发明名称 METHOD FOR SECURE USER AND SITE AUTHENTICATION
摘要 The present invention provides a new method of site and user authentication. This is achieved by creating a pop-up window on the user's PC that is in communication with a security server, and where this communication channel is separate from the communication between the user's browser and whichever web site they are at. A legitimate web site embeds code in the web page which communicates to the security server from the user's desktop. The security server checks the legitimacy of the web site and then signals both the web page on the user's browser, as well as the pop-up window to which it has a separate channel. The security server also sends a random image to both the pop-up window and the browser. If user authentication is requested by the web site the user is first authenticated by the security server for instance by out of band authentication. Then the security server computes a one time password based on a secret it shares with the web site and sends it to the pop up window. The user copies this one time password into their browser which sends it to the web site, which can re-compute the one time password to authenticate the user.
申请公布号 US2011179472(A1) 申请公布日期 2011.07.21
申请号 US201113006806 申请日期 2011.01.14
申请人 发明人 GANESAN RAVI
分类号 H04L9/32 主分类号 H04L9/32
代理机构 代理人
主权项
地址