IP Library › Granted Patent US 10,284,543
Granted Patent B2
US 10,284,543 · App. 15/237,738 · Granted May 7, 2019

System and method for secure online authentication

Inventors: Dmitry L. Petrovichev (Moscow, RU); Artem O. Baranov (Moscow, RU); Evgeny V. Goncharov (Moscow, RU)
Assignee: AO KASPERSKY LAB
H04L63/0823H04L63/0869H04L63/101H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,284,543
App. No.
15/237,738
Granted
May 7, 2019
Kind
B2
Abstract

Disclosed are systems and methods for secure online authentication. An exemplary method comprises: determining, via a processor of a computing device, a connection being established between a browser application installed on a computer system and a protected website; obtaining information relating to the protected website in response to obtaining a request for authentication from the protected website; establishing a protected data transmission channel with the protected website to receive at least one certificate of the protected website; performing authentication and transmitting authentication data to the protected website; and in response to an indication of a successful authentication from the protected website, transmitting identification information to the browser application for enabling access to the protected website.

Claims (62)

1. A computer-implemented method for secure online authentication, the method comprising:

determining, via a processor of a secure connection device, a connection being established between a browser application installed on a computer system and a protected website, wherein the computer system is distinct from the device;

obtaining, at the device, information relating to the protected website in response to a plugin of the browser application determining that the computer system has obtained a request for authentication from the protected website;

establishing a protected data transmission channel between the device and the protected website to receive, at the device, at least one certificate of the protected website;

receiving a complete tree of certificates, except a root certificate, associated with the protected website from the plugin of the browser application;

verifying validity of the complete tree of certificates based on a list of root certificates stored on the device;

when the validity of the complete tree of certificates is not verified, disconnecting the protected data transmission channel;

responsive to the complete tree being verified, performing authentication and transmitting, from the device, authentication data stored on the device to the protected website; and

in response to an indication of a successful authentication from the protected website, transmitting a new session identifier from the device to the plugin of the browser application for enabling access to the protected website.

2. The computer-implemented method of claim 1 , wherein determining the connection being established between the browser application installed on the computer system and the protected website comprises: obtaining a uniform resource identifier (URI) address of the protected website via an application programming interface (API) provided by the browser application.

3. The computer-implemented method of claim 1 , wherein determining the connection being established between the browser application installed on the computer system and the protected website comprises:

intercepting network traffic between the browser application and the protected website via a driver installed on the device to obtain a uniform resource identifier (URI) address of the protected website.

4. The computer-implemented method of claim 1 , further comprising confirming the protected website against a list of addresses of protected websites accessed by the computer system.

5. The computer-implemented method of claim 4 , further comprising storing, on the device, the list of addresses of protected websites accessed by the computer system and encrypted data relating to the protected websites.

6. The computer-implemented method of claim 1 , wherein the information relating to the protected website comprise: a URL address, information relating to the at least one certificate of the protected website, WHOIS information about a domain of the protected website, a list of headers obtained from a reply to a request at the URL address, information relating to downloaded scripts in the form of convolutions or hash sums.

7. The computer-implemented method of claim 1 , further comprising:

checking a validity of the protected website based on obtained information relating to the protected website, the information comprising obtained headers or list of downloaded scripts when establishing the connection.

8. The computer-implemented method of claim 1 , further comprising:

obtaining a second authentication factor for performing the authentication and transmitting the authentication data to the protected website.

9. The method of claim 8 , further comprising:

storing personal data associated with a user of the computer system on the device; and

establishing the protected data transmission channel upon receiving login form information from the plugin.

10. The method of claim 9 , further comprising:

encrypting and storing payment data on the user accounts and transactions on the device.

11. The method of claim 10 , further comprising:

responsive to obtaining the second factor authentication, decrypting the payment data; and

transmitting the payment data to the protected website.

12. The computer-implemented method of claim 1 , further comprising:

continuing access to the protected website using browser application after transmitting identification information to the browser application for enabling access to the protected website.

13. The method of claim 1 , further comprising:

requesting, by the device, information related to a last virus protection activity of the computer system;

verifying the information received based on a series of rules; and

determining settings of the protected data transmission channel based on the verification.

14. A system for secure online authentication, comprising:

at least one processor of a secure data transmission device configured to:

determine a connection being established between a browser application installed on a computer system and a protected website, wherein the computer system is distinct from the device;

obtain information relating to the protected website in response to a plugin of the browser application determining that the computer system has obtained a request for authentication from the protected website;

establish a protected data transmission channel between the device and the protected website to receive at least one certificate of the protected website;

receiving a complete tree of certificates, except a root certificate, associated with the protected website from the plugin of the browser application;

verify validity of the complete tree of certificates based on a list of root certificates stored on the device;

when the validity of the complete tree of certificates is not verified, disconnect the protected data transmission channel;

responsive to the complete tree being verified, perform authentication, from the device, and transmit authentication data to the protected website; and

in response to an indication of a successful authentication from the protected website, transmit a new session identifier from the device to the plugin of the browser application for enabling access to the protected website.

15. The system of claim 14 , wherein, to determine the connection being established between the browser application installed on the computer system and the protected website, the processor is configured to:

obtain a uniform resource identifier (URI) address of the protected website via an application programming interface (API) provided by the browser application; or

intercept network traffic between the browser application and the protected website via a driver installed on the device to obtain a uniform resource identifier (URI) address of the protected website.

16. The system of claim 14 , wherein the processor is further configured to:

store a list of addresses of protected websites accessed by the computer system and encrypted data relating to the protected websites; and

confirm the protected website against the list of addresses of protected websites accessed by the computer system.

17. The system of claim 14 , wherein the information relating to the protected website comprise:

a URL address, information relating to the at least one certificate of the protected website, WHOIS information about a domain of the protected website, a list of headers obtained from a reply to a request at the URL address, information relating to downloaded scripts in the form of convolutions or hash sums.

18. The system of claim 14 , wherein the processor is further configured to check a validity of the protected website based on obtained information relating to the protected website, the information comprising obtained headers or list of downloaded scripts when establishing the connection.

19. The system of claim 14 , wherein the processor is further configured to:

continue access to the protected website using browser application after transmitting identification information to the browser application for enabling access to the protected website.

20. A non-transitory computer readable medium storing thereon computer executable instructions for secure online authentication, including instructions for:

determining a connection being established between a browser application installed on a computer system and a protected website;

obtaining information relating to the protected website in response to a plugin of the browser application determining that the computer system has obtained a request for authentication from the protected website;

establishing a protected data transmission channel between a secure data transmission device and the protected website to receive, at the device, at least one certificate of the protected website, wherein the computer system is distinct from the device;

receiving a complete tree of certificates, except a root certificate, associated with the protected website from the plugin of the browser application;

verifying validity of the complete tree of certificates based on a list of root certificates stored on the device;

when the validity of the complete tree of certificates is not verified, disconnecting the protected data transmission channel;

responsive to the complete tree being verified, performing authentication and transmit, from the device, authentication data to the protected website; and in response to an indication of a successful authentication from the protected website, transmitting a new session identifier from the device to the plugin of the browser application for enabling access to the protected website.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2016
From: PETROVICHEV, DMITRY L.; BARANOV, ARTEM O.; GONCHAROV, EVGENY V.
To: AO KASPERSKY LAB
Reel/Frame 039449/0853 →
Priority Claims (1)
RU 2016125283 · Jun 24, 2016 · national
Continuity (1)
Related Publication 20170374057A1 · Dec 28, 2017
Cited By (1)
US 12,238,101