IP Library Granted Patent US 9,323,909
Granted Patent B1
US 9,323,909 · App. 13/708,343 · Granted Apr 26, 2016

Sharing a cryptographic device by partitioning challenge-response space

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,323,909
App. No.
13/708,343
Granted
Apr 26, 2016
Kind
B1
Abstract

Techniques, apparatus and articles of manufacture are provided herein. A method includes providing a first sub-set of authentication information from a set of authentication information associated with a first cryptographic device issued to a user to a second cryptographic device in connection with a first user authentication request responsive to a request from the user to access a first protected resource, wherein the first sub-set comprises a first set of N pre-computed passcodes and corresponding challenges, and providing a second sub-set of authentication information from the set of authentication information associated with the first cryptographic device to a third cryptographic device in connection with a second user authentication request responsive to a request from the user to access a second protected resource, wherein the second sub-set comprises a second set of N pre-computed passcodes and corresponding challenges.

Claims (46)

1. A method comprising:

partitioning a set of multiple pre-computed passcodes and multiple challenges corresponding thereto associated with a given authentication token issued to a given user into multiple non-overlapping sub-sets of authentication information associated with the given authentication token issued to the given user, wherein each respective one of the multiple non-overlapping sub-sets of authentication information comprises (i) one or more distinct pre-computed passcodes selected from the multiple pre-computed passcodes and (ii) one or more distinct challenges (a) selected from the multiple challenges and (b) corresponding to the selected one or more distinct pre-computed passcodes;

randomizing each of the multiple non-overlapping sub-sets of authentication information associated with the given authentication token issued to the given user prior to providing a sub-set of authentication information to an authentication authority;

providing, from the multiple non-overlapping sub-sets of authentication information, a first randomized sub-set of authentication information associated with the given authentication token issued to the given user to a first authentication authority in connection with a first user authentication request responsive to a request from the given user to access a first protected resource; and

providing, from the multiple non-overlapping sub-sets of authentication information, a second randomized sub-set of authentication information associated with the given authentication token to a second authentication authority in connection with a second user authentication request responsive to a request from the given user to access a second protected resource.

2. The method of claim 1 , wherein the first authentication authority comprises a first service provider.

3. The method of claim 1 , wherein the second authentication authority comprises a second service provider.

4. The method of claim 1 , wherein the given authentication token comprises a hardware component.

5. The method of claim 1 , wherein the given authentication token comprises a software component resident on a device.

6. The method of claim 1 , further comprising:

eradicating a sub-set of authentication information upon revocation of the sub-set of authentication information from the corresponding authentication authority.

7. The method of claim 1 , further comprising:

providing one or more additional sub-sets of authentication information from the multiple pre-computed passcodes and multiple challenges corresponding thereto associated with the given authentication token issued to the given user to one or more additional authentication authorities in connection with one or more additional user authentication requests related to a request from the given user to access one or more additional protected resources.

8. An article of manufacture comprising a non-transitory processor-readable storage medium having processor-readable instructions tangibly embodied thereon which, when implemented, cause a processor to carry out the steps of the method of claim 1 .

9. A method comprising:

partitioning a set of multiple derived keys for passcode generation and multiple challenges corresponding thereto associated with a given authentication root key issued to a given user into multiple non-overlapping sub-sets of authentication information associated with the given authentication root key issued to the given user, wherein each of the multiple non-overlapping sub-sets of authentication information comprises (i) a given derived key, selected from the multiple derived keys, for passcode generation to be shared between a cryptographic device associated with the given user and a given authentication authority, and (ii) one or more of the multiple challenges corresponding thereto;

providing, from the multiple non-overlapping sub-sets of authentication information, a first sub-set of authentication information associated with the given authentication root key issued to the given user to a first authentication authority representing a first service provider in connection with a first user authentication request responsive to a request from the given user to access a first protected resource, wherein the first sub-set of authentication information comprises a first derived secret key for passcode generation to be shared between the cryptographic device associated with the given user and the first authentication authority; and

providing, from the multiple non-overlapping sub-sets of authentication information, a second sub-set of authentication information associated with the given authentication root key issued to the given user to a second authentication authority representing a second service provider in connection with a second user authentication request responsive to a request from the given user to access a second protected resource, wherein the second sub-set of authentication information comprises a second derived secret key for passcode generation to be shared between the cryptographic device associated with the given user and the second authentication authority.

