IP Library Granted Patent US 9,071,424
Granted Patent B1
US 9,071,424 · App. 13/853,207 · Granted Jun 30, 2015

Token-based key generation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,071,424
App. No.
13/853,207
Granted
Jun 30, 2015
Kind
B1
Abstract

One embodiment is directed to a method performed by a computing device. The method includes (a) engaging in a handshake procedure with a remote second computing device to establish a secure channel, (b) generating a first encryption key using a first token having a secret seed, the first encryption key being the same as a second encryption key generated by the second computing device using a second token having the same secret seed, and (c) using the first encryption key to engage in encrypted communications with the second computing device. Other embodiments are directed to a computerized apparatus and a computer program product for performing a method similar to that described above.

Claims (74)

1. A method performed by a first computing device, the method comprising:

engaging in a handshake procedure with a remote second computing device to establish a secure channel;

generating a first encryption key using a first token having a secret seed, the first encryption key being the same as a second encryption key generated by the second computing device using a second token having the same secret seed; and

using the first encryption key to engage in encrypted communications with the second computing device,

wherein:

generating the first encryption key using the first token includes cryptographically combining the secret seed with a current time value;

engaging in the handshake procedure includes:

receiving a remote clock value within a handshake message from the second computing device, the remote clock value indicating a current clock value of a clock device in the possession of the second computing device;

obtaining the current time value from a local clock device in the possession of the first computing device; and

calculating a clock skew between the remote clock value and the current time value; and

cryptographically combining the secret seed with the current time value includes offsetting the current time value by the clock skew.

2. The method of claim 1 wherein the method further comprises:

generating a revised encryption key after a period of time by cryptographically combining the secret seed with a time value indicative of passage of the period of time; and

after generating the revised encryption key, using the revised encryption key instead of the first encryption key to engage in encrypted communications with the second computing device.

3. The method of claim 2 wherein the period of time is a fixed interval.

4. The method of claim 2 wherein the method further includes:

estimating an average amount of time it would take an attacker to guess the first encryption key using a key cracking procedure; and

setting the period of time to be less than the estimated average amount of time.

5. The method of claim 2 wherein the method further includes:

estimating an average amount of time it would take an attacker to guess the first encryption key using a key cracking procedure; and

setting the period of time to be an order of magnitude less than the estimated average amount of time.

6. The method of claim 2 wherein the method further includes:

estimating an average amount of time it would take an attacker to guess the first encryption key using a key cracking procedure; and

setting the period of time to be a factor less than the estimated average amount of time, a magnitude of the factor depending on a degree of sensitivity of the secure channel.

7. The method of claim 1 wherein

the handshake message from the second computing device is a Transport Layer Security (TLS) ServerKeyExchange message; and

receiving the remote clock value within the handshake message from the second computing device includes receiving the remote clock value within a key identity hint field of the TLS ServerKeyExchange message.

8. The method of claim 1 wherein both the first token and the second token are hardware tokens.

9. The method of claim 8 wherein the method further comprises, prior to engaging in the handshake procedure:

determining, by a central authority, that there is a need for the first computing device and the second computing device to securely communicate with each other; and

in response to determining, pre-provisioning, by the central authority, the first hardware token to the first computing device and the second hardware token to the second computing device.

10. The method of claim 1 wherein receiving the remote clock value within the handshake message from the second computing device includes receiving the remote clock value within a key identity hint field of the handshake message.

11. The method of claim 10 wherein the handshake message from the second computing device is a Transport Layer Security (TLS) ServerKeyExchange message.

12. A system comprising:

a first computing device;

a second computing device;

a network connecting the first computing device and the second computing device;

a first token device assigned to the first computing device, the first token device being programmed with a secret seed; and

a second token device assigned to the second computing device, the second token device being programmed with the same secret seed as the first token device;

wherein the first computing device is configured to:

engage in a handshake procedure with the second computing device to establish a secure channel;

generate a first encryption key using the first token device, the first encryption key being the same as a second encryption key generated by the second computing device using the second token; and

use the first encryption key to engage in encrypted

communications with the second computing device over the network;

wherein:

generating the first encryption key using the first token includes cryptographically combining the secret seed with a current time value;

engaging in the handshake procedure includes:

obtaining the current time value from a local clock device in the possession of the first computing device; and

sending the current time value within a handshake message to the second computing device for the second computing device to use in correcting a remote clock value indicating a current clock value of a clock device in the possession of the second computing device, wherein sending the current time value within the handshake message to the second computing device includes embedding the current time value within a key identity field of the handshake message.

13. The system of claim 12 wherein the secret seed is shared only by the first token device and the second token device, the secret seed not being shared by any other token device.

14. The system of claim 12 wherein:

the secret seed is shared by a third token device in addition the first token device and the second token device; and

engaging in the handshake procedure with the second computing device to establish the secure channel further includes:

sending a first unique identifier of the first computing device to the second computing device; and

receiving a second unique identifier of the second computer from the second computer; and

generating the first encryption key using the first token device further includes cryptographically combining the secret seed with both the first unique identifier and the second unique identifier.

15. The system of claim 12 wherein the handshake message sent to the second computing device is a Transport Layer Security (TLS) ClientKeyExchange message.

16. An apparatus comprising:

a clock;

a network interface for communicating with a remote computing device over a network;

a processor; and

memory, the memory storing a set of instructions which, when executed by the processor, cause the apparatus to perform the operations of:

engaging in a handshake procedure with the remote computing device to establish a secure channel;

generating a first encryption key using a first token having a secret seed, the first token being under the control of the apparatus, the first encryption key being the same as a second encryption key generated by the remote computing device using a second token having the same secret seed, the second token under the control of the remote computing apparatus; and

using the first encryption key to engage in encrypted communications with the remote computing device;

wherein:

generating the first encryption key using the first token includes cryptographically combining the secret seed with a current time value;

engaging in the handshake procedure includes:

receiving a remote clock value within a handshake message from the remote computing device, the remote clock value indicating a current clock value of a clock device in the possession of the remote computing device;

obtaining the current time value from the clock; and

calculating a clock skew between the remote clock value and the current time value; and

cryptographically combining the secret seed with the current time value includes offsetting the current time value by the clock skew.

17. The apparatus of claim 16 wherein receiving the remote clock value within the handshake message from the remote computing device includes receiving the remote clock value within a key identity hint field of the handshake message.

18. The apparatus of claim 17 wherein the handshake message from the remote computing device is a Transport Layer Security (TLS) ServerKeyExchange message.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →