IP Library Granted Patent US 9,197,411
Granted Patent B2
US 9,197,411 · App. 13/412,275 · Granted Nov 24, 2015

Protocol and method for client-server mutual authentication using event-based OTP

Inventors: Salah E. Machani (Thornhill, CA); Konstantin Teslenko (Richmond Hill, CA)
Assignee: IMS HEALTH INCORPORATED
H04L9/0863G06Q20/3829G06Q20/401H04L9/3228H04L9/3234H04L9/3242H04L63/0435H04L63/061H04L63/0838H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,197,411
App. No.
13/412,275
Granted
Nov 24, 2015
Kind
B2
Abstract

A method of authenticating and encrypting a client-server communication is provided. Two one-time passwords (OTP 1 and OTP 2 ) are generated from a cryptographic token. An encryption key (K_ENC) and a MAC key (K_MAC) are generated based on OTP 2 . The client data are prepared and protected using K_ENC and K_MAC. A request message is sent from the client to the server, and contains the protected client data, a cryptographic token identifier and OTP 1 . OTP 1 is validated at the server, and OTP 2 is generated at the server upon successful validation. K_ENC and K_MAC are derived from OTP 2 at the server. The request message is processed and result data is generated. The result data is encrypted using K_ENC and a digest is created using K_MAC. The encrypted result data is sent to the client, and is decrypted using K_ENC and the authenticity of the result data is verified using K_MAC.

Claims (26)

1. A method of authenticating and encrypting a client-server communication, comprising steps of:

a) generating a first one-time password (OTP 1 ) and a second one-time password (OTP 2 ) from a cryptographic token;

b) generating an encryption key (K_ENC) and a MAC (Message Authentication Code) key (K_MAC) based on OTP 2 ;

c) preparing and protecting client data using K_ENC and K_MAC;

d) sending a request message from the client to the server, the request message containing the protected client data, a cryptographic token identifier (TID) and OTP 1 ;

e) validating OTP 1 at the server, and generating OTP 2 at the server upon successful validation;

f) deriving K_ENC and K_MAC from OTP 2 at the server;

g) processing the request message and generating result data;

h) encrypting the result data using K_ENC and creating a digest using K_MAC;

i) sending the encrypted result data to the client; and

j) decrypting the result data at the client using K_ENC and verifying the authenticity of the result data using K_MAC.

2. The method of claim 1 , wherein said request message further includes client request data encrypted with K_ENC and the method includes an additional step of decrypting the client request data at the server using K_ENC.

3. The method of claim 2 , wherein said request message further includes MAC data encrypted with K_MAC and the method includes an additional step of authenticating the client request data using K_MAC.

4. The method of claim 1 , wherein the step of validating OTP 1 takes place internally at the server.

5. The method of claim 1 , wherein the step of validating OTP 1 takes place at a validation service external to the server.

6. The method of claim 1 , wherein K_ENC and K_MAC are derived using PKDF2 (Password-Based Key Derivation Function).

7. The method of claim 1 , wherein K_MAC is derived using a SHA-1 (Secure Hash Algorithm) MAC algorithm.

8. The method of claim 1 , wherein OTP 1 and OTP 2 are derived using a HMAC-based (Hashed Message Authentication Code) OTP (One-Time Password) algorithm.

9. A system to authenticate and to encrypt a client-server communication, comprising:

a processor; and

a memory coupled to the processor, the memory comprising a data authentication and encryption protocol executable by the processor, wherein the data authentication and encryption protocol comprises:

a) generating a pair of one-time passwords, OTP 1 and OTP 2 , where OTP 1 is used for user validation and OTP 2 is used for key generation;

b) deriving an encryption key, K_ENC derived from OTP 2 , used to encrypt data; and

c) deriving a MAC key, K_MAC, derived from OTP 2 , used to authenticate encrypted data,

wherein OTP 1 , OTP 2 , K_ENC and K_MAC are derived such that the protocol does not require a public-key infrastructure.

10. The system of claim 9 , wherein K_ENC and K_MAC are derived using PKDF2 (Password-Based Key Derivation Function).

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Jun 15, 2026
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: IMS SOFTWARE SERVICES LTD.; IQVIA INC.; IQVIA RDS INC.; RULES-BASED MEDICINE, INC.
Reel/Frame 075844/0867 →
SECURITY INTEREST Recorded Mar 12, 2026
From: IMS SOFTWARE SERVICES LTD.; IQVIA INC.; IQVIA RDS INC.; RULES-BASED MEDICINE, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 075047/0061 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTIES INADVERTENTLY NOT INCLUDED IN FILING PREVIOUSLY RECORDED AT REEL: 065709 FRAME: 618. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT. Recorded Dec 6, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065790/0781 →
SECURITY INTEREST Recorded Nov 29, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065710/0253 →
SECURITY INTEREST Recorded Nov 29, 2023
From: IQVIA INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065709/0618 →
SECURITY INTEREST Recorded May 24, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 063745/0279 →
CHANGE OF NAME Recorded Oct 9, 2018
From: QUINTILES IMS INCORPORATED
To: IQVIA INC.
Reel/Frame 047207/0276 →
CHANGE OF NAME Recorded Sep 7, 2018
From: IMS HEALTH INCORPORATED
To: QUINTILES IMS INCORPORATED
Reel/Frame 047029/0637 →
SECURITY AGREEMENT Recorded Nov 6, 2013
From: IMS HEALTH INCORPORATED
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031592/0179 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2013
From: DIVERSINET CORP.
To: IMS HEALTH INC.
Reel/Frame 031268/0020 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2013
From: MACHANI, SALAH E.; TESLENKO, KONSTANTIN
To: DIVERSINET CORP.
Reel/Frame 031203/0790 →
Continuity (1)
Related Publication 20120226906A1 · Sep 6, 2012