IP Library Granted Patent US 9,843,450
Granted Patent B2
US 9,843,450 · App. 15/668,598 · Granted Dec 12, 2017

System and method to use a cloud-based platform supported by an API to authenticate remote users and to provide PKI- and PMI- based distributed locking of content and distributed unlocking of protected content

Inventors: David W. Kravitz (San Jose, CA); Donald Houston Graham, III (Pasadena, CA); Josselyn L. Boudett (Clearwater, FL); Russell S. Dietz (San Ramon, CA)
Assignee: T-CENTRAL, INC.
H04L9/3263H04L9/0894H04L63/061H04L9/321H04L9/3271H04L63/10H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,843,450
App. No.
15/668,598
Granted
Dec 12, 2017
Kind
B2
Abstract

System and method for authenticating a computer user includes: sending an invitation message from an entity computer to an API for authenticating a user of a user computer; receiving and translating by the API the invitation message and sending the translated invitation message including the first public key to the platform server; sending an invitation response to the API to be translated and sending the translated invitation response to the entity computer; preparing a first message including a link and a unique code by the entity computer and sending the first message to the user computer; registering with the platform server utilizing the link and the unique code, and generating a second public key, by the user computer; receiving a correct answer to the secret from the user computer; receiving the second public key by the platform server; and authenticating the user based on the received correct answer.

Claims (35)

1. A method for authenticating a computer user in a computer network, the computer network including an entity computer, a platform server, a user computer and an application programming interface (API) for communication between the entity computer and the platform server, the method comprising:

sending an invitation message from the entity computer to the API for authenticating an identity of a user of the user computer, the invitation message including a first public key of the entity computer and a secret question with an answer;

receiving and translating by the API the invitation message and sending the translated invitation message including the first public key to the platform server;

preparing an invitation response by the platform server and sending the invitation response to the API;

receiving and translating the invitation response by the API and sending the translated invitation response to the entity computer;

preparing a first message including a link and a unique code by the entity computer and sending the first message to the user computer;

receiving the first message, registering with the platform server utilizing the link and the unique code, and generating a second public key, by the user computer;

sending the secret question to the user computer by the platform server;

receiving a correct answer to the secret from the user computer;

receiving the second public key by the platform server;

authenticating the identity of the user of the user computer based on the received correct answer; and

receiving the first public key from the platform server, by the user computer, after said authentication of the identity of user of the user computer;

preparing a second message by the platform server including the second public key and transmitting the second message to the entity computer via the API; and

establishing a secure communication line between the entity computer and the user computer, utilizing the first public key and the second public key, wherein

said secure communication line is authenticated using a certificate received from a certificate authority.

2. The method of claim 1 , wherein said platform server includes a public key infrastructure system.

3. The method of claim 1 , wherein the user computer utilizes security or cryptographic functions of the platform server to establish the secure communication line.

4. The method of claim 1 , wherein the user computer invokes a digital signature generation key pair and at least one of key establishment key pair, encryption-decryption key pair, or digital signature verification to authenticate the identity of the user of the user computer and establish the secure communication line.

5. The method of claim 1 , further comprising delivering secure content from the entity computer to the user computer.

6. A system for authenticating a computer user in a computer network comprising:

a control computer coupled to the computer network for executing an application programming interface (API);

a user computer coupled to the computer network;

an entity computer coupled to the computer network for sending an invitation message to the API for authenticating an identity of a user of the user computer, the invitation message including a first public key of the entity computer and a secret question with an answer; and

a platform server coupled to the computer network for providing security or public key infrastructure functions, wherein the API receives and translates the invitation message and sends the translated invitation message including the first public key to the platform server, wherein

the platform server prepares an invitation response and sends the invitation response to the API, wherein

the API receives and translates the invitation response and sends the translated invitation response to the entity computer, wherein

the entity computer prepares a first message including a link and a unique code by and sends the first message to the user computer, wherein

the user computer receives the first message, registers with the platform server utilizing the link and the unique code, and generates a second public key, and wherein

the platform server sends the secret question to the user computer and receives a correct answer to the secret and the second public key from the user computer, and authenticates the identity of the user of the user computer based on the received correct answer, wherein

the user computer receives the first public key from the platform server, after said authentication of the identity of user of the user computer, wherein the platform server prepares a second message including the second public key and transmits the second message to the entity computer via the API and establishes a secure communication line between the entity computer and the user computer, utilizing the first public key and the second public key, and wherein

said secure communication line is authenticated using a certificate received from a certificate authority.

7. The system of claim 6 , wherein said platform server includes a public key infrastructure system.

8. The system of claim 6 , wherein the user computer utilizes security or cryptographic functions of the platform server to establish the secure communication line.

9. The system of claim 6 , wherein the user computer invokes a digital signature generation key pair and at least one of key establishment key pair, encryption-decryption key pair, digital signature verification or digital identity token to authenticate the identity of the user of the user computer and establish the secure communication line.

10. The system of claim 6 , wherein the entity computer delivers secure content to the user computer via the established secure communication line.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2017
From: KRAVITZ, DAVID W.; GRAHAM, DONALD H., III; BOUDETT, JOSSELYN L.; DIETZ, RUSSELL S.
To: T-CENTRAL, INC.
Reel/Frame 043250/0301 →
Continuity (15)
Continuation 15409427 · Jan 18, 2017
Continuation 15154864 · May 13, 2016
Continuation 14715588 · May 18, 2015
Continuation In Part 14218897 · Mar 18, 2014
Continuation In Part 13481553 · May 25, 2012
Continuation In Part 13096764 · Apr 28, 2011
Provisional Application 62133371 · Mar 15, 2015
Provisional Application 61994885 · May 17, 2014
Provisional Application 61792927 · Mar 15, 2013
Provisional Application 61650866 · May 23, 2012
Provisional Application 61490952 · May 27, 2011
Provisional Application 61330226 · Apr 30, 2010
Provisional Application 61367576 · Jul 26, 2010
Provisional Application 61416629 · Nov 23, 2010
Related Publication 20170331633A1 · Nov 16, 2017