会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 3. 发明申请
    • METHODS AND SYSTEMS FOR SECURE USER AUTHENTICATION
    • 确保用户认证的方法和系统
    • US20110197266A1
    • 2011-08-11
    • US13019333
    • 2011-02-02
    • Ronald King-Hang CHUMark KogenWarren TanSimon MaYosif SmushkovichGerry GlindroJeffrey William Coyte Nicholas
    • Ronald King-Hang CHUMark KogenWarren TanSimon MaYosif SmushkovichGerry GlindroJeffrey William Coyte Nicholas
    • H04L9/32
    • H04L9/3228
    • Methods and systems for secure user authentication using a OTP involve, for example, pre-storing a OTP application on a first computing device for generating a valid OTP value for the user responsive to receiving entry of a valid PIN value of the user, no part of the valid PIN value is stored on the first computing device and pre-storing on a back-end server the valid PIN value and a valid shared secret for the user. Upon receiving entry of a purported PIN value of the user, a purported shared secret is dynamically synthesized on the first computing device by the OTP application based on the purported PIN value of the user and a purported OTP value is generated on the first computing device. When entry of the purported OTP value is received by the back-end server in an attempt to log on the back-end server from a second computing device, the back-end server cryptographically calculates a window of OTP values, and log on to the back-end server from the second computing device is allowed if the calculated window of OTP values corresponds to the received OTP value.
    • 用于使用OTP的安全用户认证的方法和系统涉及例如在第一计算设备上预先存储OTP应用,用于响应于接收到用户的有效PIN值的输入而生成用户的有效OTP值, 的有效PIN值存储在第一计算设备上,并且在后端服务器上预存储用户的有效PIN值和有效的共享秘密。 在接收到用户的所声明的PIN值的输入时,基于所声称的用户的PIN值,OTP应用在第一计算设备上动态地合成所声称的共享秘密,并且在第一计算设备上生成所声称的OTP值。 当后端服务器接收到所声称的OTP值的输入以尝试从第二计算设备登录后端服务器时,后端服务器密码地计算OTP值的窗口,并登录到 如果所计算的OTP值的窗口对应于接收到的OTP值,则允许来自第二计算设备的后端服务器。