IP Library Granted Patent US 7,502,467
Granted Patent B2
US 7,502,467 · App. 11/265,510 · Granted Mar 10, 2009

System and method for authentication seed distribution

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,502,467
App. No.
11/265,510
Granted
Mar 10, 2009
Kind
B2
Abstract

In one embodiment of a user authentication system and method according to the invention, a device shares a secret, referred to as a master seed, with a server. The device and the server both derive one or more secrets, referred to as verifier seeds, from the master seed, using a key derivation function. The server shares a verifier seed with one or more verifiers. The device, or an entity using the device, can authenticate with one of the verifiers using the appropriate verifier seed. In this way, the device and the verifier can share a secret, the verifier seed for that verifier, without that verifier knowing the master seed, or any other verifier seeds. Thus, the device need only store the one master seed, have access to the information necessary to correctly derive the appropriate seed, and have seed derivation capability. A verifier cannot compromise the master seed, because the verifier does not have access to the master seed.

Claims (70)

1. A method for distributing seed information associated with a device, said method comprising:

generating a master seed associated with the device;

deriving a derived seed from the master seed and information associated with a security system; and

sharing with the security system a value that is derived from the derived seed, wherein the security system cannot access the master seed.

2. The method of claim 1 , further comprising sharing the master seed with the device.

3. The method of claim 2 , wherein sharing with the device said information associated with the security system includes entering said information associated with the security system into the device through a key pad.

4. The method of claim 2 , further comprising in the device deriving the derived seed.

5. The method of claim 2 , further comprising storing a static password in the device and using the static password along with the derived seed to perform authentication with the security system.

6. The method of claim 2 , further comprising sharing with the device the information associated with the security system.

7. The method of claim 6 , wherein sharing with the device said information associated with the security system includes programming said information associated with the security system into the device.

8. The method of claim 6 , wherein sharing with the device said information associated with the security system includes entering said information associated with the security system into the device electronically.

9. The method of claim 6 , wherein sharing with the device said information associated with the security system includes entering said information associated with the security system into the device through a key pad.

10. The method of claim 1 , further comprising sharing the master seed with the device and a server.

11. The method of claim 1 , further comprising:

deriving a second derived seed using the master seed and information associated with a second security system; and

sharing the second derived seed with the second security system.

12. The method of claim 1 , further comprising, at the security system, generating an authentication code in response to deriving the derived seed.

13. The method of claim 12 , wherein authentication code generating includes generating the authentication code from the derived seed and a time dependent value.

14. The method of claim 12 , further comprising authenticating using the authentication code.

15. The method of claim 14 , wherein authenticating comprises authenticating a user or a device by verifying the authentication code.

16. The method of claim 15 wherein authenticating further comprises transmitting the authentication code to the security system.

17. The method of claim 12 , wherein authentication code generating includes sending a challenge value to the device and receiving from the device a response which is the challenge encrypted by using the derived seed.

18. The method of claim 1 wherein master seed generating comprises at least one of randomly generating and pseudorandomly generating the master seed.

19. The method of claim 1 wherein deriving comprises deriving the derived seed from a time identifier.

20. The method of claim 1 , wherein deriving comprises deriving the derived seed by using the master seed and information associated with a verifier as inputs to a key derivation function.

21. The method of claim 20 , wherein the key derivation function comprises a hash function.

22. The method of claim 1 , further comprising generating an encryption key from the derived seed.

23. The method of claim 1 , further comprising using the derived seed for encryption.

24. The method of claim 1 , wherein generating the master seed is performed by the device.

25. The method of claim 1 , further comprising:

deriving a plurality of different derived seeds using the master seed and information associated with a plurality of security systems; and

sharing the plurality of derived seeds with the plurality security systems, wherein the first-mentioned security system is one of the plurality of security systems and the first-mentioned derived seed is one of the plurality of derived seeds.

26. The method of claim 1 , wherein sharing said value with the security system includes typing the value into a keypad associated with the security system.

