发明名称 One-time rotating key for third-party authentication
摘要 Systems, methods, and computer program products are provided for secure authentication of third-parties accessing a network system (e.g., a website or the like) through an intermediary entity (i.e., a trusted caller). A session token having a predetermined time-out period (i.e., an expiration time) is implemented in conjunction with a rotating key that is generated for each request and response pair associated with each call/interaction between the third-party entity and the network system. In this regard, the third-party entity must authenticate themselves each time they interact (i.e., call-in) into the network system by presenting the assigned session token and rotating key communicated in response to the previous interaction. As such hijacking of the third-party's network session with the network system is prevented by implementing tokens that expire, in unison with, encrypted rotating keys that are valid only until the next third-party call-in/interaction with the network entity.
申请公布号 US8504824(B1) 申请公布日期 2013.08.06
申请号 US201213551337 申请日期 2012.07.17
申请人 ABBOTT ROBERT L.;BANK OF AMERICA CORPORATION 发明人 ABBOTT ROBERT L.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址