发明名称 METHOD AND SYSTEM OF PROVIDING AUTHENTICATION OF USER ACCESS TO A COMPUTER RESOURCE VIA A MOBILE DEVICE USING MULTIPLE SEPARATE SECURITY FACTORS
摘要 A method and system of authenticating a computer resource such as an application or data on a mobile device uses a contactless token to provide multi-factor user authentication. User credentials are stored on the token in the form of private keys, and encrypted data and passwords are stored on the device. When an application user requires access to the resource an encrypted password is transmitted to and decrypted on the token using a stored key. An unencrypted data encryption key or password is then transmitted back to the device under the protection of a cryptographic session key which is generated as a result of strong mutual authentication between the device and the token.
申请公布号 US2016261411(A1) 申请公布日期 2016.09.08
申请号 US201615156072 申请日期 2016.05.16
申请人 HOVERKEY LTD. 发明人 YAU ARNOLD;IVES STEVE
分类号 H04L9/32;G06F9/54;H04L9/08;H04L29/06 主分类号 H04L9/32
代理机构 代理人
主权项 1. A method of conducting a cryptocurrency payment via a mobile computing device comprising: using the mobile computing device, storing an encrypted wallet received from a portable security token that is separate from the mobile device, wherein the encrypted wallet comprises a cryptocurrency wallet encrypted with a secret key that is restricted to the portable security token; using the mobile computing device, receiving a cryptocurrency payment instruction; using the mobile computing device, prompting for a user credential to approve the cryptocurrency payment instruction; using the mobile computing device, sending, to the portable security token, a message in response to receiving the user credential, wherein the message comprises the encrypted wallet, the cryptocurrency payment instruction, and the user credential; and wherein the sending of the message causes the portable security token to: decrypt, using the secret key, the cryptocurrency wallet from the encrypted wallet; in response to confirming that the user credential matches an authentication identifier registered with the portable security token, create a cryptocurrency payment transaction by digitally signing the cryptocurrency payment instruction using the cryptocurrency wallet; transmit the cryptocurrency payment transaction to a cryptocurrency network or cryptocurrency bank or exchange; and erase the cryptocurrency wallet; wherein the confirming the user credential matches an authentication identifier registered with the portable security token comprises using any of PIN, biometric or fingerprint on the mobile device, or authentication via button press confirmation, PIN or fingerprint on the portable security token.
地址 London GB