Invention Grant
US08099765B2 Methods and systems for remote password reset using an authentication credential managed by a third party
有权
使用由第三方管理的认证凭据进行远程密码重置的方法和系统
- Patent Title: Methods and systems for remote password reset using an authentication credential managed by a third party
- Patent Title (中): 使用由第三方管理的认证凭据进行远程密码重置的方法和系统
-
Application No.: US11448161Application Date: 2006-06-07
-
Publication No.: US08099765B2Publication Date: 2012-01-17
- Inventor: Steven William Parkinson
- Applicant: Steven William Parkinson
- Applicant Address: US NC Raleigh
- Assignee: Red Hat, Inc.
- Current Assignee: Red Hat, Inc.
- Current Assignee Address: US NC Raleigh
- Agency: Lowenstein Sandler PC
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Embodiments of the present invention provide a secure remote password reset capability. In some embodiments, an exemplary method provides a remote reset of a password associated with a token in a computer system having a security server. A token-based authentication process is activated by connecting the token to the security server. A server-based authentication process is initiated in the security server by activating a password reset process in a security client. The server-based authentication process communicates with the token-based authentication process over a secure channel. An authentication credential is managed by a third party agent that supplies a query and the authentication credential as a correct response to the query to the security server. A prompt provided by the password reset process collects the authentication credential and a new password. After the authentication credential is validated mutually authentication is performed between the security server and the token. The token is updated with the new password based on a successful result of the mutual authentication.
Public/Granted literature
Information query