet Contract/Network Transaction and passing on to USER Agent Software; USER Agent Software checking for the origination of Internet Contract/Network Transaction from within USER system such as; (c1) ensuring continuity of connection with SERVICE PROVIDER; (c2) ensuring the integrity of command to do the Internet Contract/Network Transaction, through checking the keyboard and other input entries; (c3) upon confirming the origination, the USER Agent Software, (c4) creating a folder containing Password for the Call obtained in step (b) and the file or message packet containing the USER's Internet Contract/Network Transaction; (c5) encrypting and access restricting the folder as in step (a) of claim 25; (c6) sending the folder to SERVICE PROVIDER; (d) SERVICE PROVIDER opening and decrypting the folder, (d1) verifying Password furnished by USER Agent Software; (d2) checking and processing the contents of file or message packet; (d3) responding by creating a folder containing Call for the next transaction and the file or message packet containing the SERVICE PROVIDER's Internet Contract/Network Transaction; (d4) encrypting and access restricting the folder as in step (a) of claim 25; (d5) sending the folder to USER Agent Software; (e) USER Agent Software opening and decrypting the folder from SERVICE PROVIDER, checking and passing on the file or message packet to USER; retaining the Call; (e repeating steps (c) to (e) till the transactions are completed and exiting after advising SERVICE PROVIDER; (g) USER Agent Software performing further required steps as claimed in claim 24; (h) SERVICE PROVIDER keeping proof for every transaction of USERs including the USER name, the IP address of USER system, the date and time, the details of Internet Contract/Network Transaction, the Call and the Password for each transaction; (i) providing direct and computationally non intensive means of tracing all actions/objects of a USER/SERVICE PROVIDER from access to exit.
27 . The method of authenticating and securing of every individual Internet/Network transaction of a Previously Unknown USER including implementing the method by means a memory device, a data processor loaded with software implementing the method for Previously Unknown USER and SERVICE PROVIDER, connected by communication network, comprising steps of (a) Previously Unknown USER's System using USER Agent Software, provided on request by SERVICE PROVIDER; (b) SERVICE PROVIDER and Previously Unknown USER/USER Agent Software (b1) recording their mutual Internet Protocol/Network addresses at the beginning of a session; (b2) placing all unexposed Calls, Passwords and file or message packets in to folders, exchanging the folders after encrypting and access restricting using the Call for a transaction for object exchange from Previously Unknown USER/USER Agent Software to SERVICE PROVIDER and the Password for a transaction for object exchange from SERVICE PROVIDER to Previously Unknown USER/USER Agent Software; (b3) access restriction and ensuring continuity of the link is by ensuring IP address from which the Previously Unknown USER/USER Agent Software or SERVICE PROVIDER are transacting remains the one and the same from beginning to end of session and by obtaining a variable Password known only to Previously Unknown USER/USER Agent Software and SERVICE PROVIDER for each object exchanged from respective systems; (b4) confirming correctness of Calls, Passwords and allowing pre agreed number of chances to rectify; exiting upon failure to rectify or lapse of time or inability to open or decrypt folders; (b5) optionally checking objects exchanged before accepting, the checks are for compliance of regulations, contract conditions as agreed at the commencement of session, and freedom from undesirable programs like virus; (c) Previously Unknown USER requesting a known Internet SERVICE PROVIDER/Network server to facilitate transactions with an Unknown SERVICE PROVIDER, furnishing the domain name of the website or IP address of the SERVICE PROVIDER; (d) Internet SERVICE PROVIDER/Network server authenticating said USER with a Password from that USER's account, conveying the request of the said USER, passing on the USER name, the IP address of the USER and USER data as required to that SERVICE PROVIDER; (e) SERVICE PROVIDER, (e1) considering the request; (e2) when unwilling to transact with that USER, conveying unwillingness through the Internet SERVICE PROVIDER/Network server to that USER; (e3) when willing to transact with that Previously Unknown USER, storing a newly assigned USER name, linked with validated USER data furnished by Internet SERVICE PROVIDER/Network server, IP address of the USER and IP address of Internet SERVICE PROVIDER/Network server for record; (e4) creating a folder containing temporary Sub Variable Character Set of at least eight Character Units and a Call for the Internet SERVICE PROVIDER or Network server, a sub folder for Previously Unknown USER containing temporary USER Name, temporary Sub Variable Character Set of at least eight Character Units having equal number of Basic Characters in all Character Units and a Call for at least four Character Units; (e5) encrypting and access restricting the subfolder to IP address of Previously Unknown USER as USER Name with a Password; (e6) sending the folder to Internet SERVICE PROVIDER or Network server; (f) Internet SERVICE PROVIDER/Network server conveying SERVICE PROVIDER's unwillingness to USER or opening the folder, furnishing Password to SERVICE PROVIDER, passing on the subfolder to USER and exiting; (g) SERVICE PROVIDER checking Password from Internet SERVICE PROVIDER/Network server and upon finding it correct, sending the Password to open the subfolder directly to Previously Unknown USER (h) Previously Unknown USER exiting on unwillingness of SERVICE PROVIDER to transact or opening the subfolder using Password received from SERVICE PROVIDER and obtaining temporary Sub Variable Character Set (i) Previously Unknown USER accessing SERVICE PROVIDER's website, recording IP address of SERVICE PROVIDER, furnishing USER Name, creating folder containing Password to the Call received in the subfolder, encrypting and access restricting as in step (b); sending the folder to SERVICE PROVIDER; (j) SERVICE PROVIDER verifying USER Name, recording IP address of USER, locating authentication device; upon finding the Password as correct, advising about successful authentication, for that session, from when on, that Previously Unknown USER becomes an authenticated but temporary USER to that SERVICE PROVIDER; (k) Previously Unknown USER, authorizing USER Agent Software to act further, passing on the Password and Call used for initial access; (l) USER Agent Software forming a Sub Variable Character Set of any Level, using all Character Units of the Password for initial access, assigning Serial Number of Character Units as Call for initial access or in a different manner and using it as the authentication device of that session.
