-
1.
公开(公告)号:US08209744B2
公开(公告)日:2012-06-26
申请号:US12122126
申请日:2008-05-16
IPC: G06F21/00
CPC classification number: H04L63/0869 , G06Q10/02 , H04L63/0838 , H04L63/0853 , H04L63/18 , H04L2463/082
Abstract: Mobile device assisted secure computer network communications embodiments are presented that employ a mobile device (e.g., a mobile phone, personal digital assistant (PDA), and the like) to assist in user authentication. In general, this is accomplished by having a user enter a password into a client computer which is in contact with a server associated with a secure Web site. This password is integrated with a secret value, which is generated in real time by the mobile device. The secret value is bound to both the mobile device's hardware and the secure Web site being accessed, such that it is unique to both. In this way, a different secret value is generated for each secure Web site accessed, and another user cannot impersonate the user and log into a secure Web site unless he or she knows the password and possesses the user's mobile device simultaneously.
Abstract translation: 提出了使用移动设备(例如,移动电话,个人数字助理(PDA)等)的移动设备辅助的安全计算机网络通信实施例来协助用户认证。 一般来说,这是通过使用户将密码输入到与与安全网站相关联的服务器联系的客户端计算机来实现的。 这个密码是与移动设备实时生成的秘密值集成的。 秘密值绑定到移动设备的硬件和被访问的安全网站,这两者都是唯一的。 以这种方式,为所访问的每个安全网站生成不同的秘密值,而另一个用户不能模拟用户并登录到安全网站,除非他或她知道密码并同时拥有用户的移动设备。
-
2.
公开(公告)号:US20090287921A1
公开(公告)日:2009-11-19
申请号:US12122126
申请日:2008-05-16
IPC: H04L9/32
CPC classification number: H04L63/0869 , G06Q10/02 , H04L63/0838 , H04L63/0853 , H04L63/18 , H04L2463/082
Abstract: Mobile device assisted secure computer network communications embodiments are presented that employ a mobile device (e.g., a mobile phone, personal digital assistant (PDA), and the like) to assist in user authentication. In general, this is accomplished by having a user enter a password into a client computer which is in contact with a server associated with a secure Web site. This password is integrated with a secret value, which is generated in real time by the mobile device. The secret value is bound to both the mobile device's hardware and the secure Web site being accessed, such that it is unique to both. In this way, a different secret value is generated for each secure Web site accessed, and another user cannot impersonate the user and log into a secure Web site unless he or she knows the password and possesses the user's mobile device simultaneously.
Abstract translation: 提出了使用移动设备(例如,移动电话,个人数字助理(PDA)等)的移动设备辅助的安全计算机网络通信实施例来协助用户认证。 一般来说,这是通过使用户将密码输入到与与安全网站相关联的服务器联系的客户端计算机来实现的。 这个密码是与移动设备实时生成的秘密值集成的。 秘密值绑定到移动设备的硬件和被访问的安全网站,这两者都是唯一的。 以这种方式,为所访问的每个安全网站生成不同的秘密值,而另一个用户不能模拟用户并登录到安全网站,除非他或她知道密码并同时拥有用户的移动设备。
-