IP Library Granted Patent US 9,594,896
Granted Patent B2
US 9,594,896 · App. 13/723,429 · Granted Mar 14, 2017

Two factor authentication using near field communications

Inventor: Anthony Rosati (Ottawa, CA)
Assignee: BlackBerry Limited
G06F21/44G06F21/35G07C9/00174G07C9/00309H04W4/008H04W12/06G07C2009/0042G07C2209/14H04L63/0492H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,594,896
App. No.
13/723,429
Granted
Mar 14, 2017
Kind
B2
Abstract

There is provided a method and apparatus for communications using short range communications such as Near Field Communications (NFC). A mobile device comprising an NFC subsystem provides a dynamic credential for use to login to a network requiring two factor authentication. A terminal used for logging in to the network is associated with an NFC reader, and bringing the NFC device in proximity to the NFC reader provides the terminal with the dynamic credential required for two factor authentication.

Claims (54)

1. A method at a short range communications capable device for providing a dynamic credential to a terminal controlling access to a resource, the method comprising:

receiving, utilizing near field communications, an application identifier, a current time, and a random number from a reader associated with the terminal;

retrieving an encryption key, the encryption key corresponding to the application identifier;

transmitting, to the terminal, a response including a device identifier and the random number signed with the encryption key;

executing an applet on a secure element of the short range communications capable device, the applet corresponding to the application identifier;

computing, with the applet, the dynamic credential based on the current time; and

transmitting the dynamic credential to the reader;

wherein access to the resource is provided upon transmitting a valid dynamic credential and a valid signature corresponding to the signed random number; and

wherein the application identifier indicates two factor authentication.

2. The method of claim 1 , wherein the dynamic credential is updated periodically.

3. The method of claim 1 , wherein the short range communications capable device includes a powered timer circuit.

4. The method of claim 1 , wherein the short range communications capable device is a near field communications (NFC) capable device, including an NFC subsystem powered by induction when placed in proximity to the reader.

5. The method of claim 1 , wherein the encryption key is stored in a secure element of the short range communications capable device.

6. The method of claim 1 , further comprising receiving an indication at the short range communications capable device, that authentication was successful.

7. The method of claim 1 , wherein the response includes the dynamic credential in a payload field.

8. The method of claim 1 , wherein the dynamic credential is for a login to a network requiring two factor authentication.

9. The method of claim 1 wherein the short range communications capable device is a mobile communications device.

10. The method of claim 1 wherein the short range communications capable device is a dedicated dynamic credential providing device.

11. A short range communications capable device for providing a dynamic credential to a terminal controlling access to a resource, the short range communications capable device comprising:

an antenna;

a controller; and

at least one secure element,

wherein the antenna, controller and at least one secure element are configured to:

receive an application identifier, a current time, and a random number from a reader associated with the terminal;

retrieve an encryption key, the encryption key corresponding to the application identifier;

transmit, to the terminal, a response including a device identifier and the random number signed with the encryption key;

execute an applet on a secure element of the short range communications capable device, the applet corresponding to the application identifier;

compute, with the applet, the dynamic credential based on the current time; and

transmit the dynamic credential to the reader;

wherein access to the resource is provided upon transmitting a valid dynamic credential and a valid signature corresponding to the signed random number; and

wherein the application identifier indicates two factor authentication.

12. The short range communications capable device of claim 11 , wherein the dynamic credential is updated periodically.

13. The short range communications capable device of claim 11 , wherein the short range communications capable device includes a powered timer circuit.

14. The short range communications capable device of claim 11 , wherein the short range communications capable device is a near field communications (NFC) capable device powered by induction when placed in proximity to the reader.

15. The short range communications capable device of claim 11 , wherein the encryption key is stored in a secure element of the short range communications capable device.

16. The short range communications capable device of claim 11 , wherein the dynamic credential is for a login to a network requiring two factor authentication.

17. A non-transitory computer-readable medium having instructions stored thereon for execution by a processor of a short range communications capable device, the instructions comprising code for:

receiving, utilizing near field communications, an application identifier, a current time, and a random number from a reader associated with a terminal, the terminal controlling access to a resource;

retrieving an encryption key, the encryption key corresponding to the application identifier;

transmitting, to the terminal, a response including a device identifier and the random number signed with the encryption key;

executing an applet on a secure element of the short range communications capable device, the applet corresponding to the application identifier;

computing, with the applet, the dynamic credential based on the current time; and

transmitting the dynamic credential to the reader;

wherein access to the resource is provided upon transmitting a valid dynamic credential and a valid signature corresponding to the signed random number; and

wherein the application identifier indicates two factor authentication.

18. The non-transitory computer-readable medium of claim 17 , wherein the dynamic credential is updated periodically.

19. The non-transitory computer-readable medium of claim 17 , wherein the short range communications capable device includes a powered timer circuit.

20. The non-transitory computer-readable medium of claim 17 , wherein the short range communications capable device is a near field communications (NFC) capable device, including an NFC subsystem powered by induction when placed in proximity to the reader.

21. The non-transitory computer-readable medium of claim 17 , wherein the encryption key is stored in a secure element of the short range communications capable device.

22. The non-transitory computer-readable medium of claim 17 , wherein the instructions comprise code for receiving an indication at the short range communications capable device, that authentication was successful.

23. The non-transitory computer-readable medium of claim 17 , wherein the response includes the dynamic credential in a payload field.

24. The non-transitory computer-readable medium of claim 17 , wherein the dynamic credential is for a login to a network requiring two factor authentication.

25. The non-transitory computer-readable medium of claim 17 , wherein the short range communications capable device is a mobile communications device.

26. The non-transitory computer-readable medium of claim 17 , wherein the short range communications capable device is a dedicated dynamic credential providing device.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2012
From: ROSATI, ANTHONY
To: CERTICOM CORP.
Reel/Frame 029515/0876 →
Continuity (1)
Related Publication 20140181955A1 · Jun 26, 2014