IP Library Granted Patent US 9,736,149
Granted Patent B2
US 9,736,149 · App. 15/168,850 · Granted Aug 15, 2017

Method and system for establishing trusted communication using a security device

Inventors: Nicolas Johannes Sebastian Bettenburg (Ottawa, CA); Randy Kuang (Ottawa, CA)
Assignee: INBAY TECHNOLOGIES INC.
H04L63/083G06F17/30879G06F21/34G06F21/36G06F21/42G06K7/1417H04L63/0428H04L63/0838H04L63/0853H04L63/0869H04L63/0281H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,736,149
App. No.
15/168,850
Granted
Aug 15, 2017
Kind
B2
Abstract

Methods and systems for authenticating a security device for establishing trusted email communication. The security device is authenticated by installing private security software on the security device. In order to authorize an email transaction, a transaction authorization is performed using the security device by display a QR (Quick Response) code from an authorization server on a user terminal and scanning the QR code into the security device. After scanning the QR code, an OTA (One-Time-Authorization) code is sent from the security device to the authorization server for verifying the transaction. Embodiments of the present invention provide trusted email communication. A corresponding system for authenticating a security device and preforming trusted email communication is also provided.

Claims (78)

1. A method for providing a secure access from a security device at a local network location to a remote network application, the method comprising:

at the security device, having a global unique identifier (UID), a processor, and a memory:

obtaining, from a remote network location, a private security software, and causing the private security software to obtain a user selectable personal identification number (PIN), and the UID of the security device, the UID uniquely identifying the security device;

forwarding the PIN, the UID and the private security software to the remote network location for generating a user-personalized credential code using the PIN, the UID and the private security software, comprising encrypting the user-personalized credential code;

at the security device, obtaining the user-personalized credential code from the remote network location, and verifying an authenticity of the user selectable PIN and the UID, without communicating over a network, comprising decrypting the user-personalized credential code;

retrieving access credentials to the remote network application upon verifying the authenticity of the user selectable PIN and the UID; and

authorizing access to the remote network application using the retrieved access credentials.

2. The method of claim 1 wherein the authorizing access to the remote network application comprises:

sending a request for a QR (Quick Response) code from a transaction server to an authorization server at the remote network location;

sending the QR code from the authorization server to the transaction server;

sending the QR code to a user terminal from the transaction server and displaying the QR code on the user terminal; and

scanning the QR code into the security device using a QR code scanner in the security device.

3. The method of claim 1 wherein the authorizing access to the remote network application comprises authorizing access to a sending server.

4. The method of claim 3 wherein the authorizing access to the remote network application comprises authorizing access to an email sending server.

5. The method of 3 further comprising:

authorizing access of a user to a client application using the security device;

adding an identity token to a message;

sending the message from the client application to the sending server;

verifying the message at the sending server using the identity token within the message;

sending the message from the sending server to a receiving server; and

verifying the message at the receiving server using the identity token within the message.

6. The method of claim 5 wherein the authorizing access of the user to the client application comprises:

presenting a challenge to the user by the client application;

receiving the challenge by the user using the security device;

generating a response to the challenge; and

verifying an identity of the user based on the response.

7. The method of claim 5 wherein the adding the identity token to the message comprises calculating a hash of a body of the message.

8. The method of claim 5 wherein the verifying the message at the sending server comprises:

checking for a presence of the identity token in the message;

verifying the identity of the user based on the identity token in the message;

adding to the message an indication that verifying the message has been carried out; and

adding to the message an indication of a status of the verifying of the message.

9. The method of claim 5 wherein the verifying the message at the receiving server comprises:

checking for a presence of the identity token in the message;

verifying the identity of the user based on the identity token in the message;

adding to the message an indication that verifying the message has been carried out; and

adding to the message an indication of a status of the verifying of the message.

10. The method of claim 5 further comprising

sending the message from the receiving server to a receiver, provided the verifying of the message at the receiving server is successful.

