IP Library Granted Patent US 10,367,642
Granted Patent B1
US 10,367,642 · App. 13/711,877 · Granted Jul 30, 2019

Cryptographic device configured to transmit messages over an auxiliary channel embedded in passcodes

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,367,642
App. No.
13/711,877
Granted
Jul 30, 2019
Kind
B1
Abstract

A first cryptographic device determines multiple sets of passcodes for possible release in association with a corresponding one of a plurality of epochs, and transmits a message to a second cryptographic device over an auxiliary channel embedded in one or more passcodes released by the first cryptographic device to the second cryptographic device. For example, the first cryptographic device can determine multiple sets of passcodes by precomputing and storing the multiple sets of passcodes, or by generating one or more data sets from which the multiple sets of passcodes can be computed. The first cryptographic device transmits the message over the auxiliary channel by selecting a particular one of the multiple sets of passcodes based on content of the message and releasing a passcode from the selected set. The first cryptographic device may comprise an authentication token and the second cryptographic device may comprise an authentication server.

Claims (44)

1. A method comprising:

determining multiple sets of passcodes in a first cryptographic device, the multiple sets comprising respective different valid passcodes for possible release in association with a given one of a plurality of epochs;

determining a message to communicate from the first cryptographic device to a second cryptographic device in conjunction with the given epoch;

selecting a particular one of the multiple sets of passcodes based on content of said message;

releasing a passcode associated with the given epoch from the selected set; and

communicating said message over an auxiliary channel embedded in the released passcode, wherein communicating said message comprises transmitting the released passcode from the first cryptographic device to the second cryptographic device.

2. The method of claim 1 wherein determining multiple sets of passcodes comprises precomputing and storing the multiple sets of passcodes in the first cryptographic device.

3. The method of claim 1 wherein determining multiple sets of passcodes comprises generating one or more data sets from which the multiple sets of passcodes can be computed.

4. The method of claim 1 wherein for the given epoch, denoted as epoch t, a message m t is communicated over the auxiliary channel by conditioning selection of the particular one of the multiple sets of passcodes on message m t and releasing a particular passcode P t from the selected set of passcodes in association with epoch t.

5. The method of claim 4 wherein a given one of the multiple sets of passcodes is of the form {P 1 , . . . , P n }, where P t =ƒ κ (t) for 1≤t≤n, t denotes a current one of the plurality of epochs, n denotes the number of passcodes in the given set, and ƒ κ (t) is a function that utilizes a secret key κ of the first cryptographic device, and further wherein the first cryptographic device releases passcode P t in association with epoch t.

6. The method of claim 5 wherein the message comprises a one-bit binary message m t ∈{0,1} and the multiple sets of passcodes comprise two sets of passcodes {P 1 (0) , . . . , P n (0) } and {P 1 (1) , . . . , P n (1) } and further wherein for epoch t communicating the message m t comprises releasing passcode P t ←P t (m t ) and then erasing P t (0) and P t (1) .

7. The method of claim 5 wherein compromise of the first cryptographic device allowing observation of a released passcode for epoch s<t does not allow determination of a corresponding message m s .

8. The method of claim 5 wherein an attacker is unable to alter message m t in an intercepted passcode P t =P t (m t ) without knowing P t (1-m t ) .

9. The method of claim 3 wherein the determining multiple sets of passcodes, determining the message to communicate and selecting comprise:

generating a set of data elements using a secret key of the first cryptographic device;

selecting a subset of data elements from the set of data elements;

identifying particular data elements in the subset of data elements based on the message; and

determining a passcode to be released in association with a current one of the epochs as a function of the particular data elements.

10. The method of claim 9 wherein generating the set of data elements comprises generating a data set D={d 0 , . . . , d n } of l-bit data items pseudorandomly from a seed σ where l and n denote security parameters.

11. The method of claim 10 wherein selecting a subset of data elements from the set of data elements comprises identifying a subset S t of k data elements for current epoch t from data set D.

12. The method of claim 11 wherein identifying particular data elements in the subset of data elements based on the message comprises identifying selected ones of the k data elements in S t based on a message m t .

13. The method of claim 12 wherein determining the passcode to be released in association with current epoch t comprises computing the passcode as an XOR function of the particular selected ones of the k data elements.

14. The method of claim 9 further comprising replacing the particular data elements with new data elements.

15. The method of claim 14 wherein replacing the particular data elements with new data elements comprises replacing the particular data elements with predetermined binary strings.

16. A computer program product comprising a processor-readable storage medium having embodied therein one or more software programs, wherein the one or more software programs when executed by a processor of the first cryptographic device cause the method of claim 1 to be performed.

17. An apparatus comprising:

a first cryptographic device comprising a processor coupled to a memory;

the first cryptographic device being configured:

to determine multiple sets of passcodes, the multiple sets comprising respective different valid passcodes for possible release in association with a given one of a plurality of epochs,

to determine a message to communicate from the first cryptographic device to a second cryptographic device in conjunction with the given epoch,

to select a particular one of the multiple sets of passcodes based on content of said message,

to release a passcode associated with the given epoch from the selected set, and

to communicate said message over an auxiliary channel embedded in the released passcode, wherein the first cryptographic device is configured to communicate said message by transmitting the released passcode from the first cryptographic device to the second cryptographic device.

18. The apparatus of claim 17 wherein the first cryptographic device comprises an authentication token and the second cryptographic device comprises an authentication server.

19. The apparatus of claim 18 wherein the authentication token comprises one of a hardware authentication token and a software authentication token.

20. A communication system comprising:

a plurality of processing devices configured to communicate over one or more networks;

first and second ones of the processing devices comprising respective first and second cryptographic devices;

the first cryptographic device being configured:

to determine multiple sets of passcodes, the multiple sets comprising respective different valid passcodes for possible release in association with a given one of a plurality of epochs,

to determine a message to communicate from the first cryptographic device to the second cryptographic device in conjunction with the given epoch,

to select a particular one of the multiple sets of passcodes based on content of said message,

to release a passcode associated with the given epoch from the selected set, and

to communicate said message over an auxiliary channel embedded in the released passcode, wherein the first cryptographic device is configured to communicate said message by transmitting the released passcode from the first cryptographic device to the second cryptographic device.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2013
From: JUELS, ARI
To: EMC CORPORATION
Reel/Frame 029761/0518 →