发明授权
- 专利标题: One time password key ring for mobile computing device
- 专利标题(中): 用于移动计算设备的一次密码密钥环
-
申请号: US12423163申请日: 2009-04-14
-
公开(公告)号: US08230231B2公开(公告)日: 2012-07-24
- 发明人: Trevor William Freeman , Josh Benaloh , K John Biccum , Atul Kumar Shah
- 申请人: Trevor William Freeman , Josh Benaloh , K John Biccum , Atul Kumar Shah
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Corporation
- 当前专利权人: Microsoft Corporation
- 当前专利权人地址: US WA Redmond
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
Single-use character combinations are a secure mechanism for user authentication. Such “one-time passwords” (OTPs) can be generated by a mobile device to which the user otherwise maintains easy access. A key exchange, such as in accordance with the Diffie-Hellman algorithm, can provide both the mobile device and a server with a shared secret from which the OTPs can be generated. The shared secret can be derived from parameters posted on the server and updated periodically, and the mobile device can obtain such parameters from the server before generating an OTP. Such parameters can also specify the type of OTP mechanism to be utilized. A second site can, independently, establish an OTP mechanism with the mobile device. For efficiency, the first server can provide an identity token which provides the mobile device's public key in a trusted manner, enabling more efficient generation of the shared secret with the second server.
公开/授权文献
- US20100262834A1 ONE TIME PASSWORD KEY RING FOR MOBILE COMPUTING DEVICE 公开/授权日:2010-10-14
信息查询