Transparent client authentication

H - Electricity – 04 – L

Patent

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

H04L 9/32 (2006.01) H04L 9/14 (2006.01)

Patent

CA 2740698

A system and method for authenticating a client application to a service. During registration, an application requesting access to a service receives a service identifier, which can be authenticated. The application can generate and send to the service an application-service key, based upon the authenticated identifier and a secret application key, a service-application identifier based upon the authenticated service identifier and an application identifier, and a registration nonce, all of which can be stored at the server. During authentication, the client sends the application-service identifier to the service, which the server can use to lookup the stored registration data. The server sends the registration nonce to the client, which can compute a proof of possession of the service-application key and send to the server. The server can compute its own version of the key, which is compared with the received key for authentication purposes.

Cette invention se rapporte à un système et à un procédé destinés à authentifier une application client auprès d'un service. Au cours d'un enregistrement, une application qui demande à accéder à un service reçoit un identifiant de service qui peut être authentifié. L'application peut générer et envoyer au service une clé de service d'application sur la base de l'identifiant authentifié et d'une clé d'application secrète, un identifiant d'application de service sur la base de l'identifiant de service authentifié et d'un identifiant d'application et un nonce d'enregistrement, tous pouvant être stockés dans le serveur. Au cours d'une authentification, le client envoie l'identifiant de service d'application au service, que le serveur peut utiliser afin de consulter les données d'enregistrement stockées. Le serveur envoie le nonce d'enregistrement au client, qui peut calculer une preuve de possession de la clé d'application de service et l'envoyer au serveur. Le serveur peut calculer sa propre version de la clé, qui est comparée à la clé reçue à des fins d'authentification.

LandOfFree

Say what you really think

Search LandOfFree.com for Canadian inventors and patents. Rate them and share your experience with other people.

Rating

Transparent client authentication does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Transparent client authentication, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Transparent client authentication will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFCA-PAI-O-1973934

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.