IP Library Granted Patent US 8,769,289
Granted Patent B1
US 8,769,289 · App. 13/617,159 · Granted Jul 1, 2014

Authentication of a user accessing a protected resource using multi-channel protocol

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,769,289
App. No.
13/617,159
Granted
Jul 1, 2014
Kind
B1
Abstract

A user accessing a protected resource is authenticated using multiple channels, including a mobile device of the user. A user attempting to access a protected resource is authenticated by receiving a request from a mobile device of the user to access the protected resource; receiving a public key from the mobile device of the user; providing a provision token to the mobile device, wherein the provision token is used by the user to access the protected resource using a second device; and confirming the provision token to a provider of the protected resource to authorize the user to access the protected resource. The user then communicates with the provider using a second device to authorize the provisioning token. A transaction signing protocol is also provided.

Claims (46)

1. A method for authentication of a user attempting to access a protected resource, comprising:

receiving a request from a mobile device of said user to access said protected resource;

receiving a public key from said mobile device of said user;

providing a provision token to said mobile device, wherein said provision token is used by said user to access said protected resource using a second device;

confirming said provision token to a provider of said protected resource to authorize said user to access said protected resource;

receiving encoded transaction data from a provider of said protected resource, wherein said transaction data is encoded using a private key of said provider and a public key of said user;

providing said encoded transaction data to a mobile device of said user, wherein said mobile device decodes said encoded transaction data using a public key of said provider and a private key of said user;

receiving from a second device of said user a signed concatenation of said transaction data and a personal identification number of said user; and

providing confirmation to one or more of said user and said provider that said signed concatenation is for said transaction data received from said provider and is signed by said user of said mobile device.

2. The method of claim 1 , wherein said concatenation of said transaction data and said personal identification number of said user is signed using said private key of said user.

3. The method of claim 1 , wherein said user communicates with said provider using a second device to authorize said provisioning token.

4. The method of claim 1 , further comprising the step of said provider authenticating said user.

5. A tangible machine-readable recordable storage medium for authentication of a user attempting to access a protected resource, wherein the one or more software programs when executed by one or more processing devices implement the steps of the method of claim 1 .

6. A method for authentication of a user performing a transaction with a protected resource, comprising:

receiving encoded transaction data from a provider of said protected resource, wherein said transaction data is encoded using a private key of said provider and a public key of said user;

providing said encoded transaction data to a mobile device of said user, wherein said mobile device decodes said encoded transaction data using a public key of said provider and a private key of said user;

receiving from a second device of said user a signed concatenation of said transaction data and a personal identification number of said user; and

providing confirmation to one or more of said user and said provider that said signed concatenation is for said transaction data received from said provider and is signed by said user of said mobile device.

7. The method of claim 6 , wherein said concatenation of said transaction data and said personal identification number of said user is signed using said private key of said user.

8. The method of claim 7 , wherein said signed concatenation is further signed using said public key of said provider.

9. The method of claim 6 , further comprising the step of receiving a public key from said mobile device of said user.

10. A tangible machine-readable recordable storage medium for authentication of a user performing a transaction with a protected resource, wherein the one or more software programs when executed by one or more processing devices implement the steps of the method of claim 6 .

11. An apparatus for authentication of a user performing a transaction with a protected resource, comprising:

a memory; and

at least one hardware device, coupled to the memory, operative to implement the following steps:

receive a request from a mobile device of said user to access said protected resource;

receive a public key from said mobile device of said user;

provide a provision token to said mobile device, wherein said provision token is used by said user to access said protected resource using a second device;

confirm said provision token to a provider of said protected resource to authorize said user to access said protected resource;

receive encoded transaction data from a provider of said protected resource, wherein said transaction data is encoded using a private key of said provider and a public key of said user;

provide said encoded transaction data to a mobile device of said user, wherein said mobile device decodes said encoded transaction data using a public key of said provider and a private key of said user;

receive from a second device of said user a signed concatenation of said transaction data and a personal identification number of said user; and

provide confirmation to one or more of said user and said provider that said signed concatenation is for said transaction data received from said provider and is signed by said user of said mobile device.

12. The apparatus of claim 11 , wherein said concatenation of said transaction data and said personal identification number of said user is signed using said private key of said user.

13. The apparatus of claim 11 , wherein said user communicates with said provider using a second device to authorize said provisioning token.

14. The apparatus of claim 11 , wherein said provider authenticates said user.

15. An apparatus for authentication of a user attempting to access a protected resource, comprising:

a memory; and

at least one hardware device, coupled to the memory, operative to implement the following steps:

receive encoded transaction data from a provider of said protected resource, wherein said transaction data is encoded using a private key of said provider and a public key of said user;

provide said encoded transaction data to a mobile device of said user, wherein said mobile device decodes said encoded transaction data using a public key of said provider and a private key of said user;

receive from a second device of said user a signed concatenation of said transaction data and a personal identification number of said user; and

provide confirmation to one or more of said user and said provider that said signed concatenation is for said transaction data received from said provider and is signed by said user of said mobile device.

16. The apparatus of claim 15 , wherein said concatenation of said transaction data and said personal identification number of said user is signed using said private key of said user.

17. The apparatus of claim 16 , wherein said signed concatenation is further signed using said public key of said provider.

18. The apparatus of claim 15 , wherein said at least one hardware device is further configured to receive a public key from said mobile device of said user.

Assignments (22)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2012
From: KRONROD, BORIS
To: EMC CORPORATION
Reel/Frame 029384/0878 →