IP Library Granted Patent US 9,379,894
Granted Patent B1
US 9,379,894 · App. 13/917,112 · Granted Jun 28, 2016

Authentication using cryptographic value derived from a shared secret of a near field communication tag

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,379,894
App. No.
13/917,112
Granted
Jun 28, 2016
Kind
B1
Abstract

An apparatus comprises a first processing device comprising near field communication (NFC) interface circuitry, a memory and a processor coupled to the memory. The first processing device is configured to establish an NFC connection with an NFC tag using the NFC interface circuitry, receive a shared secret established between the NFC tag and an authentication server in an authentication protocol, and present a cryptographic value derived from the shared secret to a second processing device. The cryptographic value is utilizable by the second processing device for authenticating to the authentication server.

Claims (97)

1. An apparatus comprising:

a first processing device comprising:

near field communication (NFC) interface circuitry;

a memory; and

a processor coupled to the memory;

the first processing device being configured to:

establish an NFC connection with an NFC tag using the NFC interface circuitry;

utilize the NFC tag to perform an authentication protocol with an authentication server;

receive a shared secret, the shared secret being established between the NFC tag and the authentication server in conjunction with the authentication protocol; and

present a cryptographic value derived from the shared secret to a second processing device other than the NFC tag, the second processing device not being configured to communicate with the NFC tag;

wherein the cryptographic value is utilizable by the second processing device for authenticating to the authentication server;

wherein at least one of a length and a complexity of the cryptographic value presented to the second processing device is determined based on a mode of connection between the first processing device and the second processing device; and

wherein said at least one of the length and the complexity of the cryptographic value is greater in a connected mode than in an unconnected mode.

2. The apparatus of claim 1 , wherein the first processing device further comprises a display, the first processing device being configured to present the cryptographic value on the display.

3. The apparatus of claim 1 , wherein the first processing device further comprises a network interface, the first processing device being configured to present the cryptographic value by:

utilizing the network interface to establish a network connection to the second processing device; and

transmitting the cryptographic value over the network connection.

4. The apparatus of claim 3 , wherein the network connection comprise a Bluetooth connection.

5. The apparatus of claim 1 , wherein the cryptographic value comprises a passcode utilizable for authenticating to the authentication server.

6. The apparatus of claim 1 , wherein the first processing device is configured to authenticate to the authentication server by presenting the shared secret to the authentication server.

7. The apparatus of claim 6 , wherein the first processing device is configured to receive the cryptographic value from the authentication server over a secure channel established responsive to the first processing device authenticating to the authentication server.

8. The apparatus of claim 1 , wherein the first processing device is configured to derive the cryptographic value from the shared secret.

9. The apparatus of claim 1 , wherein the second processing device does not have NFC interface circuitry.

10. The apparatus of claim 1 , wherein:

the connection mode between the first processing device and the second processing device comprises one of:

the connected mode wherein the first processing device and the second processing device are connected using a network connection and the cryptographic value is presented to the second processing device by transmitting the cryptographic value over the network connection; and

the unconnected mode wherein the first processing device and the second processing device are not connected using the network connection and the cryptographic value is presented to the second processing device by outputting the cryptographic value on a display of the first processing device.

11. The apparatus of claim 1 , wherein:

the connection mode between the first processing device and the second processing device comprises one of:

a first connected mode wherein the first processing device and the second processing device are connected using a trusted network connection and the cryptographic value is presented to the second processing device by transmitting the cryptographic value over the network connection;

a second connected mode wherein the first processing device and the second processing device are connected using an untrusted network connection and the cryptographic value is presented to the second processing device by outputting the cryptographic value on a display of the first processing device; and

the unconnected mode wherein the first processing device and the second processing device are not connected using the trusted network connection or the untrusted network connection and the cryptographic value is presented to the second processing device by outputting the cryptographic value on the display of the first processing device; and

said at least one of the length and the complexity of the cryptographic value is greater in the first connected mode than in the second connected mode and the unconnected mode.

