IP Library Granted Patent US 8,590,030
Granted Patent B1
US 8,590,030 · App. 13/086,946 · Granted Nov 19, 2013

Credential seed provisioning system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,590,030
App. No.
13/086,946
Granted
Nov 19, 2013
Kind
B1
Abstract

A system for efficiently storing and activating credential seeds that are embedded in authentication devices. Device manufacturers provide copies of credential seeds embedded in the devices to an authentication service. The authentication service stores the credential seeds for authentication devices in a pre-active credential seed data store. When a credential seed is needed to perform a real-time or near real-time authentication of a One Time Password, the credential is fetched from the pre-active credential seed data store, used to authenticate the OTP and injected into the active credential seed data store, which can be a database. Thereafter, the credential seed is fetched from the active credential seed data store for real-time and near real-time authentication of OTPs. The credential seeds can be stored in the data stores with additional information, such as user profile data, permissions and authorizations, OTP authentication algorithm information, metadata, OTP moving factor data, time-to-live, and other attributes.

Claims (34)

1. A method comprising:

receiving a plurality of credential seeds, each credential seed suitable for generating a one time password;

storing the plurality of credential seeds in a pre-active data store;

receiving an indication that a first one of the plurality of credential seeds is to be activated, the indication including an authentication device identifier;

locating the first one of the plurality of credential seeds to be activated in the pre-active data store based upon the authentication device identifier;

reading the first one of the plurality of credential seeds to be activated from the pre-active data store; and

activating, by a computer, the first one of the plurality of credential seeds by storing a copy of the first one of the plurality of credential seeds in an active data store in response to the indication that the one of the plurality of credential seeds is to be activated.

2. The method of claim 1 , wherein receiving the indication comprises receiving a request to authenticate the one time password an OTP, the request including the authentication device identifier.

3. The method of claim 1 , wherein receiving the indication indicates a request to activate the first one of the plurality of credential seeds based upon the authentication device identifier.

4. The method of claim 2 , further comprising authenticating the one time password based upon the first one of the plurality of credential seeds from the pre-active data store.

5. The method of claim 1 , wherein the pre-active data store comprises one or more flat files.

6. The method of claim 1 , wherein the active data store comprises at least one table in a relational database.

7. The method of claim 1 , wherein the active data store further stores at least one from the group of a manufacturer identifier, a token identifier and an authentication algorithm identifier.

8. The method of claim 1 , wherein locating the first one of the plurality of credential seeds to be activated comprises searching an index table.

9. The method of claim 1 , wherein the plurality of credential seeds stored in the pre-active data store are linked in a group such that activating one credential seed automatically activates the other credential seeds in the group.

10. A system comprising:

a pre-active data store storing a plurality of non-active credential seeds, each credential seed being suitable for generating a one time password for use by an authentication device;

an active data store storing a plurality of active credential seeds;

an index table that indicates the locations of the plurality of non-active credential seeds in the pre-active data store;

an authentication module in communication with the index table, where the authentication module receives an indication to activate a credential seed, consults the index table, locates the credential seed to be activated and activates the credential seed by sending instructions to fetch the credential seed from the pre-active data store and store a copy of the credential seed in the active data store; and

a data store interface module in communication with the pre-active data store, the active data store and the authentication module, where the data store receives instructions from the authentication module to fetch the credential seed from a data store and store a copy of the credential seed in a data store.

11. The system of claim 10 , wherein the pre-active data store comprises at least one flat file.

12. The system of claim 10 , wherein the active data store comprises at least one table in a relational database.

13. The system of claim 10 , wherein the authentication module authenticates the one time password.

14. The system of claim 10 , further comprising a credential seed loader module that receives credential seeds through an out-of-band channel and causes the credential seeds to be stored in the pre-active data store.

15. A non-transitory computer readable medium storing a plurality of instructions that cause a computer to perform a method comprising:

receiving a plurality of credential seeds, each credential seed suitable for generating a being suitable for generating a one time password;

storing the plurality of credential seeds in a pre-active data store;

receiving an indication that a first one of the plurality of credential seeds is to be activated, the indication including an authentication device identifier;

locating the first one of the plurality of credential seeds to be activated in the pre-active data store based upon the authentication device identifier;

reading the first one of the plurality of credential seeds to be activated from the pre-active data store; and

activating the first one of a the plurality of credential seeds by storing a copy of the first one of the plurality of credential seeds in an active data store in response.

16. The non-transitory computer readable medium of claim 15 storing a plurality of instructions that cause a computer to further perform a method comprising receiving a request to authenticate an one time password.

17. The non-transitory computer readable medium of claim 15 storing a plurality of instructions that cause a computer to further perform a method comprising authenticating a one time password.

Assignments (4)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2011
From: PEI, MINGLIANG
To: SYMANTEC, CORP.
Reel/Frame 026279/0345 →