IP Library Granted Patent US 6,985,583
Granted Patent B1
US 6,985,583 · App. 09/304,775 · Granted Jan 10, 2006

System and method for authentication seed distribution

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,985,583
App. No.
09/304,775
Granted
Jan 10, 2006
Kind
B1
Abstract

In one embodiment of a user authentication system and method according to the invention, a device shares a secret, referred to as a master seed, with a server. The device and the server both derive one or more secrets, referred to as verifier seeds, from the master seed, using a key derivation function. The server shares a verifier seed with one or more verifiers. The device, or an entity using the device, can authenticate with one of the verifiers using the appropriate verifier seed. In this way, the device and the verifier can share a secret, the verifier seed for that verifier, without that verifier knowing the master seed, or any other verifier seeds. Thus, the device need only store the one master seed, have access to the information necessary to correctly derive the appropriate seed, and have seed derivation capability. A verifier cannot compromise the master seed, because the verifier does not have access to the master seed.

Claims (61)

1. A method for distributing authentication information associated with a device, comprising the steps of:

generating a master seed associated with the device, and providing the master seed to a verifier seed generator;

deriving, by the verifier seed generator, a verifier seed using the master seed and information associated with a verifier, wherein the verifier seed generator and the verifier are distinct entities, such that the verifier cannot access the master seed; and

transmitting the verifier seed from the verifier seed generator to the verifier.

2. The method of claim 1 , further comprising, after the generating step, the step of transmitting the master seed to the device.

3. The method of claim 1 , further comprising, after the generating step, the step of sharing the master seed with the device and a server.

4. The method of claim 1 , further comprising, after the transmitting step, the steps of:

deriving a second verifier seed using the master seed and information associated with a second verifier; and

transmitting the second verifier seed to the second verifier.

5. The method of claim 1 , further comprising, after the transmitting step, the step of generating an authentication code in response to the verifier seed.

6. The method of claim 5 , wherein the authentication code generating step further comprises generating an authentication code in response to the verifier seed and a time dependent value.

7. The method of claim 5 , further comprising the step of authenticating using the authentication code.

8. The method of claim 7 , wherein the authenticating step comprises authenticating a user or a device by verifying the authentication code.

9. The method of claim 8 wherein the authenticating step comprises transmitting the authentication code to the verifier.

10. The method of claim 1 wherein the master seed generating step comprises at least one of randomly generating and pseudorandomly generating the master seed.

11. The method of claim 1 wherein the deriving step further comprises deriving the verifier seed in response to a time identifier.

12. The method of claim 1 , wherein the deriving step comprises deriving a verifier seed by using the master seed and information associated with a verifier as inputs to a key derivation function.

13. The method of claim 12 wherein the key derivation function comprises a hash function.

14. A system for distributing authentication information associated with a device, comprising:

a master seed generator for generating a master seed associated with a device;

a verifier seed generator for deriving a verifier seed using the master seed and information associated with a verifier, wherein (i) the master seed generator and the verifier are distinct entities, and (ii) the verifier seed generator and the verifier are distinct entities, such that the verifier cannot access the master seed, and

a transmitter for transmitting the verifier seed from the verifier seed generator to the verifier.

15. The system of claim 14 , further comprising a transmitter for transmitting the master seed to the device.

16. The system of claim 14 , further comprising a communication channel for sharing the master seed with the device and the verifier seed generator.

17. The system of claim 14 , wherein the verifier seed generator derives a second verifier seed using the master seed and information associated with a second verifier, and wherein the transmitter transmits the second verifier seed to the second verifier.

18. The system of claim 14 , further comprising an authentication code generator for generating an authentication code in response to the verifier seed.

19. The system of claim 14 , further comprising an authentication code generator for generating an authentication code in response to the verifier seed and a time dependent value.

20. The system of claim 14 , wherein the master seed generator comprises at least one of a random and pseudorandom generator.

21. The system of claim 14 , wherein the verifier seed generator comprises a key derivation function.

22. A method for authentication, comprising:

storing a master seed associated with a device;

deriving a verifier seed using the master seed and information associated with a verifier;

isolating the master seed from the verifier such that the verifier cannot access the master seed; and

generating an authentication code in response to the verifier seed.

23. The method of claim 22 , further comprising the step of authenticating a user with the authentication code.

24. The method of claim 23 , further comprising the step of transmitting the authentication code to a verifier.

25. The method of claim 23 , further comprising the step of receiving the authentication code by a verifier.

26. A system for authentication, comprising:

a memory for storing a master seed associated with a device;

a server for deriving a verifier seed using the master seed and information associated with a verifier, wherein the master seed is isolated from the verifier such that the verifier cannot access the master seed; and

an authentication code generator for generating an authentication code in response to the verifier seed, wherein the verifier includes the authentication code generator.

27. A verifier for authentication, comprising:

a data store for storing a verifier seed, the verifier seed derived from a master seed associated with a device in response to information associated with the verifier, wherein the master seed is isolated from the verifier such that the verifier cannot access the master seed;

an input for receiving an input authentication code; and

an authenticator for determining whether the input authentication code was correctly generated in response to the verifier seed.

28. A token, comprising:

a data store for storing a master seed;

a key derivation function for deriving a verifier seed from a master seed in response to information associated with a verifier, wherein the master seed is isolated from the verifier such that the verifier cannot access the master seed;

an authentication code generator for generating an authentication code in response to the verifier seed; and

an output for providing the authentication code to a verifier.

29. A method for authentication, comprising:

generating a master seed;

sharing the master seed between a token and a server, and isolating the master seed from a verifier such that the verifier cannot access the master seed;

deriving a verifier seed from the master seed in response to information associated with the verifier using a key derivation function; and

transmitting an authentication code responsive to the verifier seed.

30. The method of claim 1 wherein the information associated with the verifier comprises a verifier identifier.

31. The method of claim 4 wherein the information associated with the second verifier comprises a second verifier identifier.

32. The system of claim 14 wherein the information associated with the verifier comprises a verifier identifier.

33. The system of claim 17 wherein the information associated with the second verifier comprises a second verifier identifier.

34. The method of claim 22 wherein the information associated with the verifier comprises a verifier identifier.

35. The method of claim 14 , wherein the master seed generator and the verifier seed generator are incorporated in a server, and wherein the server and the verifier are distinct entities, such that the verifier cannot access the master seed.

Assignments (12)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023975/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023975/0453 →
MERGER Recorded Jan 27, 2010
From: RSA SECURITY INC.
To: RSA SECURITY LLC
Reel/Frame 023852/0500 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023825/0011 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023824/0721 →