Invention Grant
- Patent Title: Cryptographic binding of authentication schemes
- Patent Title (中): 验证方案的加密绑定
-
Application No.: US11943783Application Date: 2007-11-21
-
Publication No.: US07793340B2Publication Date: 2010-09-07
- Inventor: W. Scott Kiester , Cameron Mashayekhi , Karl E. Ford
- Applicant: W. Scott Kiester , Cameron Mashayekhi , Karl E. Ford
- Applicant Address: US UT Provo
- Assignee: Novell, Inc.
- Current Assignee: Novell, Inc.
- Current Assignee Address: US UT Provo
- Agency: King & Schickli, PLLC
- Main IPC: H04L9/32
- IPC: H04L9/32 ; G06F7/04 ; G06F15/16 ; G06F12/14

Abstract:
Methods and apparatus cryptographically bind authentication schemes to verify that a secure authentication sequence was executed for access to sensitive applications/resources. Users execute two login sequences with a strong authentication framework. Upon completion of the first, the framework generates an unencrypted token from underlying data, later hashed into an authentication token. With a private key corresponding to the first sequence, the authentication token is encrypted and passed to the second sequence where it is encrypted again with a private key corresponding to the second sequence. Upon access attempts to the sensitive applications/resources, verification of execution of the two login sequences includes recovering the authentication token from its twice encrypted form and comparing it to a comparison token independently generated by the application/resource via the underlying data. An audit log associated with the application/resource stores the data, the recovered authentication token, etc., for purposes of later non-repudiation.
Public/Granted literature
- US20090132828A1 CRYPTOGRAPHIC BINDING OF AUTHENTICATION SCHEMES Public/Granted day:2009-05-21
Information query