27. The method of claim 1 , wherein sharing said value with the security system includes transmitting over a network.

28. The method of claim 1 , wherein deriving the derived seed includes first deriving an intermediate seed from the master seed and a time identifier and then deriving the derived seed from the intermediate seed and said information associated with the security system.

29. A method of authenticating a device to a security system based on a master seed associated with the device, said method comprising:

deriving a derived seed using the master seed and information associated with the security system;

isolating the master seed from the security system such that the security system cannot access the master seed;

in the security system. generating an authentication code based at least in part on the derived seed;

using the authentication code to authenticate the device; and

storing a static password in the device and using the static password along with the derived seed to perform authentication with the security system.

30. A method comprising:

at a user device, calculating a verifier seed by applying a cryptographic function to a master seed and to a verifier identifier, the master seed being uniquely associated with the user device, the verifier identifier being associated with a security system;

at a host server, the host server storing the master seed associated with the user device and the verifier identifier associated with the security system, calculating the verifier seed by applying the cryptographic function to the master seed and to the verifier identifier;

transmitting the calculated verifier seed from the host server to the security system by a secure mechanism, the security system having no access to the master seed;

transmitting an authentication message from the user device to the security system; and

at the security system, authenticating, based on the received authentication message and the received calculated verifier seed, that the user device is in possession of the verifier seed.

31. A method as in claim 30 wherein the method further comprises:

generating the master seed associated with the user device with one of a random number generator and a pseudorandom number generator;

sharing the generated master seed with the user device and the host server; and

persistently storing the shared master seed in user device and in the host server.

32. A method as in claim 31 wherein generating the master seed is performed by the user device.

33. A method as in claim 30 wherein:

the security system is one security system of a plurality of security systems; and

the verifier identifier is uniquely associated with the security system of the plurality of security systems.

34. A method as in claim 30 wherein calculating the verifier seed, at both the user device and the security system, further includes applying the cryptographic function to a time identifier.

35. A method as in claim 30 wherein transmitting the calculated verifier seed from the host server to the security system by the secure mechanism includes transmitting across a secure channel.

36. A method as in claim 30 wherein transmitting the calculated verifier seed from the host server to the security system by the secure mechanism includes transmitting across a computer network with encryption.

37. A method as in claim 30 wherein transmitting the authentication message from the user device to the security system includes sending the verifier seed from the user device to the security system.

38. A method as in claim 30 wherein transmitting the authentication message from the user device to the security system includes:

at the user device, calculating an authentication code by encrypting a piece of data with the verifier seed as encryption key; and

transmitting the authentication code from the user device to the security system.

39. A method as in claim 38 wherein:

calculating the authentication code by encrypting a piece of data with the verifier seed as encryption key includes encrypting a personal identification code with the verifier seed; and

authenticating, based on the received authentication message and the received calculated verifier seed, that the user device is in possession of the verifier seed includes decrypting the received authentication message with the calculated verifier seed and verifying that the decrypted authentication message encodes a valid personal identification code.

40. A method as in claim 39 wherein the method further comprises, at the user device, receiving the personal identification code through user entry at substantially the same time that a user seeks access to the security system.

41. A method as in claim 39 wherein encrypting the personal identification code with the verifier seed includes retrieving the personal identification code from persistent storage within the user device.

42. A method as in claim 38 wherein:

calculating the authentication code by encrypting a piece of data with the verifier seed as encryption key includes encrypting a time identifier with the verifier seed; and

authenticating, based on the received authentication message and the received calculated verifier seed, that the user device is in possession of the verifier seed includes decrypting the received authentication message with the calculated verifier seed and verifying that the decrypted authentication message encodes a time identifier indicating that the authentication code was generated within a specified time period prior to the decryption.

Assignments (12)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023975/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023975/0453 →
MERGER Recorded Jan 27, 2010
From: RSA SECURITY INC.
To: RSA SECURITY LLC
Reel/Frame 023852/0500 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023825/0011 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023824/0721 →