IP Library › Granted Patent US 7,370,199
Granted Patent B2
US 7,370,199 · App. 10/766,060 · Granted May 6, 2008

System and method for n-way authentication in a network

Assignee: Microsoft Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,370,199
App. No.
10/766,060
Granted
May 6, 2008
Kind
B2
Abstract

A method of controlling information exposure in a multiparty transaction includes an originating transaction participant cryptographically encoding all information for each of the transaction participants such that a unique data content and encryption are used for each of the messages destined to the other transaction participants. The cryptographically encoded messages are transmitted to the transaction participants such that each may decrypt their message and respond to a primary transaction participant with status concerning their portion of the transaction. After reception of affirmative status messages from the transaction participants, the primary transaction participant may transmit messages to the responding transaction participants to execute the multiparty transaction. The originating transaction participant may also be provided an indication that the multiparty transaction is executed.

Claims (48)

1. A method of protecting a message having information in a multiparty transaction, the method comprising:

obtaining, in response to a user request, from a primary transaction participant, identities of at least two transaction participants in the multiparty transaction;

obtaining, in response to a user request, cryptographic information corresponding to the at least two transaction participants;

dividing, by a user, the information into segments and placing only a relevant portion of the information which is needed by a particular transaction participant into a segment;

cryptographically encoding the segments using the cryptographic information corresponding to the particular transaction participant;

transmitting the cryptographically encoding segments to one of the transaction participants identified as the primary transaction participant; and

transmitting the cryptographically encoding segments to the at least two transaction participants.

2. The method of claim 1 , wherein obtaining identities of at least two transaction participants comprises acquiring the identities from one of the transaction participants.

3. The method of claim 1 , wherein obtaining cryptographic information comprises acquiring cryptographic information from at least one of a directory and cryptographic identity provider.

4. The method of claim 3 , wherein the cryptographic identity provider is not one of the transaction participants.

5. A method of controlling data content exposure in a multiparty transaction, the method comprising:

obtaining, in response to a user request, from a primary transaction participant, at least two identities of secondary transaction participants to be involved in a multiparty transaction;

obtaining, in response to a user request, cryptographic information for the at least two secondary transaction participants, each secondary transaction participant having unique cryptographic information;

cryptographically encoding a unique portion of the data content for each of the at least two secondary transaction participants such that a unique data content and a unique encryption are used for each secondary transaction participant, the unique portion of the data content selected by the user such that only a relevant portion of the data content which is needed by a particular secondary transaction participant is encoded for that particular secondary transaction participant; and

transmitting the cryptographically encoded information to the at least two secondary transaction participants.

6. The method of claim 5 , wherein transmitting the cryptographically encoded information comprises transmitting the cryptographically encoded information to the primary transaction participant.

7. The method of claim 6 , further comprising:

receiving status from the primary transaction participant concerning a successful examination of data content by one or more of the at least two secondary transaction participants, whereby multiparty transaction status is assessed.

8. The method of claim 5 , further comprising transmitting a message request to act upon the information represented by the data content so as to execute the multiparty transaction.

9. A computer-readable storage medium having computer-executable instructions for performing a method of protecting a message having information in a multiparty transaction, the method comprising:

obtaining, in response to a user request, from a primary transaction participant, identities of at least two transaction participants in the multiparty transaction;

obtaining, in response to a user request, cryptographic information corresponding to the at least two transaction participants;

dividing, by a user, the information into segments and placing only a relevant portion of the information which is needed by a particular transaction participant into a segment;

cryptographically encoding the segments using the cryptographic information corresponding to the particular transaction participant; and

transmitting the cryptographically encoding segments to the at least two transaction participants.

10. The computer-readable storage medium of claim 9 , wherein obtaining identities of at least two transaction participants comprises acquiring the identities from one of the transaction participants.

11. The computer-readable storage medium of claim 9 , wherein obtaining cryptographic information comprises acquiring cryptographic information from at least one of a directory and cryptographic identity provider.

12. A system comprising:

a processor having access to memory, the memory having instructions which, when executed, perform the method of protecting a message having information in a multiparty transaction, the method comprising:

obtaining, in response to a user request, from a primary transaction participant, identities of at least two transaction participants in the multiparty transaction;

obtaining, in response to a user request, cryptographic information corresponding to the at least two transaction participants;

dividing, by a user, the information into segments and placing only a relevant portion of the information which is needed by a particular transaction participant into a segment;

cryptographically encoding the segments using the cryptographic information corresponding to the particular transaction participant;

transmitting the cryptographically encoding segments to one of the transaction participants identified as the primary transaction participant; and

transmitting the cryptographically encoding segments to the at least two transaction participants.

13. The system of claim 12 , wherein the instructions having the method step of obtaining identities of at least two transaction participants comprise acquiring the identities from one of the transaction participants.

14. The system of claim 12 , wherein the instruction having the method step of obtaining cryptographic information comprise acquiring cryptographic information from at least one of a directory and cryptographic identity provider.

15. A system comprising:

a processor having access to memory, the memory having instructions which, when executed, perform the method of controlling data content exposure in a multiparty transaction, the method comprising:

obtaining, in response to a user request, from a primary transaction participant, at least two identities of secondary transaction participants to be involved in a multiparty transaction;

obtaining, in response to a user request, cryptographic information for the at least two secondary transaction participants, each secondary transaction participant having unique cryptographic information;

cryptographically encoding a unique portion of the data content for each of the at least two secondary transaction participants such that a unique data content and a unique encryption are used for each secondary transaction participant, the unique portion of the data content selected by the user such that only a relevant portion of the data content which is needed by a particular secondary transaction participant is encoded for that particular secondary transaction participant; and

transmitting the cryptographically encoded information to the at least two secondary transaction participants.

16. The system of claim 15 , wherein the instructions performing the method step of transmitting the cryptographically encoded information comprise transmitting the cryptographically encoded information to the primary transaction participant.

17. The system of claim 15 , wherein the instructions performing the method further comprise:

receiving status from the primary transaction participant concerning a successful examination of data content by one or more of the at least two secondary transaction participants, whereby multiparty transaction status is assessed.

18. The system of claim 15 , wherein the instructions performing the method step of cryptographically encoding information for the at least two secondary transaction participants comprise encoding a data content that is unique for at least one of the at least two secondary transaction participants.

19. The system method of claim 15 , wherein the instructions performing the method steps further comprise transmitting a message request to act upon the information represented by the data content so as to execute the multiparty transaction.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034541/0477 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2004
From: ADAY, MICHAEL A.; WILLMAN, BRYAN M.; PEINADO, MARCUS; GELLER, ALAN S.
To: MICROSOFT CORPORATION
Reel/Frame 015160/0475 →
Continuity (1)
Related Publication 20050204128A1 · Sep 15, 2005