A system for authentication of network users which is operable in multiple
modes, includes a plurality of user network stations and at least one
sponsor network station representing a sponsor. Each network station
represents a user associated with an asymmetric crypto-key having either
a first or second number of private portions, the second number being
greater than the first number. The one or more sponsor network stations
receive authentication requests from the user network stations, determine
the identity of a user associated with each of the received
authentication requests, select from two or more available modes of
operation based upon the determined identity. If operation in one mode is
selected, the sponsor network station signs a particular received
authentication request using one private portion of an asymmetric
crypto-key having a first number of private portions. However, if another
mode is selected, the sponsor network station signs that particular
authentication request using one private portion of an asymmetric
crypto-key having a second number of private portions.