IP Library Granted Patent US 8,453,232
Granted Patent B1
US 8,453,232 · App. 12/894,502 · Granted May 28, 2013

Virtual smart card through a PC/SC interface

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,453,232
App. No.
12/894,502
Granted
May 28, 2013
Kind
B1
Abstract

A technique of providing a cryptographic service on a computer having a processor includes deploying an executable cryptographic agent set on the computer, each executable cryptographic agent from the executable cryptographic agent set being a set of instructions executed on the processor. The technique also includes activating an executable cryptographic agent on the computer, each executable cryptographic agent being constructed and arranged to generate cryptographic codes which change over time in response to activation of the agent. The technique further includes providing, to an application running on the computer, access to the executable cryptographic agent through a Personal Computer/Smart Card (PC/SC) interface of the computer.

Claims (82)

1. A method of providing a cryptographic service on a computer having a processor, the method comprising:

deploying an executable cryptographic agent set on the computer, each executable cryptographic agent from the executable cryptographic agent set being a set of instructions executed on the processor and being provided by a virtual smart card stored in the computer;

activating an executable cryptographic agent on the computer, each executable cryptographic agent being constructed and arranged to generate cryptographic codes which change over time in response to activation of the agent; and

providing, to an application running on the computer, access to the executable cryptographic agent through a Personal Computer/Smart Card (PC/SC) interface of the computer.

2. A method as in claim 1 , wherein providing access to the executable cryptographic agent includes:

locating, on a non-volatile memory coupled to the processor, a token seed value; and

generating, based on the token seed value, a set of one-time passcodes which act as a cryptographic code.

3. A method as in claim 2 , wherein deploying the executable cryptographic agent set on the computer includes:

providing a set of inquiries to a user;

receiving a set of enrollment answers from the user in response to the set of inquiries, each enrollment answer from the set of enrollment answers corresponding to an inquiry from the set of inquiries; and

storing the sets of inquiries and enrollment answers on the non-volatile memory;

wherein the sets of inquiries and enrollment answers, in combination with a personal identification number, provide a vehicle for the user to be identified within the computer.

4. A method as in claim 3 , wherein activating the executable cryptographic agent on the computer includes:

providing, from the non-volatile, computer-readable storage medium, the set of inquiries to a prospective user;

receiving a set of answers from the prospective user in response to the set of inquiries; and

comparing the received set of answers to the stored set of enrollment answers.

5. A method as in claim 4 , wherein providing the set of inquiries to the prospective user includes:

sending, via a network interface on the computer, a message to the prospective user, the message including the set of inquiries;

wherein the prospective user is connected to a network through a virtual desktop environment; and

wherein the network interface is coupled to the network to which the prospective user is connected.

6. A method as in claim 3 , wherein providing access to the executable cryptographic agent includes:

making available, to the application, a digital certificate from the executable cryptographic agent through the PC/SC interface;

wherein the digital certificate is constructed and arranged to identify the user to a third party.

7. A method as in claim 3 , wherein providing access to the executable cryptographic agent includes:

making available, to the application, a public key from the executable cryptographic agent through the PC/SC interface; and

providing encryption services for messages generated and sent to a third party by the application;

wherein the public key is constructed and arranged to match a private key from the third party.

8. A method as in claim 3 , wherein providing access to the executable cryptographic agent includes:

making available, to the application, a private key from the executable cryptographic agent through the PC/SC interface; and

providing decryption services for messages generated and sent from third parties to the user via the application;

wherein the private key is constructed and arranged to match public keys contained in the messages.

9. A method as in claim 1 , further comprising:

activating a second executable cryptographic agent from the executable cryptographic agent set on the computer; and

providing, to a second application running on the computer, access to the second executable cryptographic agent through the Personal Computer/Smart Card (PC/SC) interface of the computer.

