IP Library Granted Patent US 8,904,504
Granted Patent B2
US 8,904,504 · App. 13/755,943 · Granted Dec 2, 2014

Remote keychain for mobile devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,904,504
App. No.
13/755,943
Granted
Dec 2, 2014
Kind
B2
Abstract

An app of a mobile device registers the mobile device for a remote credential server (RCS) and receives a device token. When a credential for a remote asset is supplied on the mobile device it is routed to the RCS and stored external to the mobile device but referenced on the mobile device via an asset token. When the credential is needed, the device token and the asset token permit the RCS to authenticate and return the credential to or on behalf of the mobile device so that the mobile device can authenticate to and access the remote asset.

Claims (39)

1. A method implemented in a non-transitory machine-readable storage medium and processed by a device configured to perform the method, comprising:

requesting, by the device, a device token from a remote server;

receiving, by the device, the device token;

passing, by the device, the device token to a keychain application for storage in a keychain;

sending, by the device, a reference identifier and a credential to the remote server with the device token;

acquiring, by the device, an asset token linked to the credential and reference identifier; and

instructing, by the device, the keychain application to store the asset token and the reference identifier in the keychain; wherein instructing further includes ensuring the credential is deleted and removed from memory and storage on the device.

2. The method of claim 1 further comprising, executing, on the device, the method as a mobile device app that monitors calls made to and information produced from the keychain application.

3. The method of claim 1 further comprising:

providing, on the device, the reference identifier to the keychain application;

receiving, on the device, the device token and the asset token;

sending, from the device, the reference identifier, the device token, and the asset token to the remote server;

acquiring, on the device, the credential; and

using, from the device, the credential to authenticate to and access a remote asset.

4. The method of claim 3 , wherein acquiring the credential further includes obtaining the credential in an encrypted format from the remote server.

5. The method of claim 1 further comprising:

providing, on the device, the reference identifier to the keychain application;

receiving, on the device, the device token and the asset token;

sending, from the device, the reference identifier, the device token, and the asset token to the remote server; and

accessing, on the device, a remote asset after the remote server authenticates the device to the remote asset by providing the credential on behalf of the device to the remote asset or an authentication service of the remote asset.

6. The method of claim 1 further comprising, communicating, from the device, the reference identifier and the asset token to a mobile app that the mobile app can use with the remote server to authenticate to and access a remote asset using the credential managed by the remote server.

7. The method of claim 1 , wherein requesting further includes authenticating the device or a principal of the device to the remote server.

8. The method of claim 1 , wherein receiving the device token further includes obtaining a signed device token that is signed by the remote server.

9. The method of claim 1 , wherein passing further includes signing by the device the device token before passing to the keychain application for storage in the keychain.

10. The method of claim 1 , wherein sending further includes encrypting the credential before sending to the remote server.

11. The method of claim 1 , wherein sending further includes prompting a principal of the device to dynamically enter the credential for sending to the remote server.

12. A method implemented in a non-transitory machine-readable storage medium and processed by a server configured to perform the method, comprising:

registering, by the server, a mobile device and supplying a device token back to the mobile device;

storing, by the server, a reference identifier and a credential received from the mobile device, the reference identifier identifies a remote asset, and the credential provides authenticated access to the remote asset;

returning, by the server, an asset token back to the mobile device;

receiving, on the server, the device token, the reference identifier, and the asset token;

returning, by the server, the credential back to the mobile device;

receiving, on the server, a different device token for a different mobile device, the reference identifier, and the asset token; and

returning, by the server, the credential back to the different mobile device when policy permits.

13. The method of claim 12 further comprising:

receiving, on the server, the device token, the resource identifier, and the asset token; and

supplying, by the server, the credential to authenticate the mobile device or a principal associated with the mobile device to the remote asset.

14. The method of claim 12 , wherein storing further includes encrypting the credential with a secret associated with the mobile device or a principal of the mobile device before storing within an association on the server, the association between the resource identifier and the credential.

15. The method of claim 12 , wherein storing further includes decrypting the credential received from the mobile device and verifying a mobile device signature associated with the credential before storing within an association on the server, the association between the resource identifier and the credential.

Assignments (12)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 030323/0411 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034446/0384 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 030323/0401 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034446/0343 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2014
From: NOVELL, INC.
To: NETIQ CORPORATION
Reel/Frame 033553/0379 →
GRANT OF PATENT SECURITY INTEREST (FIRST LIEN) Recorded Apr 30, 2013
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 030323/0401 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded Apr 30, 2013
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 030323/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2013
From: BURCH, LLOYD L; ANGELO, MICHAEL F; MASOUD, BAHA
To: NOVELL, INC.
Reel/Frame 029746/0737 →