IP Library Granted Patent US 9,230,075
Granted Patent B1
US 9,230,075 · App. 13/600,641 · Granted Jan 5, 2016

Multi-server authentication using proactivization journaling

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,230,075
App. No.
13/600,641
Granted
Jan 5, 2016
Kind
B1
Abstract

Secret values used in a multi-server authentication scheme are updated. Information is authenticated in a system comprising a plurality of processing devices each adaptable for communication with one or more other devices. The information is authenticated by generating at least first and second shares of a first password associated with a first device (such as a client device); storing the first and second shares in respective second and third devices (such as authentication server devices); updating the first and second shares using a secret value T; assigning a version number to the updated first and second shares; and upon submission of additional information associated with the first device to at least one of the second and third devices, the second and third devices utilizing the respective updated first and second shares for a given version number to collectively determine a correspondence of the additional information with the first password.

Claims (40)

1. A method for authenticating information in a system comprising a plurality of processing devices each adaptable for communication with one or more of the other devices, the method comprising the steps of:

generating at least first and second shares of a first password associated with a first device of the plurality of devices;

storing the first and second shares in respective second and third devices of the plurality of devices;

updating the first and second shares using a secret value;

assigning a version number to said updated first and second shares; and

upon submission of additional information associated with the first device to at least one of the second and third devices, the second and third devices (i) exchange a given version number for the respective updated first and second shares during the authentication, and (ii) utilize the respective updated first and second shares for said given version number to collectively determine a correspondence of the submitted additional information with the first password.

2. The method of claim 1 , wherein third and fourth shares are computed by the respective second and third devices as a function of their respective first and second shares and at least a portion of the submitted additional information.

3. The method of claim 1 , wherein the submitted additional information comprises a third share and a fourth share, the third share being delivered by the first device to the second device, the fourth share being delivered by the first device to the third device.

4. The method of claim 1 , wherein the first device comprises a client device and wherein the second and third devices comprise respective first and second servers connectable to the client device over a network.

5. The method of claim 1 , wherein the generating and storing steps provide a registration of the first password for subsequent authentication of the submitted additional information.

6. The method of claim 1 , wherein the first and second shares comprise respective first and second elements in an algebraic group, the composition of said first and second elements under an operator of said group yielding a representation of the first password.

7. The method of claim 4 , wherein the submitted additional information comprises third and fourth shares of a second password associated with the client device and wherein the first and second servers accept the submitted additional information as authentic if a first quantity and a second quantity are determined to be substantially equivalent, wherein the first quantity is generated by the first server as a function of the first and third shares and the second quantity is generated by the second server as a function of the second and fourth shares.

8. The method of claim 1 , wherein the first and second shares each comprise a representation of a corresponding information element from a set of information for one or more users, such that no single one of at least the second and third devices can feasibly determine the entire set of information.

9. The method of claim 1 , wherein the version numbers are monotonically increasing.

10. The method of claim 1 , wherein the step of updating the first and second shares comprises adding a hashed version of the secret value to a prior version of the first and second shares.

11. The method of claim 1 , wherein the step of updating the first and second shares comprises applying an exclusive OR function (XOR) to the secret value and a prior version of the first and second shares.

12. The method of claim 1 , further comprising the step of updating one or more of the first and second shares using the secret value if a desired version number does not exist.

13. The method of claim 1 , further comprising the steps of storing a first portion of a data secret on the second device with a version number and a second portion of the data secret on the third device with the version number and updating the first and second portions using a second secret value.

14. The method of claim 13 , further comprising the steps of authenticating the first device and providing the first and second portions for a given version number to the first device for reassembly of the data secret.

15. An apparatus for authenticating information in a system comprising a plurality of processing devices each adaptable for communication with one or more of the other devices, the apparatus comprising:

a memory; and

at least one hardware device, coupled to the memory, operative to:

generate at least first and second shares of a first password associated with a first device of the plurality of devices;

store the first and second shares in respective second and third devices of the plurality of devices;

update the first and second shares using a secret value;

assign a version number to said updated first and second shares; and

upon submission of additional information associated with the first device to at least one of the second and third devices, the second and third devices (i) exchange a given version number for the respective updated first and second shares during the authentication, and (ii) utilize the respective updated first and second shares for said given version number to collectively determine a correspondence of the submitted additional information with the first password.

16. The apparatus of claim 15 , wherein the generation and storage of the first and second shares provide a registration of the first password for subsequent authentication of the submitted additional information.

17. The apparatus of claim 15 , wherein the version numbers are monotonically increasing.

18. The apparatus of claim 15 , wherein the first and second shares are updated by adding a hashed version of the secret value to a prior version of the first and second shares.

19. The apparatus of claim 15 , wherein the first and second shares are updated by applying an exclusive OR function (XOR) to the secret value and a prior version of the first and second shares.

20. The apparatus of claim 15 , wherein said at least one hardware device is further configured to update one or more of the first and second shares using the secret value if a desired version number does not exist.

21. The apparatus of claim 15 , wherein said at least one hardware device is further configured to store a first portion of a data secret on the second device with a version number and a second portion of the data secret on the third device with the version number and update the first and second portions using a second secret value.

22. The apparatus of claim 21 , wherein said at least one hardware device is further configured to authenticate the first device and provide the first and second portions for a given version number to the first device for reassembly of the data secret.

23. An article of manufacture for authenticating information in a system comprising a plurality of processing devices each adaptable for communication with one or more of the other devices, comprising a tangible machine readable recordable medium containing one or more programs which when executed implement the steps of:

generating at least first and second shares of a first password associated with a first device of the plurality of devices;

storing the first and second shares in respective second and third devices of the plurality of devices;

updating the first and second shares using a secret value-T;

assigning a version number to said updated first and second shares; and

upon submission of additional information associated with the first device to at least one of the second and third devices, the second and third devices (i) exchange a given version number for the respective updated first and second shares during the authentication, and (ii) utilize the respective updated first and second shares for said given version number to collectively determine a correspondence of the submitted additional information with the first password.

Assignments (20)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2012
From: ROBINSON, PETER; BROWN, JAIMEE; YOUNG, ERIC
To: EMC CORPORATION
Reel/Frame 029297/0486 →