IP Library Granted Patent US 9,071,439
Granted Patent B2
US 9,071,439 · App. 11/769,855 · Granted Jun 30, 2015

Method and apparatus for remote administration of cryptographic devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,071,439
App. No.
11/769,855
Granted
Jun 30, 2015
Kind
B2
Abstract

Techniques are disclosed for performing operations in an authentication token or other cryptographic device in a system comprising an authentication server. In one aspect, a code generated by the authentication server is received in the cryptographic device. The code may have associated therewith information specifying at least one operation to be performed by the cryptographic device. The cryptographic device authenticates the code, and responsive to authentication of the code, performs the specified operation. If the code is not authenticated, the operation is not performed. The code may be determined as a function of a one-time password generated by the authentication server. The function may also take as an input an identifier of the operation to be performed.

Claims (32)

1. A method of performing at least one operation in a cryptographic device in a system comprising an authentication server, the method comprising receiving in the cryptographic device a code generated by the authentication server; authenticating the code in the cryptographic device; and responsive to authentication of the code, performing said at least one operation in the cryptographic device; wherein the code is received in the cryptographic device in association with a request by the authentication server for the cryptographic device to perform said at least one operation; and wherein the operation to be performed by the cryptographic device comprises resetting a time value or event counter value on the cryptographic device.

2. The method of claim 1 wherein the code has associated therewith information specifying said at least one operation to be performed by the cryptographic device.

3. The method of claim 1 wherein the cryptographic device comprises an authentication token.

4. A method of performing at least one operation in a cryptographic device in a system comprising an authentication server, the method comprising: receiving in the cryptographic device a code generated by the authentication server; authenticating the code in the cryptographic device; and responsive to authentication of the code, performing said at least one operation in the cryptographic device; wherein the code is received in the cryptographic device in association with a request by the authentication server for the cryptographic device to perform said at least one operation;

and wherein the code is determined as a function of at least an identifier of the operation.

5. A method of performing at least one operation in a cryptographic device in a system comprising an authentication server, the method comprising: receiving in the cryptographic device a code generated by the authentication server; authenticating the code in the cryptographic device; and responsive to authentication of the code, performing said at least one operation in the cryptographic device; wherein the code is received in the cryptographic device in association with a request by the authentication server for the cryptographic device to perform said at least one operation; and wherein the code is determined as a function of at least a one-time password generated by the authentication server.

6. The method of claim 5 wherein the one-time password corresponds to a password to be generated by the cryptographic device.

7. The method of claim 6 wherein the password to be generated by the cryptographic device comprises a password to be generated at a designated offset from a current state of the cryptographic device.

8. The method of claim 1 further including providing to the authentication server from the cryptographic device an additional code indicative of success or failure of the operation.

9. The method of claim 1 wherein the operation to be performed by the cryptographic device comprises updating an access code of the cryptographic device.

10. The method of claim 1 wherein the operation to be performed by the cryptographic device comprises unlocking the cryptographic device.

11. The method of claim 1 wherein the operation to be performed by the cryptographic device comprises altering a configurable parameter of the cryptographic device.

12. The method of claim 1 wherein the operation to be performed by the cryptographic device comprises updating a shared secret in the cryptographic device.

13. The method of claim 1 wherein the operation to be performed by the cryptographic device comprises granting administrative access to the cryptographic device or a host associated with the cryptographic device.

14. A method of controlling the performance of at least one operation in a cryptographic device in a system comprising an authentication server, the method comprising: generating a code in the authentication server; and providing the generated code to the cryptographic device;

wherein the code is authenticated in the cryptographic device, and responsive to authentication of the code, the cryptographic device performs said at least one operation; wherein the code is provided to the cryptographic device in association with a request by the authentication server for the cryptographic device to perform said at least one operation; and wherein the authentication server generates the code based at least in part on computation of a one-time password OTP s for a future time specified by an offset o relative to a current time t s :

OTP S =F 1 (( t S +o ), k ),

where F 1 denotes a cryptographic function, and k denotes a secret shared by the server and the cryptographic device.

15. The method of claim 14 wherein the code comprises a code Code s generated by the authentication server based on the one-time password OTP s :

Code S =F 2 ( OTP S , r ),

where F 2 denotes a cryptographic function, and r denotes an identifier of the operation.

16. The method of claim 15 wherein the identifier r of the specified operation is sent by the authentication server with the code Code s to the cryptographic device.

17. The method of claim 15 wherein for each of a plurality of time intervals t within a designated range, the cryptographic device computes

OTP T =F 1 ( t, k ) and Code T =F 2 ( OTP T , r ),

and if Code s =Code T for any one of the intervals in the range, then the operation r is performed.

18. A non-transitory processor-readable storage medium storing one or more software programs, wherein the one or more software programs when executed by a processor of a cryptographic device implement: receiving in the cryptographic device a code generated by an authentication server; authenticating the code in the cryptographic device; and responsive to authentication of the code, performing said at least one operation in the cryptographic device; wherein the code is received in the cryptographic device in association with a request by the authentication server for the cryptographic device to perform said at least one operation; and wherein the operation to be performed by the cryptographic device comprises resetting a time value or event counter value on the cryptographic device.

19. An apparatus comprising:

a cryptographic device having a processor coupled to a memory;

wherein the cryptographic device is configured to receive a code generated by an authentication server; wherein the cryptographic device is further configured to authenticate the code generated by the authentication server, and responsive to authentication of the code, to perform at least one operation; wherein the code is received in the cryptographic device in association with a request by the authentication server for the cryptographic device to perform said at least one operation; and wherein the operation to be performed by the cryptographic device comprises resetting a time value or event counter value on the cryptographic device.

20. The apparatus of claim 19 wherein the cryptographic device comprises an authentication token.

21. A method of controlling the performance of at least one operation in a cryptographic device in a system comprising an authentication server, the method comprising generating a code in the authentication server; and providing the generated code to the cryptographic device; wherein the code is authenticated in the cryptographic device, and responsive to authentication of the code, the cryptographic device performs said at least one operation; wherein the code is provided to the cryptographic device in association with a request by the authentication server for the cryptographic device to perform said at least one operation; and wherein the code is determined as a function of at least one of: an identifier of the operation; and a one-time password generated by the authentication server.

22. A system comprising: a plurality of cryptographic devices; and an authentication server; wherein the authentication server is configured to generate a code; wherein a given one of the cryptographic devices is configured to authenticate the code generated by the authentication server, and responsive to authentication of the code, to perform at least one operation; wherein the code is received in the given one of the cryptographic devices in association with a request by the authentication server for the given one of the cryptographic devices to perform said at least one operation; and wherein the code is determined as a function of at least one of: an identifier of the operation; and a one-time password generated by the authentication server.

Assignments (14)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023975/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023975/0453 →
MERGER Recorded Jan 27, 2010
From: RSA SECURITY INC
To: RSA SECURITY LLC
Reel/Frame 023852/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023824/0729 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023825/0109 →