28 . The method of authenticating and securing of every individual Interne/Network transaction of a Previously Unknown USER as claimed in claim 27 , further comprising the steps of (a) USER Agent Software seeking a Call; (b) SERVICE PROVIDER upon confirming the Internet Protocol/Network address of the USER Agent Software and temporary USER are same, creating a folder containing Call within the authentication device of the session, encrypting and access restricting the folder as in step (b) of claim 27 , sending it to USER Agent Software; USER Agent Software opening and obtaining the Call for next transaction; (c) temporary USER creating Internet Contract/Network Transaction and passing on to the USER Agent Software; USER Agent Software checking for the origination Internet Contract/Network Transaction from within temporary USER's system such as; (c1) ensuring continuity of connection with SERVICE PROVIDER; (c2) ensuring the integrity of command to do the Internet Contract/Network Transaction, through checking the keyboard and other input entries (c3) upon confirming the origination, the USER Agent Software, (c4) creating a folder containing Password for the Call obtained in step (b) and the file or message packet containing the temporary USER's Internet Contract/Network Transaction; (c5) encrypting and access restricting the folder as in step (b) of claim 27; (c6) sending the folder to SERVICE PROVIDER (d) SERVICE PROVIDER opening and decrypting the folder, (d1) verifying Password furnished by USER Agent Software; (d2) checking and processing the contents of file or message packet; (d3) responding by creating a folder containing Call for the next transaction and the file or message packet containing the SERVICE PROVIDER's Internet Contract/Network Transaction; (d4) encrypting and access restricting the folder as in step (b) of claim 27; (d5) sending the folder to USER Agent Software; (e) USER Agent Software opening and decrypting the folder from SERVICE PROVIDER, checking and passing on the file or message packet to temporary USER; retaining the Call (f) Repeating steps (c) to (e) till the transactions are completed and exiting after advising SERVICE PROVIDER (g) USER Agent Software performing further required steps as claimed in claim 24; (h) SERVICE PROVIDER keeping proof for every transaction of USERs including the USER name, the IP address of USER system, the date and time, the details of Internet Contract/Network Transaction, the Call and the Password for each transaction; (i) providing direct and computationally non intensive means of tracing all actions/objects of a Previously Unknown USER/SERVICE PROVIDER from access to exit.
29 . The method of Authenticated Dialogue Initiation in the Internet/network between a USER/SERVICE PROVIDER and another party, who is known or Unknown to USER/SERVICE PROVIDER including a memory device, a data processor loaded with software implementing the method for USER and SERVICE PROVIDER, connected by communication network, using Bilaterally Generated Variable Instant Password system comprising steps of (a) Publishing Variable Character Set for Authenticated Dialogue Initiation purpose; (b) USER intending to initiate a dialogue with any party in Internet/Network, calling for a Password from the Variable Character Set published for Authenticated Dialogue Initiation purpose, from the party sought by USER, when sending the Internet Protocol/Network Address of the party; (c) the party called by USER, taking decision on Response to this Call and optionally responding with Password from the said Variable Character Set published for Authenticated Dialogue Initiation purpose; (d) USER checking Internet Protocol/Network Address of the party along with Password; (e) admitting the party when both Internet Protocol/Network Address of the party and Password are correct; (f) USER denying access to uninvited parties (g) USER optionally granting non preferred access, the said non preferred access is limiting the uninvited parties to boundary set by USER.
30 . The method of Automatic Classification of USERs upon access including implementing the method by means a memory device, a data processor loaded with software implementing the method for USER and SERVICE PROVIDER, connected by communication network, using Bilaterally Generated Variable Instant Password System, comprising steps of (a) using Master Variable Character Set/Sub Variable Character Sets arrangement; (b) assigning each USER of a particular groups or subgroup, Sub Variable Character Sets with a partly common identification specific to each class of USERs; (c) Calling identification of Sub Variable Character Sets as part of Password; (d) checking the partly common identification of Sub Variable Character Sets of Password; (e) identifying USER groups or subgroups (f) classifying USERs on access based on partly common identification, (g) using the classification arrived in previous step to authorize USER to access sub domains within a domain, thereby, dispensing with USER furnishing input data further to USER Name and Password and dispensing with SERVICE PROVIDER referring to stored information related to the said USER; reducing at least one step of communication.
31 . The use of Bilaterally Generated Variable Instant Password System claimed in claims 1 to 30 .