IP Library Granted Patent US 9,083,527
Granted Patent B1
US 9,083,527 · App. 13/601,972 · Granted Jul 14, 2015

Using mobile data to establish a shared secret in second-factor authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,083,527
App. No.
13/601,972
Granted
Jul 14, 2015
Kind
B1
Abstract

A server computer system receives mobile device activity data from a mobile device. The server computer system verifies that the mobile device activity data matches mobile device activity data that is stored at the mobile device and generates a shared secret at the server computer system using the received mobile device activity data. The shared secret at the server computer system matches a shared secret generated at the mobile device.

Claims (43)

1. A method comprising:

receiving, by a server computer system, mobile device activity data from a mobile device;

verifying that the mobile device activity data matches mobile device activity data that is stored at the mobile device, wherein the mobile device activity data comprises mobile device location data, mobile device usage data, mobile application usage data, and mobile application inventory data;

generating a shared secret at the server computer system using the received mobile device activity data, wherein the shared secret at the server computer system matches a shared secret generated at the mobile device; and

sending a message to the mobile device indicating criteria for the mobile device to use to generate a shared secret at the mobile device, wherein the criteria comprises at least one of the mobile device activity data to use to generate the shared secret, one or more sampling algorithms to use to generate the shared secret, a length of the shared secret, or an order of the mobile device activity data to use to generate the shared secret.

2. The method of claim 1 , wherein the mobile device activity data is received via a secure transmission protocol.

3. The method of claim 1 , further comprising:

receiving additional mobile device activity data from the mobile device;

verifying that the additional mobile device activity data matches additional mobile device activity data that is stored at the mobile device; and

generating a new shared secret at the server computer system using the additional mobile device activity data, wherein the new shared secret at the server computer system matches a new shared secret generated at the mobile device.

4. A method comprising:

sending, by a mobile device, mobile device activity data to a server computer system, wherein the mobile device activity data comprises mobile device location data, mobile device usage data, mobile application usage data, and mobile application inventory data;

verifying that the mobile device activity data sent by the mobile device matches mobile device activity data that is received at the server computer system;

receiving a message from the server computer system indicating criteria to use to generate a shared secret at the mobile device, wherein the criteria comprises at least one of the mobile device activity data to use to generate the shared secret, one or more sampling algorithms to use to generate the shared secret, a length of the shared secret, or an order of the mobile device activity data to use to generate the shared secret; and

generating the shared secret at the mobile device using the mobile device activity data, wherein the shared secret generated at the mobile device matches a shared secret generated at the server computer system.

5. The method of claim 4 , wherein the mobile device activity data is sent via a secure transmission protocol.

6. The method of claim 4 , further comprising:

sending additional mobile device activity data to the server computer system;

verifying that the additional mobile device activity data sent by the mobile device matches additional mobile device activity data that is received at the server computer system; and

generating a new shared secret at the mobile device using the additional mobile device activity data, wherein the new shared secret generated at the mobile device matches a new shared secret generated at the server computer system.

7. A system comprising:

a first memory; and

a first processing device coupled with the memory to:

receive mobile device activity data from a second processing device;

verify that the mobile device activity data matches mobile device activity data that is stored in a second memory coupled to the second processing device, wherein the mobile device activity data comprises mobile device location data, mobile device usage data, mobile application usage data, and mobile application inventory data;

generate a shared secret using the received mobile device activity data, wherein the shared secret is to match a shared secret generated by the second processing device; and

send a message to the second processing device indicating criteria for the second processing device to use to generate the shared secret, wherein the criteria comprises at least one of the mobile device activity data to use to generate the shared secret, one or more sampling algorithms to use to generate the shared secret, a length of the shared secret, or an order of the mobile device activity data to use to generate the shared secret.

8. The system of claim 7 , wherein the mobile device activity data is received via a secure transmission protocol.

9. The system of claim 7 , wherein the first processing device is further configured to:

receive additional mobile device activity data from the second processing device;

verify that the additional mobile device activity data matches additional mobile device activity data that is stored in the second memory; and

generate a new shared secret using the additional mobile device activity data, wherein the new shared secret matches a new shared secret generated by the second processing device.

10. The system of claim 7 , wherein the criteria are associated with the mobile device activity data.

11. A non-transitory computer readable storage medium including instructions that, when executed by a processor device, cause the processing device to perform a method comprising:

receiving mobile device activity data from a mobile device;

verifying that the mobile device activity data matches mobile device activity data that is stored at the mobile device, wherein the mobile device activity data comprises mobile device location data, mobile device usage data, mobile application usage data, and mobile application inventory data;

generating a shared secret at a server computer system using the received mobile device activity data, wherein the shared secret at the server computer system matches a shared secret generated at the mobile device; and

sending a message to the mobile device indicating criteria for the mobile device to use to generate the shared secret at the mobile device, wherein the criteria comprises at least one of the mobile device activity data to use to generate the shared secret, one or more sampling algorithms to use to generate the shared secret, a length of the shared secret, or an order of the mobile device activity data to use to generate the shared secret.

12. The non-transitory computer readable storage medium of claim 11 , wherein the mobile device activity data is received via a secure transmission protocol.

13. The non-transitory computer readable storage medium of claim 11 , further comprising:

receiving additional mobile device activity data from the mobile device;

verifying that the additional mobile device activity data matches additional mobile device activity data that is stored at the mobile device; and

generating a new shared secret at the server computer system using the additional mobile device activity data, wherein the new shared secret at the server computer system matches a new shared secret generated at the mobile device.

Assignments (4)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2012
From: MCCORKENDALE, BRUCE; COOLEY, SHAUN
To: SYMANTEC CORPORATION
Reel/Frame 028889/0207 →