Three Party Authentication
    12.
    发明申请
    Three Party Authentication 审中-公开
    三方认证

    公开(公告)号:US20080235513A1

    公开(公告)日:2008-09-25

    申请号:US11687966

    申请日:2007-03-19

    Abstract: A trust provider uses established relationships with a client device and a server of an e-commerce merchant or service provider to assure the identity of each to the other. The e-commerce merchant can request an encrypted token from the client. The client may use a trust-provider key to generate the encrypted token. The server then passes the token to the trust provider, who only accepts tokens from known, authenticated entities. The trust provider then verifies the token and returns a response to the server. The response may include a client verification for use by the server and an encrypted server verification that is forwarded by the server to the client. In this fashion, both the server and client may be authenticated without prior knowledge of each other.

    Abstract translation: 信任提供者使用与客户端设备和电子商务商家或服务提供商的服务器建立的关系来确保每个对方的身份。 电子商务商可以从客户端请求加密的令牌。 客户端可以使用信任提供者密钥来生成加密的令牌。 然后,服务器将令牌传递给信任提供者,信任提供者只接受来自已知的身份验证实体的令牌。 然后,信任提供者验证令牌并向服务器返回响应。 响应可能包括客户端验证供服务器使用,以及由服务器转发给客户端的加密服务器验证。 以这种方式,服务器和客户端可以在没有彼此之前的知识的情况下被认证。

Patent Agency Ranking