U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

Icon_funbox Did You Know...

...that a workman who left the soap mixing machine on too long was responsible for making Ivory Soap? He was so embarrassed by his mistake that he threw the mess in a stream. Imagine his dismay when the evidence of his error floated to the surface! Result: Ivory soap, the soap that floats.

Newsletter  PatentStorm News

Make the Most of PatentStorm

See this month's Top Inventors and Most Cited Patents.

Stay on top of the latest patents by subscribing to an RSS feed.

Got questions? Ask a Patent Expert!

Registered users: Manage your profile, comments and alerts.

 

US Patent 5604803 - Method and apparatus for secure remote authentication in a public network

US Patent Issued on February 18, 1997
Estimated Patent Expiration Date: Icon_subject June 3, 2014Estimated Expiration Date is calculated based on simple USPTO term provisions. It does not account for terminal disclaimers, term adjustments, failure to pay maintenance fees, or other factors which might affect the term of a patent.
loading...


View Patent Images (PDF)
(Registered users only)

Abstract

A client workstation provides a login address as an anonymous ftp (file transfer protocol) request, and a password as a user's e-mail address. A destination server compares the user's e-mail address provided as a password to a list of authorized users' addresses. If the user's e-mail address is located on the list of authorized users' addresses maintained by the destination server, the destination server generates a random number (X), and encrypts the random number in an ASCII representation using encryption techniques provided by the Internet Privacy Enhanced Mail (PEM) procedures. The encrypted random number is stored in a file as the user's anonymous directory. The server further establishes the encrypted random number as one-time password for the user. The client workstation initiates an ftp request to obtain the encrypted PEM random number as a file transfer (ftp) request from the destination server. The destination server then sends the PEM encrypted password random number, as an ftp file, over the Internet to the client workstation. The client workstation decrypts the PEM encrypted file utilizing the user's private RSA key, in accordance with established PEM decryption techniques. The client workstation then provides the destination server with the decrypted random number password, which is sent in the clear over the Internet, to login to the destination server. Upon receipt of the decrypted random number password, the destination server permits the user to login to the anonymous directory, thereby completing the user authentication procedure and accomplishing login.

Other References

  • Whitfield Diffie, "The First Ten Years of Public-Key Cryptography", (Proceedings of the IEEE, vol. 76, No. 5, May 1988)
  • Paul Fahn, "Answers to Frequently Asked Questions About Today's Cryptography", (RSA Laboratories, 1992)
  • "Part I: Message Encryption and Authentication Procedures", (Privacy Enhancement for Internet Electronic Mail, J. Linn (Network Working Group)
  • "Part II: Certificate-Based Key Management", (Privacy Enhancement for Internet Electronic Mail, S. Kent (Network Working Group)
  • "Part III: Algorithms, Modes, and Identifiers", (Privacy Enhancement for Internet Electronic Mail), D. Balenson (Network Working Group)
  • "Part IV: Key Certification and Related Services" (Privacy Enhancement for Internet Electronic Mail), B. Kaliski (Network Working Group)
  • Whitfield Diffie, Paul C. Van Oorschoot and Michael J. Weiner, "Authentication and Authenticated Key Exchanges" (Designs, Codes and Cryptography, 2-107-125 (1992), Kluwer Academic Publishers)
  • "The MD5 Message-Digest Algorithm", MIT Laboratory for Computer Science and RSA Data Security, Inc. (1992) R. Rivest (Network Working Group)
  • RSA Data Security, Inc. Technology Bulleti

Inventor

Application

No. 253802 filed on 06/03/1994

US Classes:

713/155, Central trusted authority provides computer authentication709/228, Session/connection parameter setting713/152, Application layer security713/162, Having particular address related cryptography713/171Having key exchange

Examiners

Primary: Cangialosi, Salvatore

Attorney, Agent or Firm

US Patent References

4193131, Cryptographic verification of operational keys used in communication networks
Issued on: 03/11/1980
Inventor: Lennon ,   et al.
4349695, Recipient and message authentication method and system
Issued on: 09/14/1982
Inventor: Morgan ,   et al.
4736423, Technique for reducing RSA Crypto variable storage
Issued on: 04/05/1988
Inventor: Matyas
4817140, Software protection system using a single-key cryptosystem, a hardware-based authorization system and a secure coprocessor
Issued on: 03/28/1989
Inventor: Chandra ,   et al.
5056140, Communication security accessing system and process
Issued on: 10/08/1991
Inventor: Kimbell
5109413, Manipulating rights-to-execute in connection with a software copy protection mechanism
Issued on: 04/28/1992
Inventor: Comerford, et al.
5136642, Cryptographic communication method and cryptographic communication device
Issued on: 08/04/1992
Inventor: Kawamura, et al.
5323146, Method for authenticating the user of a data station connected to a computer system
Issued on: 06/21/1994
Inventor: Glaschick
5323465Access control
Issued on: 06/21/1994
Inventor: Avarne

Foreign Patent References

  • 2168831 GB. 11/14/1984

International Class

H04L 009/00

Comments

No comments for this page
 
 
Forgot password?
Register here