최소 단어 이상 선택하여야 합니다.
최대 10 단어까지만 선택 가능합니다.
다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
NTIS 바로가기다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
DataON 바로가기다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
Edison 바로가기다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
Kafe 바로가기국가/구분 | United States(US) Patent 등록 |
---|---|
국제특허분류(IPC7판) |
|
출원번호 | US-0411576 (2006-04-26) |
등록번호 | US-8583926 (2013-11-12) |
발명자 / 주소 |
|
출원인 / 주소 |
|
대리인 / 주소 |
|
인용정보 | 피인용 횟수 : 10 인용 특허 : 496 |
Embodiments of the invention are directed to a method for providing security against phishing attacks. The method can include receiving a login ID from a client, and providing an encrypted commitment to the client. The method can also include receiving a one-time password (OTP) from the client, and
Embodiments of the invention are directed to a method for providing security against phishing attacks. The method can include receiving a login ID from a client, and providing an encrypted commitment to the client. The method can also include receiving a one-time password (OTP) from the client, and validating the OTP. The method can also include sending a commitment key, to be authenticated by the client, receiving a static password from the client and authenticating the client. Embodiments of the invention are directed to a system for providing security against phishing attacks. The system can include one or more servers configured to receive a login ID from a client, and provide an encrypted commitment to the client. The processors can be configured to receive a one-time password (OTP) from the client, validate the OTP, send a commitment key, to be authenticated by the client, receive a static password from the client and authenticate the client.
1. A method for mutual authentication by a client and a server, the method including the steps of: receiving, by the server, a message from the client requesting a connection with the server;sending, by the server, encrypted commitment information to the client, wherein the commitment information de
1. A method for mutual authentication by a client and a server, the method including the steps of: receiving, by the server, a message from the client requesting a connection with the server;sending, by the server, encrypted commitment information to the client, wherein the commitment information demonstrates that the server can determine a value of a dynamic credential;receiving, by the server, the dynamic credential from the client;validating, by the server, the dynamic credential;sending, by the server, a commitment key to the client;receiving, by the server, after the client authenticates the server using the commitment information and commitment key to confirm that the server determined the value of the dynamic credential prior to receipt of same, a static password from the client; andauthenticating, by the server, the static password. 2. The method of claim 1, comprising, prior to receiving a login ID from the client, sending, to the client, a communication containing a commitment which may be subsequently used to demonstrate knowledge of the value of the dynamic credential. 3. The method of claim 2, further comprising a step of sending, to the client, a communication containing a server url. 4. The method of claim 2, wherein the communication is an e-mail message. 5. The method of claim 1, wherein the OTP is derived from at least the server's name. 6. The method of claim 1, wherein the dynamic credential is formed by at least a distinguished name of the server. 7. A system for mutual authentication by a client and a server, the system comprising a server programmed and configured to perform the steps of: receiving a message from the client requesting a connection with the server;sending an encrypted commitment to the client;receiving a dynamic credential from the client;validating the dynamic credential;sending a commitment key to the client;receiving, after the client authenticates the server using the commitment and commitment key, a static password from the client; andauthenticating the static password. 8. The system of claim 7, the server being further configured for receiving a login ID from the client and sending, to the client, a communication containing a commitment which may be subsequently used to demonstrate knowledge of a value of the dynamic credential. 9. The system of claim 8, the server being further configured for, prior to receiving a login ID from the client, sending, to the client, a communication containing a server url. 10. The system of claim 8, wherein the communication is an e-mail message. 11. The system of claim 7, wherein the dynamic credential is derived from at least the server's name.
Copyright KISTI. All Rights Reserved.
※ AI-Helper는 부적절한 답변을 할 수 있습니다.