IP Library Granted Patent US 8,438,623
Granted Patent B2
US 8,438,623 · App. 13/275,665 · Granted May 7, 2013

Automated security token administrative services

Inventor: Jamie Angus Band (Palo Alto, CA)
Assignee: ActivCard
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,438,623
App. No.
13/275,665
Granted
May 7, 2013
Kind
B2
Abstract

This invention provides a system, method and computer program product to allow a user to access administrative security features associated with the use of a security token. The administrative security features provide the user the ability to unlock a locked security token, diagnose a security token, activate and deactivate a security token, request a replacement security token or temporary password or report the loss of a security token. The invention comprises a client application which integrates into the standard user login dialog associated with an operating system. A portion of the user dialog is linked to a remote server to access the administrative services.

Claims (56)

1. A system which performs at least one administrative security function which facilitates alternative access to system resources and services comprising:

at least one credential associated with a user;

a local client in processing communications with an authenticating computer system including;

one or more functionally connected user input devices;

a user interface means for handling input from and output to said user;

software that generates and sends an administrative access request to said authenticating computer system to perform at least one administrative security function, wherein said administrative access request includes said at least one credential;

software that mediates said at least one administrative security function between said authenticating computer system, said client and said user; and

said authenticating computer system including;

means responsive to said administrative access request for performing said at least one administrative security function, wherein said at least one administrative security function includes means for authenticating said user to said authenticating computer system using said at least one credential and means for allowing access to system resources and services,

without requiring said user to log on to an operating environment associated with said local client.

2. The system according to claim 1 wherein said authenticating computer system is a remote server.

3. The system according to claim 1 wherein said authenticating computer system is a locally connected security token.

4. The system according to claim 3 wherein said means responsive to said administrative access request for performing said at least one administrative security function is a security token application.

5. A system which performs at least one administrative security function which facilitates alternative access to system resources and services comprising:

at least one credential associated with a user;

a security token functionally connected to a local client including a user authentication mechanism, wherein said user authentication mechanism includes a changeable security state, said changeable security state operative to mediate access to system resources and services;

said local client in processing communications with a server including;

one or more functionally connected user input devices;

a user interface means for handling input from and output to said user;

software that generates and sends an administrative access request to said server to perform at least one administrative security function, wherein said administrative access request includes said at least one credential;

software that mediates at least one administrative security function between said server, said client and said security token; and

said server including;

means responsive to said administrative access request for performing said at least one administrative security function, wherein said at least one administrative security function includes means for authenticating said user to said server using said at least one credential and means for altering said changeable security state,

without requiring said user to log on to an operating environment associated with said local client.

6. The system according to claim 2 further including mutual authentication means.

7. The system according to claim 6 wherein said server is authenticated to said client using a public key infrastructure methodology.

8. The system according to claim 6 wherein said at least one administrative security function further includes means for unlocking said security token.

9. The system according to claim 6 wherein said at least one administrative security function further includes means for performing diagnostics on said security token.

10. The system according to claim 6 wherein said at least one administrative security function further includes means for reactivating or deactivating said security token.

11. The system according to claim 6 wherein said at least one administrative security function further includes means for requesting a replacement security token.

12. The system according to claim 6 wherein said at least one administrative security function further includes means for enabling a temporary password.

13. The system according to claim 6 wherein said at least one administrative security function further includes means for automatically allowing said user access to said system resources and services.

14. The system according to claim 6 wherein said at least one administrative security function further includes means for reporting that said security token has been lost, damaged or stolen.

15. The system according to claim 6 wherein said processing communications includes a secure communications protocol.

16. The system according to claim 15 wherein said secure communications protocol includes SSL, SSH, TLS, WAP or IPSEC.

17. The system according to claim 7 wherein said public key infrastructure methodology includes challenge/response authentication or digital certificate exchange.

18. The system according to claim 6 wherein said at least one credential includes a passphrase, password, PIN, biometric scan, question and answer session or a combination thereof.

19. A method for performing at least one administrative security function on his security token which facilitates alternative access to system resources whereby said user does not need to login in an operating system, and services comprising the steps of:

displaying at least one administrative security function on a user interface display,

receiving a credential from a user interface input device without logging on to an operating environment associated with said local client,

causing a request to perform said at least one administrative security function to be sent

to an authenticating computer system, wherein said request includes said credential, attempting to authenticate said user using said credential,

if said user is authenticated, retrieving said at least one administrative security function, sending said at least one administrative security function to said local client for routing into said security token, and performing said at least one administrative function on the security token, and

ending the attempt to perform said at least one administrative function on the security token if said user authentication fails.

20. The method according to claim 19 further including the step of authenticating said authenticating computer system to said client.

21. The method according to claim 19 wherein said authenticating computer system is a locally connected security token.

22. The method according to claim 19 wherein said authenticating computer system is a server.

23. The method according to claim 19 wherein said at least one administrative function is performed on a security token associated with said user.

24. A computer program product embodied in a tangible form readable by a computer system having executable instructions stored thereon for causing the computer system to perform at least one administrative security function between a security token and a remote server using a local client as an intermediary, said executable instructions comprising the actions of:

causing a client application to display at least one administrative security function on a user interface display associated with said local client,

causing said client application to receive said user's request for said at least one administrative security function from a user input device,

causing an credential input by a user in combination with said user's request to perform said at least one administrative security function to be transmitted over a network to said remote server,

causing a server application to receive said request and said credential from said network,

causing said server application to authenticate said user using said credential against a stored reference,

causing said server application to execute said user's request if said user is authenticated,

or causing said server application to end execution if said user is not authenticated.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2014
From: ACTIVIDENTITY EUROPE S.A.
To: ASSA ABLOY AB
Reel/Frame 032403/0956 →
CHANGE OF NAME Recorded Nov 19, 2013
From: ACTIVCARD S.A.
To: ACTIVIDENTITY EUROPE SA
Reel/Frame 031674/0407 →
ATTESTATION OF FULL LEGAL NAME OF ENTITY Recorded Oct 31, 2013
From: ACTIVCARD
To: ACTIVCARD S.A.
Reel/Frame 031520/0232 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2012
From: BAND, JAMIE
To: ACTIVCARD
Reel/Frame 028328/0844 →
Continuity (2)
Continuation 10304958 · Nov 27, 2002
Related Publication 20120124657A1 · May 17, 2012