Establishing trust according to historical usage of selected hardware
involves providing a usage history for a selected client device; and
extending trust to a selected user based on the user's usage history of
the client device. The usage history is embodied as signed statements
issued by a third party or an authentication server. The issued statement
is stored either on the client device, or on an authentication server.
The usage history is updated every time a user is authenticated from the
selected client device. By combining the usage history with conventional
user authentication, an enhanced trust level is readily established. The
enhanced, hardware-based trust provided by logging on from a trusted
client may eliminate the necessity of requiring secondary authentication
for e-commerce and financial services transactions, and may also be used
to facilitate password recovery and conflict resolution in the case of
stolen passwords.