IP Library Granted Patent US 8,499,157
Granted Patent B1
US 8,499,157 · App. 12/893,684 · Granted Jul 30, 2013

Device-based password management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,499,157
App. No.
12/893,684
Granted
Jul 30, 2013
Kind
B1
Abstract

A first device (e.g. smartphone) manages a first key (e.g. password) required for a security operation with a second device (e.g., WWW server) by calculating and storing a key seed using the first key and a second key shared with a third device (e.g., wireless headset). Later (e.g., upon losing communication with the third device), at least a portion of the first and second keys is/are erased to prevent the security operation. Subsequently (e.g., when communication with third device is reestablished), the first key is regenerated by (1) receiving a key hint from the third device, (2) regenerating the second key using the key hint and a known message used to create the key hint, and (3) regenerating the first key using the key seed and the regenerated second key.

Claims (47)

1. A method by which a first device manages a first key required for execution of a security operation with a second device, comprising:

calculating and storing a key seed during a period in which the first key is stored in a memory of the first device, the key seed being calculated by a first cryptographic operation using the first key and a second key shared with a third device;

subsequently erasing at least a portion of the first and second keys to prevent execution of the security operation by the first device; and

during a subsequent period in which the first device is in communication with the third device:

receiving a key hint from the third device, the key hint being generated by a second cryptographic operation at the third device using the second key and a message known to the first device;

regenerating the second key using the key hint and the known message; and

regenerating the first key by performing a third cryptographic operation using the key seed and the regenerated second key;

wherein the third device is a portable device that is in communication with the first device when located with the first device and is not in communication with the first device when located away from the first device;

wherein the subsequent period in which the first device is in communication with the third device is a period in which the third device is co-located with the first device following an immediately preceding period in which the third device is not co-located with the first device and not in communication with the first device; and

the erasing is performed during the immediately preceding period.

2. A method according to claim 1 , wherein the first key is password or personal identification number of a user of the first device, and the security operation is a login process of an online service provided via the second device.

3. A method according to claim 1 , wherein the second key is an encryption key used in symmetric key encryption of communications between the first device and the third device unrelated to the security operation.

4. A method according to claim 1 , wherein the third device is a peripheral input/output device for the first device.

5. A method according to claim 4 , wherein the peripheral input/output device is a wireless audio headset.

6. A method according to claim 4 , wherein the peripheral input/output device is operative to engage in a pairing operation with the first device by which the second key is established.

7. A method according to claim 6 , wherein the second key is an encryption key used in symmetric key encryption of communications between the first device and the peripheral input/output device.

8. A method according to claim 1 , wherein regenerating the second key includes brute-force searching of at least a portion of a key space containing the second key.

9. A method according to claim 8 , wherein the portion of the key space is a sub-space defined by a retained portion of the second key which is retained during the erasing, and wherein regenerating the second key includes regenerating an erased portion of the second key and combining the regenerated erased portion with the retained portion.

10. A method according to claim 1 , wherein the key hint includes predictable data conveyed from the third device to the first device in a normal operation unrelated to the security operation.

11. A method according to claim 10 , wherein the predictable data is a response provided in a challenge-response exchange constituting the normal operation between the first device and the third device.

12. A method according to claim 11 , wherein at least one of the key hint and the known message is one of multiple key hints and/or known messages respectively, the multiple key hints and/or known messages being used in the regenerating of the second key.

13. A device operative as a first device to manage a first key required for execution of a security operation with a second device, comprising:

a processor;

memory;

input/output circuitry providing communications between the first device and both the second device and a third device; and

interconnect circuitry operative to communicatively connect the processor, memory and input/output circuitry together,

the processor executes program instructions from the memory to perform a method of managing the first key, the method including:

calculating and storing a key seed during a period in which the first key is stored in the memory, the key seed being calculated by a first cryptographic operation using the first key and a second key shared with the third device, the key seed and second key being stored in the memory;

subsequently erasing at least a portion of the first and second keys from the memory to prevent execution of the security operation by the first device; and

during a subsequent period in which the first device is in communication with the third device:

receiving a key hint from the third device, the key hint being generated by a second cryptographic operation at the third device using the second key and a message known to the first device;

regenerating the second key using the key hint and the known message; and

regenerating the first key by performing a third cryptographic operation using the key seed and the regenerated second key;

wherein the third device is a portable device that is in communication with the first device when located with the first device and is not in communication with the first device when located away from the first device;

wherein the subsequent period in which the first device is in communication with the third device is a period in which the third device is co-located with the first device following an immediately preceding period in which the third device is not co-located with the first device and not in communication with the first device; and

the erasing is performed during the immediately preceding period.

14. A device according to claim 13 , wherein the first key is password or personal identification number of a user of the first device, and the security operation is a login process of an online service provided via the second device.

15. A device according to claim 13 , wherein the second key is an encryption key used in symmetric key encryption of communications between the first device and the third device unrelated to the security operation.

16. A device according to claim 13 , wherein the third device is a peripheral input/output device for the first device.

17. A device according to claim 16 , wherein the peripheral input/output device is a wireless audio headset.

18. A device according to claim 16 , wherein the peripheral input/output device is operative to engage in a pairing operation with the first device by which the second key is established.

19. A device according to claim 18 , wherein the second key is an encryption key used in symmetric key encryption of communications between the first device and the peripheral input/output device.

20. A device according to claim 13 , wherein regenerating the second key includes brute-force searching of at least a portion of a key space containing the second key.

21. A device according to claim 20 , wherein the portion of the key space is a sub-space defined by a retained portion of the second key which is retained during the erasing, and wherein regenerating the second key includes regenerating an erased portion of the second key and combining the regenerated erased portion with the retained portion.

22. A device according to claim 13 , wherein the key hint includes predictable data conveyed from the third device to the first device in a normal operation unrelated to the security operation.

23. A device according to claim 22 , wherein the predictable data is a response provided in a challenge-response exchange constituting the normal operation between the first device and the third device.

24. A device according to claim 23 , wherein at least one of the key hint and the known message is one of multiple key hints and/or known messages respectively, the multiple key hints and/or known messages being used in the regenerating of the second key.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2010
From: JUELS, ARI; BAILEY, DANIEL
To: EMC CORPORATION
Reel/Frame 025342/0174 →