Patent · US Expired

Method and apparatus for user authentication

US5724423A · kind A · utility

114Cited by
14References
54Claims
0Family size

Assignee

Inventor

Key dates

Filing dateSep 18, 1995
Grant dateMar 3, 1998
Priority date
Expiry dateSep 18, 2015

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG07F7/1066
  • WIPO fieldControl
  • WIPO sectorInstruments

Abstract

A user authentication service is disclosed which is both highly secure and user friendly. To access a particular service, a user simply enters a personal identification type number (PIN) using a portable terminal device which encodes the PIN. More specifically, a character position of the user's PIN is determined, and a random code having a length selectable at each service transaction by the user is generated. The user's PIN is encrypted using one of plural available, pseudo-randomly encrypting algorithms to provide an encrypted PIN. The encrypted PIN is then combined with the code at the determined position before being transmitted over a communications network. When received, the encoded PIN is decoded using an analogous procedure to determine if the user is authorized. A plurality of security levels are provided with each level having a plurality of encryption algorithms and with each increasing level providing encryption algorithms of increasing complexity and sophistication. A user may also change a current PIN from the portable device easily and securely without having to contact a service center.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.