10. An apparatus configured to provide a cryptographic service, the apparatus comprising:

a memory; and

a processor coupled to the memory, the processor configured to:

deploy an executable cryptographic agent set on the apparatus, each executable cryptographic agent from the executable cryptographic agent set being a set of instructions executed on the processor and being provided by a virtual smart card stored in the computer;

activate an executable cryptographic agent on the apparatus, each executable cryptographic agent being constructed and arranged to generate cryptographic codes which change over time in response to activation; and

provide, to an application running on the apparatus, access to the executable cryptographic agent through a Personal Computer/Smart Card (PC/SC) interface of the apparatus.

11. An apparatus as in claim 10 , wherein the memory is configured to store a token seed value;

wherein activating the executable cryptographic agent on the apparatus includes:

locating the token seed value on the memory; and

generating, based on the token seed value, a set of one-time passcodes which act as a cryptographic code.

12. An apparatus as in claim 11 , further comprising an input/output interface;

wherein deploying the executable cryptographic agent set on the apparatus includes:

providing a set of inquiries to a user via the input/output interface;

receiving, via the input/output interface, a set of enrollment answers from the user in response to the set of inquiries, each enrollment answer from the set of enrollment answers corresponding to an inquiry from the set of inquiries; and

storing the sets of inquiries and enrollment answers on the memory; and

wherein the sets of inquiries and enrollment answers, in combination with a personal identification number, provide a vehicle for the user to be identified within the apparatus.

13. An apparatus as in claim 12 , wherein activating the executable cryptographic agent includes:

providing, from the memory, the set of inquiries to a prospective user via the input/output interface;

receiving, via the input/output interface, a set of answers from the prospective user in response to the set of inquiries; and

comparing the received set of answers to the stored set of enrollment answers.

14. An apparatus as in claim 13 , further comprising a network interface;

wherein providing the set of inquiries to the prospective user includes:

sending, via the network interface, a message to the prospective user, the message including the set of inquiries;

wherein the prospective user is connected to a network through a virtual desktop environment; and

wherein the network interface is coupled to the network to which the prospective user is connected.

15. An apparatus as in claim 10 , wherein the processor is further configured to:

activate a second executable cryptographic agent from the executable cryptographic agent set on the apparatus; and

provide, to a second application running on the processor, access to the second executable cryptographic agent through the PC/SC interface.

16. A computer program product having a non-transitory computer readable storage medium which stores code to provide a cryptographic service on a computer having a processor, the code including instructions to:

deploy an executable cryptographic agent set on the computer, each executable cryptographic agent from the executable cryptographic agent set being a set of instructions executed on the processor and being provided by a virtual smart card stored in the computer;

activate an executable cryptographic agent on the computer, each executable cryptographic agent being constructed and arranged to generate cryptographic codes which change over time in response to activation; and

provide, to an application running on the computer, access to the executable cryptographic agent through a Personal Computer/Smart Card (PC/SC) interface of the computer.

17. A computer program product as in claim 16 , activating the executable cryptographic agent on the computer includes:

locating, on a memory coupled to the processor, a token seed value; and

generating, based on the token seed value, a set of one-time passwords which act as a cryptographic code.

18. A computer program product as in claim 17 , wherein deploying the executable cryptographic agent set on the computer includes:

providing a set of inquiries to a user;

receiving a set of enrollment answers from the user in response to the set of inquiries, each enrollment answer from the set of enrollment answers corresponding to an inquiry from the set of inquiries; and

storing the sets of inquiries and enrollment answers on the memory;

wherein the sets of inquiries and enrollment answers, in combination with a personal identification number, provide a vehicle for the user to be identified within the computer.

19. A computer program product as in claim 16 , wherein activating the executable cryptographic agent on the computer includes:

providing, from the memory, the set of inquiries to a prospective user;

receiving a set of answers from the prospective user in response to the set of inquiries; and

comparing the received set of answers to the stored set of enrollment answers.

20. A computer program product as in claim 16 , wherein providing access to the executable cryptographic agent through a Personal Computer/Smart Card (PC/SC) interface of the computer includes:

deploying a windowing module in a software layer above that of the PC/SC interface; and

providing a subset of data input to and output from the PC/SC interface to a log file stored on the memory;

wherein the windowing module is a dynamically linked library configured to provide an application programming interface for a PKCS 11 unit test module to access the cryptographic agent.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →