发明名称 METHOD AND SYSTEM OF PROVIDING AUTHENTICATION OF USER ACCESS TO A COMPUTER RESOURCE VIA A MOBILE DEVICE USING MULTIPLE SEPARATE SECURITY FACTORS
摘要 A method and system of authenticating a computer resource such as an application or data on a mobile device uses a contactless token to provide multi-factor user authentication. User credentials are stored on the token in the form of private keys, and encrypted data and passwords are stored on the device. When application user requires access to the resource an encrypted password is transmitted to and decrypted on the token using a stored private key. An unencrypted data encryption key or password is then transmitted back to the device under the protection of a cryptographic session key which is generated as a result of strong mutual authentication between the device and the token.
申请公布号 US2016005032(A1) 申请公布日期 2016.01.07
申请号 US201514855186 申请日期 2015.09.15
申请人 HOVERKEY LTD. 发明人 YAU ARNOLD;IVES STEVE
分类号 G06Q20/36;G06Q20/32;G06Q20/38;G06Q20/06 主分类号 G06Q20/36
代理机构 代理人
主权项 1. A method of conducting a cryptocurrency payment via a mobile computing device comprising: using the mobile computing device, storing an encrypted wallet received from a portable security token that is separate from the mobile device, wherein the encrypted wallet comprises a cryptocurrency wallet encrypted with a secret key that is restricted to the portable security token; using the mobile computing device, receiving a cryptocurrency payment instruction; using the mobile computing device, prompting for a user credential to approve the cryptocurrency payment instruction; using the mobile computing device, sending, to the portable security token, a message in response to receiving the user credential, wherein the message comprises the encrypted wallet, the cryptocurrency payment instruction, and the user credential; and wherein the sending of the message causes the portable security token to: decrypt, using the secret key, the cryptocurrency wallet from the encrypted wallet; in response to confirming that the user credential matches an authentication identifier registered with the portable security token, create a cryptocurrency payment transaction by digitally signing the cryptocurrency payment instruction using the cryptocurrency wallet; transmit the cryptocurrency payment transaction to a cryptocurrency network; and erase the cryptocurrency wallet.
地址 London GB