IP Library Granted Patent US 9,369,290
Granted Patent B2
US 9,369,290 · App. 13/691,101 · Granted Jun 14, 2016

Challenge-response authentication using a masked response value

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,369,290
App. No.
13/691,101
Granted
Jun 14, 2016
Kind
B2
Abstract

Challenge-response authentication protocols are disclosed herein, including systems and methods for a first device to authenticate a second device. In one embodiment, the following operations are performed by the first device: (a) sending to the second device: (i) a challenge value corresponding to an expected response value known by the first device, and (ii) a hiding value; (b) receiving from the second device a masked response value; (c) obtaining an expected masked response value from the expected response value and the hiding value; and (d) determining whether the expected masked response value matches the masked response value received from the second device. The operations from the perspective of the second device are also disclosed, which in some embodiments include computing the masked response value using the challenge value, the hiding value, and secret information known to the second device.

Claims (28)

1. A method for a second device to be authenticated by a first device, the method performed by the second device and comprising:

the second device receiving from the first device a challenge value and a hiding value;

the second device computing a masked response value using the challenge value, the hiding value, and secret information known to the second device;

the second device sending to the first device the masked response value for comparison to an expected masked response value, wherein the secret information is not known to the first device, the expected masked response value is computed by the first device using the hiding value and an expected response value known by the first device and corresponding to the challenge value, the challenge value and the expected response value are loaded into memory of the first device at the time of manufacture of the first device; and

repeating the receiving, computing, and sending, when authentication of the second device is performed again, using a different hiding value received from the first device and the same challenge value received from the first device.

2. The method of claim 1 , wherein said computing the masked response value comprises first computing a response value using the challenge value and the secret information, and then computing the masked response value using the response value and the hiding value.

3. The method of claim 1 , wherein said computing the masked response value comprises first computing a cryptographic hash of a message comprising the challenge value and the secret information to obtain a response value, and then computing a cryptographic hash of another message comprising the response value and the hiding value to obtain the masked response value.

4. The method of claim 3 , wherein the cryptographic hash used to obtain the response value is the same as the cryptographic hash used to obtain the masked response value.

5. The method of claim 1 , wherein said computing the masked response value comprises computing a cryptographic hash of a message comprising the challenge value, the hiding value, and the secret information.

6. The method of claim 5 , wherein the cryptographic hash is a progressive cryptographic hash and is the same as a cryptographic hash used by the first device to compute the expected masked response value.

7. The method of claim 1 , wherein the first device is a mobile device and the second device is a battery.

8. A device comprising:

a memory configured to store secret information;

an interface configured to receive from another device a challenge value and a hiding value, and to send to the another device a masked response value for comparison to an expected masked response value, wherein the secret information is not known to the another device, the expected masked response value is computed by the another device using the hiding value and an expected response value known by the another device and corresponding to the challenge value, the challenge value and the expected response value are loaded into memory of the another device at the time of manufacture of the another device; and

a processor configured to compute the masked response value using the challenge value, the hiding value, and the secret information;

wherein the interface is further configured to receive from the another device different hiding values, such that a subsequent different hiding value and the same challenge value is received from the another device when authentication of the device is performed again, and said processor is configured to compute a subsequent masked response value using the subsequent different hiding value, the same challenge value, and the secret information.

9. The device of claim 8 , wherein the processor is configured to compute the masked response value by first computing a response value using the challenge value and the secret information, and then computing the masked response value using the response value and the hiding value.

10. The device of claim 8 , wherein the processor is configured to compute the masked response value by first computing a cryptographic hash of a message comprising the challenge value and the secret information to obtain a response value, and then computing a cryptographic hash of another message comprising the response value and the hiding value to obtain the masked response value.

11. The device of claim 8 , wherein the processor is configured to compute the masked response value by computing a cryptographic hash of a message comprising the challenge value, the hiding value, and the secret information.

12. The device of claim 8 , wherein the device is a battery and the another device is a mobile device.

13. A processor readable medium having stored thereon processor readable instructions for a second device to be authenticated by a first device; the processor readable instructions, when executed, cause the second device to perform operations comprising:

receiving from the first device a challenge value and a hiding value;

computing a masked response value using the challenge value, the hiding value, and secret information known to the second device;

sending to the first device the masked response value for comparison to an expected masked response value, wherein the secret information is not known to the first device, the expected masked response value is computed by the first device using the hiding value and an expected response value known by the first device and corresponding to the challenge value, and the challenge value and the expected response value are loaded into memory of the first device at the time of manufacture of the first device; and

repeating the receiving, computing, and sending, when authentication of the second device is performed again, using a different hiding value received from the first device and the same challenge value received from the first device.

14. The processor readable medium of claim 13 , wherein said computing the masked response value comprises either:

first computing a cryptographic hash of a message comprising the challenge value and the secret information to obtain a response value, and then computing a cryptographic hash of another message comprising the response value and the hiding value to obtain the masked response value; or

computing a cryptographic hash of a message comprising the challenge value, the hiding value, and the secret information.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2013
From: LAMBERT, ROBERT JOHN
To: CERTICOM CORP.
Reel/Frame 030244/0214 →