IP Library Granted Patent US 8,130,961
Granted Patent B2
US 8,130,961 · App. 12/028,232 · Granted Mar 6, 2012

Method and system for client-server mutual authentication using event-based OTP

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,130,961
App. No.
12/028,232
Granted
Mar 6, 2012
Kind
B2
Abstract

The invention comprises a method of authenticating and encrypting a client-server communication, comprising the steps of: a) generating a first one-time password (OTP 1 ) and a second one-time password (OTP 2 ) from a cryptographic token; b) generating an encryption key (K_ENC) and a MAC key (K_MAC) based on OTP 2 ; c) preparing and protecting the client data using K_ENC and K_MAC; d) sending a request message from the client to the server, the request message containing the protected client data, a cryptographic token identifier (TID) and OTP 1 ; e) validating OTP 1 at the server, and generating OTP 2 at the server upon successful validation; f) deriving K_ENC and K_MAC from OTP 2 at the server; g) processing the request message and generating result data h) encrypting the result data using K_ENC and creating a digest using K_MAC; i) sending the encrypted result data to the client; and i) decrypting the result data at the client using K_ENC and verifying the authenticity of the result data using K_MAC.

Claims (25)

1. A method of authenticating and encrypting a client-server communication, comprising:

a) generating, by a hardware client device, a first one-time password (OTP 1 ) and an immediately subsequent to said OTP 1 second one-time password (OTP 2 ) from a cryptographic token;

b) generating an encryption key (K_ENC) and a MAC (Message Authentication Code) key (K_MAC) based on said OTP 2 ;

c) protecting client data by encrypting said client data using said K_ENC and generating a digest of said client data using said K_MAC;

d) sending a request message from the hardware client device to a hardware server computer, the request message containing the protected client data, a cryptographic token identifier (TID) and said OTP 1 ;

e) validating said OTP 1 at the hardware server computer, and regenerating said OTP 2 at the hardware server computer upon successful validation of said OTP 1 ;

f) regenerating said K_ENC and said K_MAC from said OTP 2 at the hardware server computer;

g) decrypting and authenticating the protected client data using said K_ENC and said K_MAC respectively at the hardware server computer;

h) processing the request message and generating result data;

i) encrypting the result data using said K_ENC and creating a digest of said result data using said K_MAC;

j) sending the encrypted result data to the hardware client device; and

k) decrypting the result data at the hardware client device using said K_ENC and verifying the authenticity of the result data using said K_MAC.

2. The method of claim 1 , wherein the step of validating said OTP 1 takes place internally at the hardware server computer.

3. The method of claim 1 , wherein the step of validating said OTP 1 takes place at a validation service external to the hardware server computer.

4. The method of claim 1 , wherein said K_ENC and said K_MAC are derived using PKDF2 (Password-Based Key Derivation Function).

5. The method of claim 1 , wherein said K_MAC is derived using a SHA-1 (Secure Hash Algorithm) MAC algorithm.

6. The method of claim 1 , wherein said OTP 1 and said OTP 2 are derived using a HMAC-based (Hashed Message Authentication Code) OTP (One-Time Password) algorithm.

7. A system for authenticating and encrypting a client-server communication, comprising:

a hardware server computer;

said hardware server computer configured to receive a request message from a client, the request message containing protected client data, a cryptographic identifier token (TID) and a first one-time password (OTP 1 ), said protected client data being encrypted using an encryption key (K_ENC) and having a digest created using a MAC (Message Authentication Code) key (K_MAC), both said K_ENC and said K_MAC being generated from a cryptographic token by said client using an immediately subsequent to said OTP 1 second one-time password (OTP 2 ),

said hardware server computer further configured to validate said OTP 1 and regenerate said OTP 2 upon successful validation of said OTP 1 , regenerate said K_ENC and said K_MAC from said OTP 2 , decrypt and authenticate the protected client data using said K_ENC and said K_MAC respectively, process the request message and generate result data, encrypt the result data using said K_ENC, create a digest of the result data using said K_MAC, and send said encrypted result data to said client.

8. The system of claim 7 , wherein said hardware server computer validates said OTP 1 via an external validation service.

9. The system of claim 7 , wherein said K_ENC and said K_MAC are derived using PKDF2 (Password-Based Key Derivation Function).

10. The system of claim 7 , wherein said K_MAC is derived using a SHA-1 (Secure Hash Algorithm) MAC algorithm.

11. The system of claim 7 , wherein said OTP 1 and said OTP 2 are derived using a HMAC-based (Hashed Message Authentication Code) OTP (One-Time Password) algorithm.

Assignments (10)
SECURITY INTEREST Recorded Mar 12, 2026
From: IMS SOFTWARE SERVICES LTD.; IQVIA INC.; IQVIA RDS INC.; RULES-BASED MEDICINE, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 075047/0061 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTIES INADVERTENTLY NOT INCLUDED IN FILING PREVIOUSLY RECORDED AT REEL: 065709 FRAME: 618. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT. Recorded Dec 6, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065790/0781 →
SECURITY INTEREST Recorded Nov 29, 2023
From: IQVIA INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065709/0618 →
SECURITY INTEREST Recorded Nov 29, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065710/0253 →
SECURITY INTEREST Recorded May 24, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 063745/0279 →
CHANGE OF NAME Recorded Oct 9, 2018
From: QUINTILES IMS INCORPORATED
To: IQVIA INC.
Reel/Frame 047207/0276 →
CHANGE OF NAME Recorded Sep 7, 2018
From: IMS HEALTH INCORPORATED
To: QUINTILES IMS INCORPORATED
Reel/Frame 047029/0637 →
SECURITY AGREEMENT Recorded Nov 6, 2013
From: IMS HEALTH INCORPORATED
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031592/0179 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2013
From: DIVERSINET CORP.
To: IMS HEALTH INC.
Reel/Frame 031268/0020 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 26, 2009
From: MACHANI, SALAH E; TESLENKO, KONSTANTIN
To: DIVERSINET CORP.
Reel/Frame 023573/0494 →