IP Library › Granted Patent US 8,302,172
Granted Patent B2
US 8,302,172 · App. 13/296,347 · Granted Oct 30, 2012

Methods and systems for secure authentication of a user by a host system

Assignee: Citibank Development Center, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,302,172
App. No.
13/296,347
Granted
Oct 30, 2012
Kind
B2
Abstract

A method and system for securely logging onto a banking system authentication server so that a user credential never appears in the clear during interaction with the system in which a user's credential is DES encrypted, and the DES key is PKI encrypted with the public key of an application server by an encryption applet before being transmitted to the application server. Within the HSM of the application server, the HSM decrypts and re-encrypts the credential under a new DES key known to the authentication server, the re-encrypted credential is forwarded to the authentication server, decrypted with the new DES key known to the authentication server, and verified by the authentication server.

Claims (28)

1. A method for allowing a user to securely log on to a host system via an electronic interface, comprising:

receiving, at a processor of an application server computer, a user's credentials encrypted with a symmetric key and the symmetric key and a replay prevention ID encrypted with a public key of a public/private key pair of the application server computer from a browser application on a user's computing device via a processor of a web server computer, and passing, using the processor of the application server computer, the symmetric key-encrypted user's credentials and the public key-encrypted symmetric key and replay prevention ID into a tamper-proof physical hardware security module of the application server computer;

decrypting, using a microprocessor of the tamper-proof physical hardware security module, internally within the tamper-proof physical hardware security module, the public key-encrypted symmetric key and replay prevention ID with the private key of the public/private key pair, and decrypting, using the microprocessor of the tamper-proof physical hardware security module, internally within the tamper-proof physical hardware security module, the symmetric key-encrypted user's credentials with the decrypted symmetric key;

re-encrypting, using the microprocessor of the tamper-proof physical hardware security module, internally within the tamper-proof physical hardware security module, the decrypted user's credentials with a new symmetric key, and passing, using the microprocessor of the tamper-proof physical hardware security module, the re-encrypted user's credentials and decrypted replay prevention ID out of the tamper-proof physical hardware security module;

sending, using the processor of the application server computer, the re-encrypted user's credentials to a processor of an authentication server computer for verification; and

decrypting, using the processor of the authentication server computer, the re-encrypted user's credentials with the new symmetric key, and verifying, using the processor of the authentication server computer, the decrypted user's credentials.

2. The method of claim 1 , further comprising sending an encryption applet to the user's browser.

3. The method of claim 2 , wherein sending the encryption applet to the user's browser further comprises sending the encryption applet contained in a single class file containing functionality necessary to encrypt the user's credentials.

4. The method of claim 2 , wherein sending the encryption applet to the user's browser further comprises sending an encryption applet sized to be downloaded to the user's browser on each logon.

5. The method of claim 2 , wherein sending the encryption applet to the user's browser further comprises sending an encryption applet that persists on the user's browser for a duration of a current browser session.

6. The method of claim 1 , further comprising sending the public key of the public/private key pair of the application server computer to the user's browser, the private key for which is known by the tamper-proof encryption module.

7. The method of claim 2 , further comprising encrypting the user's credentials with a symmetric key generated by the encryption applet.

8. The method of claim 7 , further comprising generating the symmetric key by the encryption applet based on a random number generated by the encryption applet.

9. The method of claim 2 , further comprising encrypting, using the encryption applet, the user's credentials with a DES key to produce a cipherPIN.

10. The method of claim 9 , further comprising encrypting, using the encryption applet, the DES key with a public key to produce a cipherKey.

11. The method of claim 2 , further comprising encrypting, using the encryption applet, the user's credentials with a symmetric key and encrypting the symmetric key with a public key.

12. The method of claim 1 , wherein receiving the symmetric key-encrypted user's credentials and public key-encrypted symmetric key and replay prevention ID further comprising receiving the symmetric key-encrypted user's credentials and public key-encrypted symmetric key and replay prevention ID by the application server via a portal application.

13. The method of claim 12 , wherein receiving the symmetric key-encrypted user's credentials and public key-encrypted symmetric key and replay prevention ID by the application server via the portal application further comprises encrypting and digitally signing the symmetric key-encrypted user's credentials and the public key-encrypted symmetric key within a single sign-on token and sending the token to the application server by the portal application.

14. The method of claim 13 , wherein receiving the symmetric key-encrypted user's credentials and public key-encrypted symmetric key and replay prevention ID by the application server via the portal application further comprises decrypting the single sign-on token and verifying that the token was received via the portal application as a trusted source.

15. A system for allowing a user to securely log on to a host system via an electronic interface, comprising:

an application server computer having a processor coupled to memory, said application server computer processor being programmed for receiving a user's credentials encrypted with a symmetric key and the symmetric key and a replay prevention ID encrypted with a public key of a public/private key pair from a browser application on a user's computing device via a processor of a web server computer and for passing the symmetric key-encrypted user's credentials and public key-encrypted symmetric key and replay prevention ID into a tamper-proof physical hardware security module of the application server computer;

the tamper-proof physical hardware security module having a microprocessor coupled to memory, said tamper-proof physical hardware security module microprocessor being programmed for:

decrypting, internally within the tamper-proof physical hardware security module, the public key-encrypted symmetric key and replay prevention ID with the private key of the public/private key pair;

decrypting, internally within the tamper-proof physical hardware security module, the symmetric key-encrypted user's credentials with the decrypted symmetric key;

re-encrypting, internally within the tamper-proof physical hardware security module, the decrypted user's credentials with a new symmetric key; and

passing the re-encrypted user's credentials and decrypted replay prevention ID out of the tamper-proof physical hardware security module of the application server computer;

the application server computer processor being further programmed for sending the re-encrypted user's credentials to an authentication server computer for verification; and

the authentication server computer having a processor coupled to memory, said authentication server computer processor being programmed for decrypting the re-encrypted user's credentials with the new symmetric key and for verifying the decrypted user's credentials.

Assignments (3)
MERGER Recorded Dec 19, 2014
From: CITICORP DEVELOPMENT CENTER, INC.
To: CITICORP CREDIT SERVICES, INC. (USA)
Reel/Frame 034557/0889 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TYPOGRAPHICAL ERROR IN ASSIGNEE'S NAME PREVIOUSLY RECORDED AT REEL: 027226 FRAME: 0752. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 25, 2014
From: GRANDCOLAS, MICHAEL; GUZMAN, MARC; YEE, THOMAS; PAREKH, DILIP; CHEN, YONGQIANG
To: CITICORP DEVELOPMENT CENTER, INC.
Reel/Frame 033608/0856 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2011
From: GRANDCOLAS, MICHAEL; GUZMAN, MARC; YEE, THOMAS; PAREKH, DILIP; CHEN, YONGQIANG
To: CITIBANK DEVELOPMENT CENTER, INC.
Reel/Frame 027226/0752 →
Continuity (3)
Continuation 11014127 · Dec 16, 2004
Provisional Application 60530063 · Dec 16, 2003
Related Publication 20120072714A1 · Mar 22, 2012