US 7,536,722 B1
Authentication system for two-factor authentication in enrollment and pin unblock
Michael K. Saltz, San Jose, Calif. (US); and Aseem Sharma, Fremont, Calif. (US)
Assigned to Sun Microsystems, Inc., Santa Clara, Calif. (US)
Filed on Mar. 25, 2005, as Appl. No. 11/89,700.
Int. Cl. H04L 9/32 (2006.01)
U.S. Cl. 726—20 22 Claims
OG exemplary drawing
 
1. An authentication system comprising:
a smart access card issued to a user, the smart access card having an authentication credential comprising an authentication certificate and a card unique identifier (CUID), the authentication certificate having a copy of the CUID;
a desktop authentication module in a client computer, the desktop authentication module configured to prevent a user from accessing resources of the client computer;
a card reader interface providing communication between the smart access card and the desktop authentication module; and
an enrollment server for enrolling the smart access card into a server data store, the enrollment server receiving the authentication credential from the desktop authentication module obtained from the smart access card and performing a two factor authentication for the user, the two factor authentication including verifying that the CUID has been issued to the user and that the certificate stored on the smart access card has a valid signature.