IP Library Granted Patent US 9,166,971
Granted Patent B1
US 9,166,971 · App. 14/274,652 · Granted Oct 20, 2015

Authentication using an external device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,166,971
App. No.
14/274,652
Granted
Oct 20, 2015
Kind
B1
Abstract

In some embodiments, techniques for computer security comprise receiving request data, wherein the request data includes identity-related information relating to a provider of the request data and information relating to an input specification; requesting authentication from a second computing device via a network, wherein requesting the authentication includes transmitting the information related to the provider of the request data and the information relating to the input specification; and receiving authentication data from the second computing device, wherein the authentication data is associated with the input specification, wherein the authentication data is encrypted, and wherein a key used for the encryption is associated with the identity-related information.

Claims (31)

1. A method, comprising:

receiving request data, wherein the request data includes identity-related information relating to a provider of the request data and information relating to an input specification;

at a computing device, requesting authentication from a second computing device via a network, wherein requesting the authentication includes transmitting the information related to the provider of the request data and the information relating to the input specification; and

receiving authentication data from the second computing device, wherein the authentication data is associated with the input specification, wherein the authentication data is encrypted, and wherein a key used for the encryption is associated with the identity-related information.

2. The method of claim 1 , wherein the second computing device is a cell phone.

3. The method of claim 1 , wherein the network is a wireless network.

4. The method of claim 1 , wherein the key is a public key, and wherein the authentication data is encrypted with public-key encryption using said key.

5. The method of claim 1 , wherein the key is a public key, and wherein the authentication data is encrypted with symmetric encryption using a second key, wherein the second key is encrypted with public-key encryption using the key, and wherein the encrypted second key is received with the authentication data.

6. The method of claim 1 , wherein the identity-related information is associated with a cryptographically signed certificate.

7. The method of claim 1 , wherein the input specification includes HTML.

8. The method of claim 1 , wherein the input specification includes a parameter relating to an input field.

9. The method of claim 1 , wherein the input specification includes a specification of use of a biometric sensor associated with the second computing device.

10. The method of claim 1 , wherein the second computing device displays a prompt to the user and receives the authentication from the user.

11. A system, comprising:

a processor configured to:

receive request data, wherein the request data includes identity-related information relating to a provider of the request data and information relating to an input specification;

request authentication from a second computing device via a network, wherein requesting the authentication includes transmitting the information related to the provider of the request data and the information relating to the input specification; and

receive authentication data from the second computing device, wherein the authentication data is associated with the input specification, wherein the authentication data is encrypted, and wherein a key used for the encryption is associated with the identity-related information; and

a memory coupled with the processor, wherein the memory provides instructions to the processor.

12. The system of claim 11 , wherein the identity-related information is associated with a cryptographically signed certificate.

13. The system of claim 11 , wherein the input specification includes a parameter relating to an input field.

14. The system of claim 11 , wherein the input specification includes a specification of use of a biometric sensor associated with the second computing device.

15. The system of claim 11 , wherein the second computing device displays a prompt to the user and receives the authentication from the user.

16. A computer program product, said computer program product being embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving request data, wherein the request data includes identity-related information relating to a provider of the request data and information relating to an input specification;

at a computing device, requesting authentication from a second computing device via a network, wherein requesting the authentication includes transmitting the information related to the provider of the request data and the information relating to the input specification; and

receiving authentication data from the second computing device, wherein the authentication data is associated with the input specification, wherein the authentication data is encrypted, and wherein a key used for the encryption is associated with the identity-related information.

17. The computer program product of claim 16 , wherein the identity-related information is associated with a cryptographically signed certificate.

18. The computer program product of claim 16 , wherein the input specification includes a parameter relating to an input field.

19. The computer program product of claim 16 , wherein the input specification includes a specification of use of a biometric sensor associated with the second computing device.

20. The computer program product of claim 16 , wherein the second computing device displays a prompt to the user and receives the authentication from the user.