IP Library Granted Patent US 7,810,147
Granted Patent B2
US 7,810,147 · App. 11/607,836 · Granted Oct 5, 2010

Detecting and preventing replay in authentication systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,810,147
App. No.
11/607,836
Granted
Oct 5, 2010
Kind
B2
Abstract

A system for detecting and preventing replay attacks includes a plurality of interconnected authentication servers, and one or more tokens for generating a one-time passcode and providing the one-time passcode to one of the authentication servers for authentication. The system includes an adjudicator function associated with each authentication server. The adjudicator evaluates a high water mark value associated with a token seeking authentication, allows authentication to proceed for the token if the high water mark evaluation indicates that the one-time passcode was not used in a previous authentication, and prevents authentication if the high water mark evaluation indicates that the one-time passcode was used in a previous authentication. The token is associated with a home authentication server that maintains a current high water mark of the token. The home authentication server validates the current high water mark on behalf of the adjudicator function evaluating the token for authentication.

Claims (68)

1. A system for detecting and preventing replay attacks in an authentication network, comprising:

a plurality of authentication servers interconnected through an authentication network;

one or more tokens for generating a one-time passcode, and for providing the one-time passcode to one of the plurality of authentication servers for authentication;

an adjudicator function associated with each of the plurality of authentication servers, wherein the adjudicator function:

(a) evaluates a high water mark value associated with a token seeking authentication;

(b) allows an authentication procedure to proceed for the token seeking authentication if the high water mark evaluation indicates that the one-time passcode was not used in a previous authentication transaction; and,

(c) prevents authentication of the token seeking authentication if the high water mark evaluation indicates that the one-time passcode was used in a previous authentication transaction;

wherein the token seeking authentication is associated with a home authentication server that maintains a current high water mark value of the token seeking authentication, and wherein the home authentication server validates the current high water mark value on behalf of the adjudicator function evaluating the token seeking authentication;

wherein, when the token seeking authentication seeks authentication from an authentication server of the plurality of authentication servers that is not the home authentication server (non-home authentication server), the system is constructed and arranged to:

(i) forward the high water mark value to the adjudicator function of the non-home authentication server;

(ii) determine, at the adjudicator function of the non-home authentication server, that the high water mark information originating from the token seeking authentication is associated with the home authentication server; and

(iii) in response to determining, send the high water mark value to the adjudicator function of the home authentication server; and

wherein, when the token seeking authentication seeks authentication from the home authentication server, the system is constructed and arranged to:

(i) forward the high water mark value to the adjudicator function of the home authentication server;

(ii) determine, at the adjudicator function of the home authentication server, that the high water mark value originating from the token seeking authentication is associated with the home authentication server; and

(iii) in response to determining, maintain the high water mark value in the adjudicator function of the home authentication server.

2. The system of claim 1 , wherein one of the plurality of authentication servers functions as the home authentication server for all of the one or more tokens in the system.

3. The system of claim 1 , wherein the high water mark value associated with the token seeking authentication includes information regarding a most recent time the token authenticated to one of the plurality of authentication servers.

4. The system of claim 1 , wherein the adjudicator disregards the high water mark associated with a token if the high water mark has aged by more than a predetermined amount of time.

5. The system of claim 4 , wherein the predetermined amount of time is a function of whether the token is a hardware-based token or a software-based token.

6. The system of claim 1 :

wherein, when the token seeking authentication seeks authentication from the non-home authentication server, the system is further constructed and arranged to:

(iv) perform cryptographic calculations associated with authenticating the one-time passcode at the non-home authentication server; and

wherein, when the token seeking authentication seeks authentication from the home authentication server, the system is further constructed and arranged to:

(iv) perform cryptographic calculations associated with authenticating the one-time passcode at the home authentication server.

