IP Library Granted Patent US 8,015,599
Granted Patent B2
US 8,015,599 · App. 12/468,144 · Granted Sep 6, 2011

Token provisioning

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,015,599
App. No.
12/468,144
Granted
Sep 6, 2011
Kind
B2
Abstract

A method for provisioning a device such as a token. The device issues a certificate request to a Certification Authority. The request includes a public cryptographic key uniquely associated with the device. The Certification Authority generates a symmetric cryptographic key for the device, encrypts it using the public key, and creates a digital certificate that contains the encrypted symmetric key as an attribute. The Certification Authority sends the digital certificate to the device, which decrypts the symmetric key using the device's private key, and stores the decrypted symmetric key.

Claims (40)

1. A method for reprovisioning a token having a first secret, comprising:

sending a request for a certificate;

receiving a certificate comprising:

a second secret encrypted with a public key of the token, the second secret distinct from the first secret;

a public key received from the token; and

a digital signature based upon a secret asymmetric key of the recipient of the request for the certificate;

decrypting the second secret with a private key of the token;

replacing the first secret with the second secret;

generating a one time password based on the second secret; and

sending the one time password based on the second secret to an authentication server to authenticate a user.

2. The method of claim 1 , wherein the certificate is an X.509 certificate.

3. The method of claim 1 , wherein the request for a certificate is sent from a PKI enabled device to a PKI certificate authority.

4. The method of claim 1 , wherein the one time password based on the second secret is further based on a personal identification number.

5. The method of claim 1 , wherein the one time password based on the second secret is further based on a signal from a clock.

6. The method of claim 1 , wherein the one time password based on the second secret is further based on a counter value.

7. A token for generating one time passwords, comprising:

a processor; and

a memory coupled to the processor, the memory storing a first secret and token instructions adapted to be executed by the processor to send a message that includes a request for a certificate, receive a certificate, replace the first secret with a second secret including storing the second secret in memory, generate a one time password based on the second secret, and send the one time password based on the second secret to an authentication server to authenticate a user,

wherein the certificate comprises:

the second secret encrypted with a public key of the token, the second secret distinct from the first secret;

a public key received from the token; and

a digital signature based upon a secret asymmetric key of the recipient of the request for the certificate.

8. The token of claim 7 , wherein the token instructions are further adapted to be executed by the processor to generate the one time password based on a personal identification number.

9. The token of claim 7 , wherein the token instructions are further adapted to be executed by the processor to generate the one time password based on the second secret and a time value.

10. The token of claim 7 , wherein the token instructions are further adapted to be executed by the processor to generate the one time password based on the second secret and a counter value.

11. The token of claim 7 , wherein the certificate is an X.509 certificate.

12. The token of claim 7 , wherein the request for a certificate is sent from a PKI enabled device to a PKI certificate authority.

13. A token for generating one time passwords, comprising:

a processor; and

a memory coupled to the processor, the memory separately storing;

a first secret for generating one time passwords;

a private key;

a public key; and

token instructions adapted to be executed by the processor to send a message that includes a request for a certificate, receive a certificate, decrypt a second secret with the private key of the token, replace the first secret with the second secret, generate a one time password based on the second secret, and send the one time password to an authentication server to authenticate a user,

wherein the certificate comprises:

the second secret encrypted with the public key of the token, the second secret distinct from the first secret;

a public key received from the token; and

a digital signature based upon a secret asymmetric key of the recipient of the request for the certificate.

14. The token of claim 13 , wherein the certificate is an X.509 certificate.

15. The token of claim 13 , wherein the request for a certificate is sent from a PKI enabled device to a PKI certificate authority.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2010
From: VERISIGN, INC.
To: SYMANTEC CORPORATION
Reel/Frame 025499/0882 →