11. A system for providing a secure access from a security device at a local network location to a remote network application, the system comprising:

a remote server computer at the remote network location; and

a security device at the local network location, the security device having a global unique identifier (UID), a processor, and a memory having computer readable instructions stored thereon, causing the processor to:

obtain, from a remote network location, a private security software, and causing the private security software to obtain a user selectable personal identification number (PIN), and the UID of the security device, the UID uniquely identifying the security device;

forward the PIN, the UID and the private security software to the remote network location for generating a user-personalized credential code using the PIN, the UID and the private security software, comprising encrypting the user-personalized credential code;

obtain, at the security device, the user-personalized credential code from the remote network location, and verifying an authenticity of the user selectable PIN and the UID, without communicating over a network, comprising decrypting the user-personalized credential code;

retrieve access credentials to the remote network application upon verifying the authenticity of the user selectable PIN and the UID; and

authorize access to the remote network application using the retrieved access credentials.

12. The system of claim 11 wherein the computer readable instructions further cause the processor to:

send a request for a QR (Quick Response) code from a transaction server to an authorization server at the remote network location;

send the QR code from the authorization server to the transaction server;

send the QR code to a user terminal from the transaction server and displaying the QR code on the user terminal; and

scan the QR code into the security device using a QR code scanner in the security device.

13. The system of claim 11 wherein the computer readable instructions that cause the processor to the authorize access to the remote network application further cause the processor to authorize access to a sending server.

14. The system of claim 13 wherein the computer readable instructions that cause the processor to authorize access to the remote network application further cause the processor to authorize access to an email sending server.

15. The system of 13 wherein the computer readable instructions further cause the processor to:

authorize access of a user to a client application using the security device;

add an identity token to a message;

send the message from the client application to the sending server;

verify the message at the sending server using the identity token within the message;

send the message from the sending server to a receiving server; and

verify the message at the receiving server using the identity token within the message.

16. The system of claim 15 wherein the computer readable instructions that cause the processor to authorize access of the user to the client application further cause the processor to:

present a challenge to the user by the client application;

receive the challenge by the user using the security device;

generate a response to the challenge; and

verify an identity of the user based on the response.

17. The system of claim 15 wherein the computer readable instructions that cause the processor to add the identity token to the message further cause the processor to calculate a hash of a body of the message.

18. The system of claim 15 wherein the computer readable instructions that cause the processor to verify the message at the sending server further cause the processor to:

check for a presence of the identity token in the message;

verify the identity of the user based on the identity token in the message;

add to the message an indication that verifying the message has been carried out; and

add to the message an indication of a status of the verifying of the message.

19. The system of claim 15 wherein the computer readable instructions that cause the processor to verify the message at the receiving server further cause the processor to:

check for a presence of the identity token in the message;

verify the identity of the user based on the identity token in the message;

add to the message an indication that verifying the message has been carried out; and

add to the message an indication of a status of the verifying of the message.

20. The system of claim 15 wherein the computer readable instructions further cause the processor to send the message from the receiving server to a receiver, provided the message is successfully verified at the receiving server.

Assignments (2)
CHANGE OF COMPANY ADDRESS Recorded Apr 20, 2018
From: INBAY TECHNOLOGIES INC.
To: INBAY TECHNOLOGIES INC.
Reel/Frame 045986/0975 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2016
From: BETTENBURG, NICOLAS JOHANNES SEBASTIAN; KUANG, RANDY
To: INBAY TECHNOLOGIES INC.
Reel/Frame 038858/0245 →
Continuity (18)
Continuation In Part 14722002 · May 26, 2015
Continuation In Part 14721996 · May 26, 2015
Continuation In Part 13913399 · Jun 8, 2013
Continuation 13035830 · Feb 25, 2011
Continuation In Part 12639464 · Dec 16, 2009
Continuation In Part 14309369 · Jun 19, 2014
Continuation In Part 14231545 · Mar 31, 2014
Continuation 13765049 · Feb 12, 2013
Provisional Application 62168905 · May 31, 2015
Provisional Application 62003160 · May 27, 2014
Provisional Application 61416270 · Nov 22, 2010
Provisional Application 61149501 · Feb 3, 2009
Provisional Application 61183830 · Jun 3, 2009
Provisional Application 61247223 · Sep 30, 2009
Provisional Application 61248047 · Oct 2, 2009
Provisional Application 61839218 · Jun 25, 2013
Provisional Application 61599556 · Feb 16, 2012
Related Publication 20170019396A1 · Jan 19, 2017