IP Library Granted Patent US 9,083,515
Granted Patent B1
US 9,083,515 · App. 13/728,271 · Granted Jul 14, 2015

Forward secure pseudorandom number generation resilient to forward clock attacks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,083,515
App. No.
13/728,271
Granted
Jul 14, 2015
Kind
B1
Abstract

Methods and apparatus are provided for generation of forward secure pseudorandom numbers that are resilient to such forward clock attacks. A forward secure pseudorandom number is generated by obtaining a first state s i corresponding to a current leaf node ν i in a hierarchical tree, wherein the current leaf ν i produces a first pseudorandom number r i−1 ; updating the first state s i to a second state s i+t corresponding to a second leaf node ν i+t ; and computing a second pseudorandom number r i+t−1 corresponding to the second leaf node ν i+t , wherein the second pseudorandom number r i+t−1 is based on a forward clock reset index that identifies an instance of the hierarchical tree, wherein the instance of the hierarchical tree is incremented when one or more criteria indicating a forward clock attack are detected. The forward clock reset index can be encoded in a forward secure manner in the hierarchical tree.

Claims (42)

1. A method for generating a forward secure pseudorandom number, comprising:

obtaining a first state s i corresponding to a current leaf node ν i in a hierarchical tree, wherein said first state s i comprises a sequence of one or more seeds in said hierarchical tree, wherein said first state s i is stored in a memory of a hardware device as at least one data structure, wherein said at least one data structure comprises each of said one or more seeds of said first state s i and corresponding position information identifying a position of said corresponding seed in said hierarchical tree, wherein said current leaf ν i produces a first pseudorandom number r i−1 ;

updating said first state s i to a second state s i+t corresponding to a second leaf node ν i+t by processing said one or more seeds in said at least one data structure in a predefined order based on said corresponding position information to traverse a portion of the hierarchical tree to the second state s i+t ; and

computing a second pseudorandom number r i+t−1 corresponding to said second leaf node ν i+t wherein said second pseudorandom number r i+t−1 is based on a forward clock reset index that identifies an instance of said hierarchical tree, wherein said instance of said hierarchical tree is incremented when one or more criteria indicating a forward clock attack are detected.

2. The method of claim 1 , wherein said forward clock reset index is encoded in a forward secure manner in said hierarchical tree.

3. The method of claim 2 , wherein said forward clock reset index is encoded as a layer in said hierarchical tree.

4. The method of claim 1 , wherein said first state s i comprises said forward clock reset index and one or more of a current device time and a last used device time during a generation of said second pseudorandom number.

5. The method of claim 4 , further comprising the step of updating a last used device time to said current device time during a generation of said second pseudorandom number.

6. The method of claim 1 , wherein said criteria indicating a forward clock attack are detected comprise a current device time being less than a difference between a last used device time during a generation of said second pseudorandom number and a predefined threshold.

7. The method of claim 1 , further comprising the step of updating said forward clock reset index if said forward clock attack is detected.

8. The method of claim 1 , wherein a server identifies a matching passcode in a hierarchical tree identified by said forward clock reset index stored by said server in a range between a current server time less a threshold and said current server time plus said threshold.

9. The method of claim 8 , further comprising the step of updating a server time corresponding to a correct passcode to be equal to a time of said identified match.

10. The method of claim 8 , wherein said server conditionally accepts an access attempt and detects a small forward clock reset (FCR) if a time of said access attempt is less than or equal to a last server time corresponding to a correct passcode.

11. The method of claim 8 , wherein said server conditionally accepts an access attempt if a time of said access attempt is greater than a last server time corresponding to a correct passcode.

12. The method of claim 1 , wherein a server does not identify a matching passcode in a hierarchical tree identified by said forward clock reset index stored by said server in a range between a current server time less a threshold and said current server time plus said threshold.

13. The method of claim 1 , further comprising the step of said server searching a hierarchical tree identified by one or more increments to said forward clock reset index.

14. The method of claim 13 , wherein said server rejects an access attempt if said server does not identify a matching passcode in one of said hierarchical trees identified by said one or more increments to said forward clock reset index.

15. The method of claim 13 , wherein said server conditionally accepts an access attempt and detects a large forward clock reset (FCR) if said server identifies a matching passcode in one of said hierarchical trees identified by said one or more increments to said forward clock reset index.

16. The method of claim 15 , further comprising the step of updating a server time corresponding to a correct passcode to be equal to a time of said identified match.

