IP Library Granted Patent US 8,060,750
Granted Patent B2
US 8,060,750 · App. 11/824,434 · Granted Nov 15, 2011

Secure seed provisioning

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,060,750
App. No.
11/824,434
Granted
Nov 15, 2011
Kind
B2
Abstract

A technique is utilized in the configuration and seeding of security tokens at third party facilities, particularly at facilities of a configuration agent, such that a token can be configured without the configuration agent having security-defeating knowledge about the token. Such a technique allows a third party to provision a token with a seed, but in such a way that the third party will not know, or be able to construct, the seed after the seed provisioning process is complete. The seed may include, by way of example, a symmetric key or other secret shared by two or more entities. In some arrangements, a method is used for secure seed provisioning. Data is derived from inherent randomness in a token or other authentication device. Based on the data, the token or other authentication device is provisioned with a seed.

Claims (61)

1. A method for use in secure seed provisioning, the method comprising the steps of:

deriving, by an authentication device, data from an inherent source of randomness in the authentication device;

based on the data, provisioning, by the authentication device, the authentication device with a seed;

preventing, by the authentication device, direct external exposure of the seed during the lifetime of the authentication device; and

receiving, by the authentication device and from a programming station, a configuration command to provision the authentication device with the seed, the authentication device being provisioned with the seed in response to the configuration command;

wherein deriving the data from an inherent source of randomness in the authentication device includes:

generating, by a processor of the authentication device, the data based on a counter value which represents an amount of time between (i) when a battery of the authentication device is connected to the processor and (ii) when the configuration command is received from the programming station.

2. The method of claim 1 , wherein the seed comprises a symmetric key.

3. The method of claim 1 , wherein the inherent source of randomness is based on a powerup characteristic of the authentication device.

4. The method of claim 1 , wherein the inherent source of randomness is based on an electronic component characteristic of the authentication device.

5. The method of claim 1 , wherein the inherent source of randomness is based on an amount of time between unsynchronized events in the authentication device.

6. The method of claim 1 , further comprising:

starting to increment a counter when power is applied to the authentication device,

wherein the data is based on a value of the counter.

7. The method of claim 1 , further comprising:

further deriving the data from a source of randomness external to the authentication device.

8. The method of claim 1 , further comprising:

outputting an intermediate level value to a recipient, the intermediate level value being required for the recipient to calculate the seed.

9. The method of claim 1 , further comprising:

deriving a value from the inherent source of randomness; and

outputting the value to a recipient, the value being required for the recipient to calculate the seed.

10. The method of claim 1 , further comprising:

outputting a first value to a first recipient, the first value alone being insufficient to allow calculation of the seed; and

at the first recipient, calculating the seed from the first value and a second value already available to the first recipient, the second value being unavailable to a second recipient.

11. The method of claim 1 , further comprising:

deriving the seed from a unique value provided in the authentication device.

12. The method of claim 1 , further comprising:

using the inherent source of randomness to affect a value of a counter in the authentication device.

13. The method of claim 1 , further comprising:

avoiding resetting the value of a counter in the authentication device to zero when the authentication device is reset.

14. The method of claim 1 , further comprising:

deriving the seed from a source of randomness that is external to the authentication device, the source of randomness being unpredictable and hardware based.

15. The method of claim 1 , further comprising:

deriving the seed using encryption.

16. The method of claim 1 , further comprising:

deriving the seed from a unique value programmed into the authentication device at the time of chip fabrication.

17. The method of claim 1 , further comprising:

controlling access to values such that only one or more authorized entities outside the authentication device have sufficient information to calculate the seed.

18. The method of claim 1 , further comprising:

deriving the seed based on a mapping between a chip serial number and a unique value programmed into the authentication device at the time of chip fabrication.

19. The method of claim 1 , further comprising:

deriving the seed based on a mapping between a serial number of the authentication device and a value based on an external source of randomness.

20. A method for use in secure seed provisioning, the method comprising the steps of:

deriving, by a first authentication device, data from a secret number embedded in multiple authentication devices including the first authentication device, and from a unique number embedded in the first authentication device only;

based on the data, provisioning, by the first authentication device, the first authentication device with a seed;

preventing, by the first authentication device, direct external exposure of the seed from the first authentication device during the lifetime of the first authentication device; and

receiving, by the first authentication device and from a programming station, a configuration command to provision the first authentication device with the seed, the authentication device being provisioned with the seed in response to the configuration command;

wherein deriving the data from the secret number embedded in the multiple authentication devices and from a unique number embedded in the first authentication device only includes:

generating, by a processor of the first authentication device, the data based on a counter value which represents an amount of time between (i) when a battery of the first authentication device is connected to the processor and (ii) when the configuration command is received from the programming station.

21. A method for use in secure seed provisioning, the method comprising the steps of:

deriving, by an authentication device, a first number from an internal source of randomness;

receiving, by the authentication device, a second number based on an external source of randomness;

receiving, by the authentication device, a serial number;

internally retrieving, by the authentication device, a non-unique secret key;

deriving, by the authentication device, a third number from the first number, serial number, and the non-unique secret key;

externally exposing the third number while preventing direct external exposure of the seed from the authentication device during the lifetime of the authentication device; and

deriving a key from the second and third numbers;

wherein deriving the first number from the internal source of randomness includes:

generating, by a processor of the authentication device, the first number based on a counter value which represents an amount of time between (i) when a battery of the authentication device is connected to the processor and (ii) when the second number is received.

22. The method of claim 21 , wherein the authentication device includes a random number generator; and wherein generating the data includes:

providing the data based on both the counter value and a random number supplied by the random number generator, the counter value and the random number being different from each other, the programming station being prevented from ever reading the seed provisioned to the authentication device which is based on the data based on both the counter value and the random number.

Assignments (25)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE OMITTED SIGNATURE PAGE FOR WILLIAM M. DUANE PREVIOUSLY RECORDED AT REEL: 019566 FRAME: 0662. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 18, 2020
From: DUANE, WILLIAM M; SILVA, ERIC A; CIAFFI, MARCO
To: RSA SECURITY INC.
Reel/Frame 054475/0317 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023975/0453 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023975/0151 →
MERGER Recorded Jan 27, 2010
From: RSA SECURITY INC
To: RSA SECURITY LLC
Reel/Frame 023852/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023824/0729 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023825/0109 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2007
From: DUANE, WILLIAM M.; SILVA, ERIC A.; CIAFFI, MARCO
To: RSA SECURITY INC.
Reel/Frame 019566/0662 →