IP Library Granted Patent US 7,257,708
Granted Patent B2
US 7,257,708 · App. 11/211,838 · Granted Aug 14, 2007

Steganographic authentication

Assignee: Microsoft Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,257,708
App. No.
11/211,838
Granted
Aug 14, 2007
Kind
B2
Abstract

Various embodiments pertain to steganographically authenticating identities and authorizing transactions based on the authenticated identities.

Claims (28)

1. A computer-implemented authentication method comprising:

defining an authentication network having a plurality of authentication paths;

receiving steganographic communication from an identity that is to be authenticated, the steganographic communication having a purpose that appears to be unrelated to authentication;

using the steganographic communication from the identity to follow an authentication path through the authentication network; and

authenticating the identity if the authentication path leads to a valid authentication state for the identity, wherein said acts of receiving, using and authenticating are performed independent of any encryption/decryption procedures.

2. The method of claim 1 , wherein the steganographic communication that is used to follow the authentication path comprises content which is in the clear, and wherein said content is used to follow said authentication path.

3. The method of claim 2 , wherein said content comprises multiple commands.

4. The method of claim 2 , wherein said content comprises multiple commands, at least some of which are not inherently related to authentication.

5. The method of claim 2 , wherein said content comprises multiple commands, at least some of which are data processing or data handling commands and are not inherently related to authentication.

6. The method of claim 2 , wherein said content comprises multiple commands, at least some of which are ISO 7816-4 or ISO 7816-9 data processing or data handling commands and are not inherently related to authentication.

7. A computer-implemented authentication method comprising:

receiving steganographic communication from an identity that is to be authenticated, the steganographic communication comprising content which is in the clear and which appears unrelated to authentication, said steganographic communication also comprising content that is false cryptographic content;

using the content of said steganographic communication to authenticate an identity.

8. The method of claim 7 , wherein said false cryptographic content comprises at least one cryptographic command.

9. The method of claim 7 , wherein said content that is in the clear comprises multiple commands.

10. The method of claim 7 , wherein said content that is in the clear comprises multiple data processing or data handling commands.

11. The method of claim 7 , wherein said content that is in the clear comprises multiple commands, and said act of using is performed by authenticating said identity based on an order of said commands.

12. The method of claim 7 , wherein said content that is in the clear comprises multiple commands, and wherein said commands have an apparent function that is not associated with an authentication function.

13. The method of claim 7 , wherein said false cryptographic content comprises a false cryptographic protocol.

14. One or more computer-readable storage media having computer-readable instructions stored thereon which, when executed, perform a method comprising:

receiving steganographic communication from an identity that is to be authenticated, the steganographic communication comprising content which is in the clear and which appears unrelated to authentication, said steganographic communication also comprising content that is false cryptographic content;

using the content of said steganographic communication to authenticate an identity.

15. The computer-readable media of claim 14 , wherein said false cryptographic content comprises at least one cryptographic command.

16. The computer-readable media of claim 14 , wherein said content that is in the clear comprises multiple commands.

17. The computer-readable media of claim 14 , wherein said content that is in the clear comprises multiple data processing or data handling commands.

18. The computer-readable media of claim 14 , wherein said content that is in the clear comprises multiple commands, and said act of using is performed by authenticating said identity based on an order of said commands.

19. The computer-readable media of claim 14 , wherein said content that is in the clear comprises multiple commands, and wherein said commands have an apparent function that is not associated with an authentication function.

20. The computer-readable media of claim 14 , wherein said false cryptographic content comprises a false cryptographic protocol.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034543/0001 →
Continuity (3)
Continuation 1102174400 · Dec 23, 2004
Continuation 0943454500 · Nov 5, 1999
Related Publication 20050283830A1 · Dec 22, 2005