10. An article of manufacture comprising a non-transitory processor-readable storage medium having processor-readable instructions tangibly embodied thereon which, when implemented, cause a processor to carry out the steps of the method of claim 9 .

11. The method of claim 9 , further comprising:

randomizing each of the multiple non-overlapping sub-sets of authentication information associated with the given authentication root key issued to the given user prior to providing a sub-set of authentication information to an authentication authority.

12. The method of claim 9 , further comprising:

eradicating a sub-set of authentication information upon revocation of the sub-set of authentication information from the corresponding authentication authority.

13. An apparatus comprising:

a memory; and

at least one processor coupled to the memory and operative for:

partitioning a set of multiple pre-computed passcodes and multiple challenges corresponding thereto associated with a given authentication token issued to a given user into multiple non-overlapping sub-sets of authentication information associated with the given authentication token issued to the given user, wherein each respective one of the multiple non-overlapping sub-sets of authentication information comprises (i) one or more distinct pre-computed passcodes selected from the multiple pre-computed passcodes and (ii) one or more distinct challenges (a) selected from the multiple challenges and (b) corresponding to the selected one or more distinct pre-computed passcodes;

randomizing each of the multiple non-overlapping sub-sets of authentication information associated with the given authentication token issued to the given user prior to providing a sub-set of authentication information to an authentication authority;

providing, from the multiple non-overlapping sub-sets of authentication information, a first randomized sub-set of authentication information associated with the given authentication token issued to the given user to a first authentication authority in connection with a first user authentication request responsive to a request from the given user to access a first protected resource; and

providing, from the multiple non-overlapping sub-sets of authentication information, a second randomized sub-set of authentication information associated with the given authentication token to a second authentication authority in connection with a second user authentication request responsive to a request from the given user to access a second protected resource.

14. The apparatus of claim 13 , wherein the given authentication token comprises a hardware component.

15. The apparatus of claim 13 , wherein the given authentication token comprises a software component resident on a device.

16. The apparatus of claim 13 , wherein the at least one processor is further operative for:

eradicating a sub-set of authentication information upon revocation of the sub-set of authentication information from the corresponding authentication authority.

17. The apparatus of claim 13 , wherein the at least one processor is further operative for:

providing one or more additional sub-sets of authentication information from the multiple pre-computed passcodes and multiple challenges corresponding thereto associated with the given authentication token issued to the given user to one or more additional authentication authorities in connection with one or more additional user authentication requests related to a request from the given user to access one or more additional protected resources.

18. An apparatus comprising:

a memory; and

at least one processor coupled to the memory and operative for:

partitioning a set of multiple derived keys for passcode generation and multiple challenges corresponding thereto associated with a given authentication root key issued to a given user into multiple non-overlapping sub-sets of authentication information associated with the given authentication root key issued to the given user, wherein each of the multiple non-overlapping sub-sets of authentication information comprises (i) a given derived key, selected from the multiple derived keys, for passcode generation to be shared between a cryptographic device associated with the given user and a given authentication authority, and (ii) one or more of the multiple challenges corresponding thereto;

providing, from the multiple non-overlapping sub-sets of authentication information, a first sub-set of authentication information associated with the given authentication root key issued to the given user to a first authentication authority representing a first service provider in connection with a first user authentication request responsive to a request from the given user to access a first protected resource, wherein the first sub-set of authentication information comprises a first derived secret key for passcode generation to be shared between the cryptographic device associated with the given user and the first authentication authority; and

providing, from the multiple non-overlapping sub-sets of authentication information, a second sub-set of authentication information associated with the given authentication root key issued to the given user to a second authentication authority representing a second service provider in connection with a second user authentication request responsive to a request from the given user to access a second protected resource, wherein the second sub-set of authentication information comprises a second derived secret key for passcode generation to be shared between the cryptographic device associated with the given user and the second authentication authority.

19. The apparatus of claim 18 , wherein the at least one processor is further operative for:

randomizing each of the multiple non-overlapping sub-sets of authentication information associated with the given authentication root key issued to the given user prior to providing a sub-set of authentication information to an authentication authority.

20. The apparatus of claim 18 , wherein the at least one processor is further operative for:

eradicating a sub-set of authentication information upon revocation of the sub-set of authentication information from the corresponding authentication authority.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2013
From: LUO, GUOYING; JUELS, ARI; BOWERS, KEVIN D.
To: EMC CORPORATION
Reel/Frame 029842/0371 →