IP Library Granted Patent US 9,871,785
Granted Patent B1
US 9,871,785 · App. 13/828,503 · Granted Jan 16, 2018

Forward secure one-time authentication tokens with embedded time hints

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,871,785
App. No.
13/828,503
Granted
Jan 16, 2018
Kind
B1
Abstract

Forward-secure one-time authentication tokens are provided with embedded time hints. A token generates a passcode for presentation to an authentication server by determining a current state of the token; generating a user authentication passcode based on the current state, wherein the generated user authentication passcode comprises an embedded time hint; and communicating the generated user authentication passcode to the authentication server. The passcode may be generated with the embedded time hint, for example, each time a user authentication passcode is generated or upon demand when a user authentication passcode is generated. A server processes a user authentication passcode by receiving the user authentication passcode, wherein the received user authentication passcode comprises an embedded time hint; and determining a time interval to search for another user authentication passcode based on the embedded time hint.

Claims (86)

1. A token-side method for generating a passcode from a user authentication token for presentation to an authentication server, comprising:

determining a current state of said token;

generating, using said token, a user authentication passcode based on said current state, wherein said generated user authentication passcode comprises an embedded time hint not previously known to said authentication server, wherein said embedded time hint is embedded in said generated user authentication passcode when said generated user authentication passcode is generated; and

communicating said generated user authentication passcode to said authentication server, wherein said authentication server obtains said embedded time hint from said generated user authentication passcode and determines a time interval to search for another user authentication passcode based on said embedded time hint, wherein said communicating step employs one or more of (i) a verification-independent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated, and (ii) a verification-dependent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated and at least two independent forward-secure pseudorandom generators.

2. The method of claim 1 , wherein said generating step is performed each time a user authentication passcode is generated.

3. The method of claim 1 , wherein said generating step is performed upon demand when a user authentication passcode is generated.

4. The method of claim 3 , wherein said generating step is performed upon detection of a forward clock attack.

5. The method of claim 3 , further comprising the step of notifying said authentication server of said embedded time hint.

6. The method of claim 5 , wherein said notification comprises setting a flag.

7. The method of claim 1 , wherein said embedded time hint comprises an indication of a last used device time during a generation of a user authentication passcode.

8. The method of claim 1 , wherein said authentication server evaluates said embedded time hint upon one or more failed authentication attempts.

9. The method of claim 1 , wherein said authentication server evaluates said embedded time hint to reduce a search space for another user authentication passcode.

10. The method of claim 1 , wherein said embedded time hint is encrypted using a secret key.

11. The method of claim 1 , wherein said verification-dependent auxiliary channel and said user authentication passcode employ a second forward-secure pseudorandom generator of said at least two independent forward-secure pseudorandom generators that is independent of a first forward-secure pseudorandom generator employed by said verification-dependent auxiliary channel and said user authentication passcode.

12. The method of claim 11 , wherein said second forward-secure pseudorandom generator generates seeds based on a low-rate time based hash chain.

13. The method of claim 11 , wherein said second forward-secure pseudorandom generator generates seeds on-demand.

14. The method of claim 13 , wherein said second forward-secure pseudorandom generator generates seeds on-demand in a hash chain.

15. The method of claim 11 , wherein said second forward-secure pseudorandom generator is used to embed a time hint indicating a current epoch of said first forward-secure pseudorandom generator.

16. The method of claim 11 , wherein said authentication server evaluates a received passcode that failed using seeds generated by said first forward-secure pseudorandom generator by employing seeds generated by said second forward-secure pseudorandom generator.

17. The method of claim 16 , wherein said second forward-secure pseudorandom generator generates seeds on-demand in a hash chain and wherein said authentication server searches said seeds generated by said second forward-secure pseudorandom generator in a window of said hash chain.

18. The method of claim 16 , wherein said authentication server employs said embedded time hint to update a search space with respect to said first forward-secure pseudorandom generator if said received passcode is verified using said seeds generated by said second forward-secure pseudorandom generator.

19. A non-transitory machine-readable recordable storage medium for generating a user authentication passcode for presentation to an authentication server, wherein one or more software programs when executed by one or more processing devices implement the following steps:

determining a current state of said token;

generating, using said token, a user authentication passcode based on said current state, wherein said generated user authentication passcode comprises an embedded time hint not previously known to said authentication server, wherein said embedded time hint is embedded in said generated user authentication passcode when said generated user authentication passcode is generated; and

communicating said generated user authentication passcode to said authentication server, wherein said authentication server obtains said embedded time hint from said generated user authentication passcode and determines a time interval to search for another user authentication passcode based on said embedded time hint, wherein said communicating step employs one or more of (i) a verification-independent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated, and (ii) a verification-dependent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated and at least two independent forward-secure pseudorandom generators.

20. A token apparatus for generating a user authentication passcode for presentation to an authentication server, the apparatus comprising:

a memory; and

at least one hardware device, coupled to the memory, operative to implement the following steps:

determine a current state of said token;

generate, using said token apparatus, a user authentication passcode based on said current state, wherein said generated user authentication passcode comprises an embedded time hint not previously known to said authentication server, wherein said embedded time hint is embedded in said generated user authentication passcode when said generated user authentication passcode is generated; and

communicate said generated user authentication passcode to said authentication server, wherein said authentication server obtains said embedded time hint from said generated user authentication passcode and determines a time interval to search for another user authentication passcode based on said embedded time hint, wherein said communication employs one or more of (i) a verification-independent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated, and (ii) a verification-dependent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated and at least two independent forward-secure pseudorandom generators.

21. The token apparatus of claim 20 , wherein said generation is performed each time a user authentication passcode is generated.

22. The token apparatus of claim 20 , wherein said generation is performed upon demand when a user authentication passcode is generated.

23. The token apparatus of claim 22 , wherein said generation is performed upon detection of a forward clock attack.

24. The token apparatus of claim 22 , wherein said at least one hardware device is further configured to notify said authentication server of said embedded time hint.

25. The token apparatus of claim 24 , wherein said notification comprises setting a flag.

26. The token apparatus of claim 20 , wherein said embedded time hint comprises an indication of a last used device time during a generation of a user authentication passcode.

27. The token apparatus of claim 20 , wherein said authentication server evaluates said embedded time hint upon one or more failed authentication attempts.

28. The token apparatus of claim 20 , wherein said authentication server evaluates said embedded time hint to reduce a search space for another user authentication passcode.

29. The token apparatus of claim 20 , wherein said embedded time hint is encrypted using a secret key.

30. The token apparatus of claim 20 , wherein said verification-dependent auxiliary channel and said user authentication passcode employ a second forward-secure pseudorandom generator of said at least two independent forward-secure pseudorandom generators that is independent of a first forward-secure pseudorandom generator employed by said verification-dependent auxiliary channel and said user authentication passcode.

31. The token apparatus of claim 30 , wherein said second forward-secure pseudorandom generator generates seeds based on a low-rate time based hash chain.

32. The token apparatus of claim 30 , wherein said second forward-secure pseudorandom generator generates seeds on-demand.

33. The token apparatus of claim 32 , wherein said second forward-secure pseudorandom generator generates seeds on-demand in a hash chain.

34. The token apparatus of claim 30 , wherein said second forward-secure pseudorandom generator is used to embed a time hint indicating a current epoch of said first forward-secure pseudorandom generator.

35. The token apparatus of claim 30 , wherein said authentication server evaluates a received passcode that failed using seeds generated by said first forward-secure pseudorandom generator by employing seeds generated by said second forward-secure pseudorandom generator.

36. The token apparatus of claim 35 , wherein said second forward-secure pseudorandom generator generates seeds on-demand in a hash chain and wherein said authentication server searches said seeds generated by said second forward-secure pseudorandom generator in a window of said hash chain.

37. The token apparatus of claim 35 , wherein said authentication server employs said embedded time hint to update a search space with respect to said first forward-secure pseudorandom generator if said received passcode is verified using said seeds generated by said second forward-secure pseudorandom generator.

38. A server-side method for processing a user authentication passcode, comprising:

receiving a user authentication passcode, generated using a token, wherein said received user authentication passcode comprises an embedded time hint not previously known to said authentication server, wherein said embedded time hint is embedded in said generated user authentication passcode when said generated user authentication passcode is generated, wherein said receiving step employs one or more of (i) a verification-independent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated, and (ii) a verification-dependent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated and at least two independent forward-secure pseudorandom generators;

obtaining, by at least one processing device of said server, said embedded time hint from said received user authentication passcode; and

determining, by said at least one processing device of said server, a time interval to search for another user authentication passcode based on said embedded time hint.

39. The server-side method of claim 38 , further comprising the step of receiving a notification of said embedded time hint.

40. The server-side method of claim 39 , wherein said notification comprises a flag.

41. The server-side method of claim 38 , wherein said embedded time hint comprises an indication of a last used device time during a generation of a user authentication passcode.

42. The server-side method of claim 38 , further comprising the step of evaluating said embedded time hint upon one or more failed authentication attempts.

43. The server-side method of claim 38 , further comprising the step of evaluating said embedded time hint to reduce a search space for another user authentication passcode.

44. The server-side method of claim 38 , wherein said embedded time hint is encrypted using a secret key.

45. The server-side method of claim 38 , wherein said verification-dependent auxiliary channel and said user authentication passcode employ a second forward-secure pseudorandom generator of said at least two independent forward-secure pseudorandom generators that is independent of a first forward-secure pseudorandom generator employed by said verification-dependent auxiliary channel and said user authentication passcode.

