Patent ReferencesCryptographic communications system and method Apparatus and method for cryptographic identity verification Technique for reducing RSA Crypto variable storage Method and apparatus for enhancing security of communications in a packet-switched data communications system Two-way authentication system between user's smart card and issuer-specific plug-in application modules in multi-issued transaction device Method and apparatus for protecting material on storage media and for transferring material on storage media to various recipients Knowledge based system for document authentication Computer network operating with multilevel hierarchical security with selectable common trust realms and corresponding security protocols One-time logon means and methods for distributed computing systems Method of verifying identification InventorsAssigneeApplicationNo. 831854 filed on 04/02/1997US Classes:380/30, Public key382/115, Personnel identification (e.g., biometrics)382/116, Using a combination of features (e.g., signature and fingerprint)713/185, Using record or token713/186Biometric acquisitionExaminersPrimary: Beausoliel, Robert W. Jr.Assistant: Hamdan, Wasseem H. Attorney, Agent or FirmInternational ClassG06F 011/00AbstractThe invention provides a method and system for simultaneously authenticating a user using two or more factors, such as both a password and a physical token or both a password and biometric information. The user presents a physical token including a storage device to a processor and attempts to log in using a first password; the processor includes a login service which receives the first password, accesses the storage device to transform the first password into a second password, and authenticates the second password using an operating system for the processor. The storage device includes encrypted information regarding the second password which can be relatively easily determined in response to the first password, but which cannot be relatively easily determined without the first password. The system or the storage device may also store information for biometric authentication of the user.Other References
| |