17. The method of claim 15 , further comprising the step of incrementing said forward clock reset index by one or more increments.

18. The method of claim 1 , wherein one or more of said forward secure pseudorandom numbers are generated using a given one of a plurality of hierarchical trees and are processed by a corresponding one of a plurality of authentication servers.

19. The method of claim 1 , wherein said hierarchical tree comprises at least one chain comprised of a plurality of nodes on a given level of said hierarchical tree.

20. A non-transitory machine-readable recordable storage medium encoded with computer program instructions for generating a forward secure pseudorandom number, when executed by one or more processors, cause a computer to perform the following steps:

obtaining a first state s i corresponding to a current leaf node ν i in a hierarchical tree wherein said first state s i comprises a sequence of one or more seeds in said hierarchical tree, wherein said first state s i is stored in a memory of a hardware device as at least one data structure, wherein said at least one data structure comprises each of said one or more seeds of said first state s i and corresponding position information identifying a position of said corresponding seed in said hierarchical tree, wherein said current leaf ν i produces a first pseudorandom number r i−1 ;

updating said first state s i to a second state s i+t corresponding to a second leaf node ν i+t by processing said one or more seeds in said at least one data structure in a predefined order based on said corresponding position information to traverse a portion of the hierarchical tree to the second state s i+t ; and

computing a second pseudorandom number r i+t−1 corresponding to said second leaf node ν i+t , wherein said second pseudorandom number r i+t−1 is based on a forward clock reset index that identifies an instance of said hierarchical tree, wherein said instance of said hierarchical tree is incremented when one or more criteria indicating a forward clock attack are detected.

21. An apparatus for generating a forward secure pseudorandom number, the apparatus comprising:

a memory; and

at least one hardware device, coupled to the memory, operative to implement the following steps:

obtain a first state s i corresponding to a current leaf node ν i in a hierarchical tree, wherein said first state s i comprises a sequence of one or more seeds in said hierarchical tree, wherein said first state s i is stored in a memory of a hardware device as at least one data structure, wherein said at least one data structure comprises each of said one or more seeds of said first state s i and corresponding position information identifying a position of said corresponding seed in said hierarchical tree, wherein said current leaf ν i produces a first pseudorandom number r i−1 ;

update said first state s i to a second state s i+1 corresponding to a second leaf node ν i+t by processing said one or more seeds in said at least one data structure in a predefined order based on said corresponding position information to traverse a portion of the hierarchical tree to the second state s i+t ; and

compute a second pseudorandom number r i+t−1 corresponding to said second leaf node ν i+t , wherein said second pseudorandom number r i+t−1 is based on a forward clock reset index that identifies an instance of said hierarchical tree, wherein said instance of said hierarchical tree is incremented when one or more criteria indicating a forward clock attack are detected.

22. The apparatus of claim 21 , wherein said forward clock reset index is encoded in a forward secure manner in said hierarchical tree.

23. The apparatus of claim 22 , wherein said forward clock reset index is encoded as a layer in said hierarchical tree.

24. The apparatus of claim 21 , wherein said first state s i comprises said forward clock reset index and one or more of a current device time and a last used device time during a generation of said second pseudorandom number.

25. The apparatus of claim 24 , wherein said at least one hardware device is further configured to synchronize said current device time and a last used device time during a generation of said second pseudorandom number.

26. The apparatus of claim 21 , wherein said criteria indicating a forward clock attack are detected comprise a current device time being less than a difference between a last used device time during a generation of said second pseudorandom number and a predefined threshold.

27. The apparatus of claim 21 , wherein a server identifies a matching passcode in a hierarchical tree identified by said forward clock reset index stored by said server in a range between a current server time less a threshold and said current server time plus said threshold.

28. The apparatus of claim 21 , wherein a server does not identify a matching passcode in a hierarchical tree identified by said forward clock reset index stored by said server in a range between a current server time less a threshold and said current server time plus said threshold.

29. The apparatus of claim 28 , further comprising the step of said server searching a hierarchical tree identified by one or more increments to said forward clock reset index.

30. The apparatus of claim 29 , wherein said server rejects an access attempt if said server does not identify a matching passcode in one of said hierarchical trees identified by said one or more increments to said forward clock reset index.

31. The apparatus of claim 21 , wherein said hierarchical tree comprises at least one chain comprised of a plurality of nodes on a given level of said hierarchical tree.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →