IP Library Granted Patent US 9,547,761
Granted Patent B2
US 9,547,761 · App. 13/442,743 · Granted Jan 17, 2017

Wireless token device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,547,761
App. No.
13/442,743
Granted
Jan 17, 2017
Kind
B2
Abstract

A first computing device is detected as substantially collocated with a wireless token device, using a short-range wireless communication network and a connection is established between the first computing device and the token device over the short-range wireless network. Authentication data is sent to the first computing device from the token device over the short-range wireless network to authenticate the token device at the first computing device. Authentication of the token device permits data accessible through the first computing device to be made available to a holder of the token device and to be presented on a user interface of the first computing device. In some instances, the wireless token device may otherwise lack user interfaces for presenting the data itself.

Claims (51)

1. At least one non-transitory machine accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to:

detect a first computing device as substantially collocated with a wireless token device, using a short-range wireless communication network;

establish a connection between the first computing device and the token device over the short-range wireless network;

generate, at the token device, authentication data from a globally unique user identifier (GUUID) stored in secure memory of the token device, wherein the GUUID is assigned to a particular user; and

send the authentication data to the first computing device from the token device over the short-range wireless network, wherein the authentication data comprises first authentication data based on the GUUID to authenticate the particular user at the first computing device and further comprises second authentication data based on the GUUID to authenticate the first computing device to a storage device remote from the first computing device and token device,

wherein full access to the second authentication data by the first computing device is restricted and is to be forwarded by the first computing device to authenticate the first computing device to the storage device, authentication of the particular user permits data stored on the storage device to be accessed through the first computing device and presented on a user interface of the first computing device, and access to the data is restricted to a subset of users including the particular user.

2. The storage medium of claim 1 , wherein the second data is retrieved by the first computing device from a data store remote from the token device and first computing device wherein the full access to the second authentication data is restricted by encrypting the second authentication data.

3. The storage medium of claim 1 , wherein the authentication data is encrypted by a first public key paired to a private key of the first computing device.

4. The storage medium of claim 1 , wherein the instructions when executed on a machine, further cause the machine to:

detect a second computing device as substantially collocated with the token device, using a short-range wireless communication network;

establish a connection between the second computing device and the token device over a short-range wireless network;

send second authentication data to the second computing device from the token device over the short-range wireless network to authenticate the token device at the second computing device, wherein the second authentication data is to be generated from the globally unique user identifier stored in secure memory of the token device.

5. The storage medium of claim 4 , wherein the authentication data sent to the first computing device comprises first authentication data and the second authentication data is different from the first authentication data.

6. The storage medium of claim 1 , wherein the instructions when executed on a machine, further cause the machine to receive from the first computing device over the short-range wireless network second authentication data authenticating access to at least a portion of stored data on the wireless token device.

7. The storage medium of claim 1 , wherein a pairing relationship exists between the wireless token device and first computing device.

8. The storage medium of claim 7 , wherein the instructions when executed on a machine, further cause the machine to:

send a first digital certificate from the wireless token device to the first computing device verifying the identity of the wireless token device;

receive a second digital certificate at the wireless token device from the first computing device verifying the identity of the first computing device; and

establish parameters for subsequent communication between the wireless storage device and first computing device.

9. The storage medium of claim 1 , wherein the wireless token device lacks user interfaces for the presentation of the data.

10. At least one non-transitory machine accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to:

detect a wireless token device as substantially collocated with a particular computing device, using a short-range wireless communication network;

establish a connection between the particular computing device and the token device over the short-range wireless network;

receive authentication data at the first computing device from the token device over the short-range wireless network, wherein the authentication data is associated with a particular user and generated at the wireless token device from a globally unique user identifier assigned to the particular user and stored securely at the wireless token device;

authenticate the particular user based on the received authentication data; and

present particular data on a user interface of the particular computing device based on the authentication to the token device, wherein the particular data is restricted to a subset of users including the particular user.

11. The storage medium of claim 10 , wherein the instructions when executed on a machine, further cause the machine to receive the particular data from a remote data store based on the authentication of the token device to the particular computing device.

12. The storage medium of claim 11 , wherein the remote data store is a cloud-based data store.

13. The storage medium of claim 10 , wherein at least a portion of the particular data is stored locally on the particular computing device.

14. The storage medium of claim 10 , wherein the particular data is presented on a graphical display of the particular computing device.

15. The storage medium of claim 10 , wherein the particular data is presented using audio speakers of the particular computing device.

16. The storage medium of claim 10 , wherein the instructions when executed on a machine, further cause the machine to receive authentication inputs from a user on one or more user interfaces of the particular computing device, wherein authentication of the token device is further based on the received authentication inputs.

17. The storage medium of claim 10 , wherein the instructions when executed on a machine, further cause the machine to identify an association of a particular one of a plurality of user profiles maintained on the particular computing device with the token device, wherein the holder of the token device is provided access to the particular user profile.

18. A method comprising:

detecting a first computing device as substantially collocated with a wireless token device, using a short-range wireless communication network;

establishing a connection between the first computing device and the token device over the short-range wireless network;

generating, at the token device, authentication data from a globally unique user identifier (GUUID) stored in secure memory of the token device, wherein the GUUID is assigned to a particular user; and

sending the authentication data to the first computing device from the token device over the short-range wireless network, wherein the authentication data comprises first authentication data based on the GUUID to authenticate the particular user at the first computing device and further comprises second authentication data based on the GUUID to authenticate the first computing device to a storage device remote from the first computing device and token device,

wherein full access to the second authentication data by the first computing device is restricted and is to be forwarded by the first computing device to authenticate the first computing device to the storage device, authentication of the particular user permits data stored on the storage device to be accessed through the first computing device and presented on a user interface of the first computing device, and access to the data is restricted to a subset of users including the particular user.

19. A wireless token apparatus comprising:

a processor device;

a memory element comprising secure memory;

a short-range wireless network adapter adapted to:

detect a first computing device as substantially collocated with the apparatus, using a short-range wireless communication network;

establish a connection between the first computing device and the apparatus over the short-range wireless network; and

an authentication broker adapted to:

identify a globally unique user identifier assigned to a particular user, wherein the globally unique user identifier is stored in the secure memory of the wireless token apparatus;

generate authentication data from the globally unique user identifier, wherein the authentication data comprises first and second authentication data and the second authentication data is obscured to restrict full access to the second authentication data to a remote data store; and

send the authentication data to the first computing device over the short-range wireless network, wherein the first authentication data is to be used to authenticate the particular user at the first computing device and the second authentication data is to be used to authenticate the first computing device to the data store,

wherein full access to the second authentication data by the first computing device is restricted and is to be forwarded by the first computing device to authenticate the first computing device to the storage device, authentication of the particular user permits data stored on the storage device to be accessed through the first computing device and presented on a user interface of the first computing device, and access to the data is restricted to a subset of users including the particular user.

20. The apparatus of claim 19 , wherein the apparatus lacks user interfaces for the presentation of the data.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2012
From: SCHRECKER, SVEN
To: MCAFEE, INC.
Reel/Frame 028015/0608 →