7. A method of associating tokens, capable of generating one-time passcodes, with home authentication servers in a network of authentication servers, comprising:

assigning each of a plurality of tokens to a home authentication server according to a predetermined characteristic of the token;

evaluating authentication activity of the plurality of tokens;

for each one of the plurality of tokens, reassigning the token to a home authentication server to which the token most often authenticates;

wherein authentication activity includes, regardless of which authentication server in the network of authentication servers that a token seeks authentication from, evaluating a high water mark value associated with the token seeking authentication at the home authentication server;

wherein evaluating the high water mark value includes, when the token seeking authentication seeks authentication from an authentication server of the plurality of authentication servers that is not the home authentication server (non-home authentication server):

(i) forwarding the high water mark value to the adjudicator function of the non-home authentication server;

(ii) determining, at the adjudicator function of the non-home authentication server, that the high water mark information originating from the token seeking authentication is associated with the home authentication server; and

(iii) in response to determining, sending the high water mark value to the adjudicator function of the home authentication server; and

wherein evaluating the high water mark value includes, when the token seeking authentication seeks authentication from the home authentication server:

(i) forwarding the high water mark value to the adjudicator function of the home authentication server;

(ii) determining, at the adjudicator function of the home authentication server, that the high water mark value originating from the token seeking authentication is associated with the home authentication server; and

(iii) in response to determining, maintaining the high water mark value in the adjudicator function of the home authentication server.

8. The method of claim 7 , wherein the predetermined characteristic of the token is a registration site of the token.

9. The method of claim 7 , wherein the predetermined characteristic of the token is an identification number associated with the token.

10. The method of claim 7 , wherein evaluating authentication activity of the plurality of tokens further includes counting authentication attempts the token submits to each authentication server in the network of authentication servers.

11. The method of claim 7 , further including reassigning the token at a predetermined token reassignment rate.

12. The method of claim 7 , further including disregarding the high water mark if the high water mark has aged by more than a predetermined amount of time.

13. The method of claim 12 , wherein the predetermined amount of time is a function of whether the token is a hardware-based token or a software-based token.

14. The method of claim 7 :

wherein evaluating the high water mark value further includes, when the token seeking authentication seeks authentication from the non-home authentication server:

(iv) performing cryptographic calculations associated with authenticating the one-time passcode at the non-home authentication server; and

wherein evaluating the high water mark value further includes, when the token seeking authentication seeks authentication from the home authentication server:

(iv) performing cryptographic calculations associated with authenticating the one-time passcode at the home authentication server.

15. A method of detecting and preventing replay attacks in an authentication network including a plurality of authentication servers interconnected through an authentication network, comprising:

associating a token, capable of generating one-time passcodes, with a home authentication server that maintains a current high water mark value of the token seeking authentication;

generating a one-time passcode with the token, and providing the one-time passcode to one of the plurality of authentication servers for authentication;

evaluating a high water mark value associated with the token;

allowing an authentication procedure to proceed for the token if the high water mark evaluation indicates that the one-time passcode was not used in a previous authentication transaction;

preventing authentication of the token seeking authentication if the high water mark evaluation indicates that the one-time passcode was used in a previous authentication transaction;

when the token seeking authentication seeks authentication from an authentication server of the plurality of authentication servers that is not the home authentication server (non-home authentication server):

(i) forwarding the high water mark value to an adjudicator function of the non-home authentication server;

(ii) determining, at the adjudicator function of the non-home authentication server, that the high water mark information originating from the token seeking authentication is associated with the home authentication server; and

(iii) in response to determining, sending the high water mark value to an adjudicator function of the home authentication server; and

when the token seeking authentication seeks authentication from the home authentication server:

(i) forwarding the high water mark value to the adjudicator function of the home authentication server;

(ii) determining, at the adjudicator function of the home authentication server, that the high water mark value originating from the token seeking authentication is associated with the home authentication server; and

(iii) in response to determining, maintaining the high water mark value in the adjudicator function of the home authentication server.

16. The method of claim 15 , further comprising:

when the token seeking authentication seeks authentication from the non-home authentication server:

(iv) performing cryptographic calculations associated with authenticating the one-time passcode at the non-home authentication server; and

when the token seeking authentication seeks authentication from the home authentication server:

(iv) performing cryptographic calculations associated with authenticating the one-time passcode at the home authentication server.

Assignments (25)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023975/0453 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023975/0151 →
MERGER Recorded Jan 27, 2010
From: RSA SECURITY INC.
To: RSA SECURITY LLC
Reel/Frame 023852/0500 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023825/0011 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023824/0721 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2007
From: DUANE, WILLIAM; FRIEDMAN, LAWRENCE N.; VOLANIS, ALEXANDER
To: RSA SECURITY INC.
Reel/Frame 019670/0619 →