Electrical computers and digital processing systems: support – Multiple computer communication using cryptography – Particular communication authentication technique
Reexamination Certificate
2003-12-11
2008-10-07
Barron, Jr., Gilberto (Department: 2139)
Electrical computers and digital processing systems: support
Multiple computer communication using cryptography
Particular communication authentication technique
C380S030000, C713S171000
Reexamination Certificate
active
07434050
ABSTRACT:
A remote user, two-way authentication and password change protocol that also allows parties to optionally establish a session key which can be used to protect subsequent communication. In a preferred embodiment, a challenge token is generated and exchanged which is a one-time value that includes a random value that changes from session to session. The construction and use of the challenge token avoids transmission of the password or even the transmission of a digest of the password itself. Thus the challenge token does not reveal any information about a secret password or a digest of the password.
REFERENCES:
patent: 6718467 (2004-04-01), Trostle
patent: 6792533 (2004-09-01), Jablon
www.atis.org, definition of Message Authentication Code.
www.ibm.com, definition of nonce.
www.searchsecurity.com, definition of one-time pad.
“Method for Protecting Password Transmission”, Mohammad Peyravian, Published in Computers and Security, vol. 19, No. 5, pp. 466-469, 2000.
“Methods for Protecting Password Transmission”, Peyravian, Zunic, Published in Computers and Security, vol. 19, No. 5, pp. 466-469, 2000.
“Secure Hash Standard”, NIST FIPS PUB 180-2, Aug. 2002.
Diffie et al., “New Directions in Cryptography”, IEEE Transactions on Information Theory, vol. IT-22, No. 6, pp. 644-654, 1976.
Peyravian et al, “Methods for Protecting Password Transmission”, Computers and Security, vol. 19, No. 5, pp. 466-469, 2000.
U.S. Appl. No. 09/549,944, filed Apr. 14, 2000, Peyravian et al., Method and Apparatus for Secure Password Transmission and Password Changes.
Jeffries Clark Debs
Peyravian Mohammad
Barron Jr. Gilberto
Glanzman Gerald H.
International Business Machines - Corporation
Lanuti Carl J.
Wang Harris C
LandOfFree
Efficient method for providing secure remote access does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with Efficient method for providing secure remote access, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Efficient method for providing secure remote access will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-4009044