46. The server-side method of claim 45 , wherein said second forward-secure pseudorandom generator generates seeds based on a low-rate time based hash chain.

47. The server-side method of claim 45 , wherein said second forward-secure pseudorandom generator generates seeds on-demand.

48. The server-side method of claim 45 , wherein said second forward-secure pseudorandom generator is used to embed a time hint indicating a current epoch of said first forward-secure pseudorandom generator.

49. The server-side method of claim 45 , wherein said authentication server evaluates a received passcode that failed using seeds generated by said first forward-secure pseudorandom generator by employing seeds generated by said second forward-secure pseudorandom generator.

50. The server-side method of claim 45 , wherein said authentication server employs said embedded time hint to update a search space with respect to said first forward-secure pseudorandom generator if said received passcode is verified using said seeds generated by said second forward-secure pseudorandom generator.

51. A non-transitory machine-readable recordable storage medium for processing a user authentication passcode, wherein one or more software programs when executed by one or more processing devices implement the following steps:

receiving a user authentication passcode, generated using a token, wherein said received user authentication passcode comprises an embedded time hint not previously known to an authentication server, wherein said embedded time hint is embedded in said generated user authentication passcode when said generated user authentication passcode is generated, wherein said receiving step employs one or more of (i) a verification-independent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated, and (ii) a verification-dependent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated and at least two independent forward-secure pseudorandom generators;

obtaining, by at least one processing device of said authentication server, said embedded time hint from said received user authentication passcode; and

determining, by said at least one processing device of said authentication server, a time interval to search for another user authentication passcode based on said embedded time hint.

52. A server apparatus for processing a user authentication passcode, the apparatus comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

receive a user authentication passcode, generated using a token, wherein said received user authentication passcode comprises an embedded time hint not previously known to said authentication server, wherein said embedded time hint is embedded in said generated user authentication passcode when said generated user authentication passcode is generated, wherein said receiving employs one or more of (i) a verification-independent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated, and (ii) a verification-dependent auxiliary channel that employs a plurality of auxiliary bits comprising at least one auxiliary bit indicating that said embedded time hint is activated and at least two independent forward-secure pseudorandom generators;

obtain, by said at least one processing device of said server apparatus, said embedded time hint from said received user authentication passcode; and

determine, by said at least one processing device of said server apparatus, a time interval to search for another user authentication passcode based on said embedded time hint.

53. The server apparatus of claim 52 , wherein said at least one hardware device is further configured to receive a notification of said embedded time hint.

54. The server apparatus of claim 53 , wherein said notification comprises a flag.

55. The server apparatus of claim 52 , wherein said embedded time hint comprises an indication of a last used device time during a generation of a user authentication passcode.

56. The server apparatus of claim 52 , wherein said at least one hardware device is further configured to evaluate said embedded time hint upon one or more failed authentication attempts.

57. The server apparatus of claim 52 , wherein said at least one hardware device is further configured to evaluate said embedded time hint to reduce a search space for another user authentication passcode.

58. The server apparatus of claim 52 , wherein said embedded time hint is encrypted using a secret key.

59. The server apparatus of claim 52 , wherein said verification-dependent auxiliary channel and said user authentication passcode employ a second forward-secure pseudorandom generator of said at least two independent forward-secure pseudorandom generators that is independent of a first forward-secure pseudorandom generator employed by said verification-dependent auxiliary channel and said user authentication passcode.

60. The server apparatus of claim 59 , wherein said second forward-secure pseudorandom generator generates seeds based on a low-rate time based hash chain.

61. The server apparatus of claim 59 , wherein said second forward-secure pseudorandom generator generates seeds on-demand.

62. The server apparatus of claim 59 , wherein said second forward-secure pseudorandom generator is used to embed a time hint indicating a current epoch of said first forward-secure pseudorandom generator.

63. The server apparatus of claim 59 , wherein said server apparatus evaluates a received passcode that failed using seeds generated by said first forward-secure pseudorandom generator by employing seeds generated by said second forward-secure pseudorandom generator.

64. The server apparatus of claim 59 , wherein said server apparatus employs said embedded time hint to update a search space with respect to said first forward-secure pseudorandom generator if said received passcode is verified using said seeds generated by said second forward-secure pseudorandom generator.

Assignments (22)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
RELEASE OF SECURITY INTEREST AT REEL 045482 FRAME 0395 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0314 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 9, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054362/0008 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 053701/0112 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2017
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 044410/0354 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2013
From: TRIANDOPOULOS, NIKOLAOS; JUELS, ARI; BRAINARD, JOHN
To: EMC CORPORATION
Reel/Frame 030764/0680 →