12. A method comprising:

establishing, by a first processing device, a near field communication (NFC) connection with an NFC tag;

utilizing, by the first processing device, the NFC tag to perform an authentication protocol with an authentication server;

receiving, in the first processing device, a shared secret, the shared secret being established between the NFC tag and the authentication server in conjunction with the authentication protocol; and

presenting, by the first processing device, a cryptographic value derived from the shared secret to a second processing device other than the NFC tag, the second processing device not being configured to communicate with the NFC tag;

wherein the cryptographic value is utilizable by the second processing device for authenticating to the authentication server;

wherein at least one of a length and a complexity of the cryptographic value presented to the second processing device is determined based on a mode of connection between the first processing device and the second processing device; and

wherein said at least one of the length and the complexity of the cryptographic value is greater in a connected mode than in an unconnected mode.

13. A non-transitory processor-readable storage medium having instruction code embodied therein which when executed by a first processing device causes the first processing device to:

establish a near field communication (NFC) connection with an NFC tag;

utilize the NFC tag to perform an authentication protocol with an authentication server;

receive a shared secret, the shared secret being established between the NFC tag and the authentication server in conjunction with the authentication protocol; and

present a cryptographic value derived from the shared secret to a second processing device other than the NFC tag, the second processing device not being configured to communicate with the NFC tag;

wherein the cryptographic value is utilizable by the second processing device for authenticating to the authentication server;

wherein at least one of a length and a complexity of the cryptographic value presented to the second processing device is determined based on a mode of connection between the first processing device and the second processing device; and

wherein said at least one of the length and the complexity of the cryptographic value is greater in a connected mode than in an unconnected mode.

14. An apparatus comprising:

a first processing device comprising:

a memory; and

a processor coupled to the memory;

the first processing device being configured to:

obtain a cryptographic value from a second processing device; and

utilize the cryptographic value in authenticating to an authentication server;

wherein the cryptographic value is derived from a shared secret established between the authentication server and a near field communication (NFC) tag connected to a second processing device using an NFC connection, the NFC tag being distinct from the first processing device and the second processing device;

wherein the second processing device utilizes the NFC tag to perform an authentication protocol with the authentication server, the shared secret being established between the NFC tag and the authentication server in conjunction with the authentication protocol;

wherein the first processing device is not configured to communicate with the NFC tag;

wherein at least one of a length and a complexity of the cryptographic value obtained at the first processing device from the second processing device is determined based on a mode of connection between the first processing device and the second processing device; and

wherein said at least one of the length and the complexity of the cryptographic value is greater in a connected mode than in an unconnected mode.

15. The apparatus of claim 14 , wherein the first processing device does not have NFC interface circuitry.

16. The apparatus of claim 14 , wherein the cryptographic value comprises a passcode and utilizing the cryptographic value comprises transmitting the passcode to the authentication server.

17. The apparatus of claim 14 , wherein the cryptographic value is presented on a display of the second processing device and wherein the first processing device is configured to obtain the cryptographic value by receiving input from a user.

18. The apparatus of claim 14 , wherein the first processing device further comprises a network interface, the first processing device being configured to obtain the cryptographic value by:

utilizing the network interface to establish a network connection to the second processing device; and

receiving the cryptographic value over the network connection.

19. The apparatus of claim 18 , wherein the network connection comprises a Bluetooth connection.

20. A method comprising:

obtaining, by a first processing device, a cryptographic value from a second processing device; and

utilizing, by the first processing device, the cryptographic value in authenticating to an authentication server;

wherein the cryptographic value is derived from a shared secret established between the authentication server and a near field communication (NFC) tag connected to a second processing device using an NFC connection, the NFC tag being distinct from the first processing device and the second processing device;

wherein the second processing device utilizes the NFC tag to perform an authentication protocol with the authentication server, the shared secret being established between the NFC tag and the authentication server in conjunction with the authentication protocol;

wherein the first processing device is not configured to communicate with the NFC tag;

wherein at least one of a length and a complexity of the cryptographic value obtained at the first processing device from the second processing device is determined based on a mode of connection between the first processing device and the second processing device; and

wherein said at least one of the length and the complexity of the cryptographic value is greater in a connected mode than in an unconnected mode.

21. A non-transitory processor-readable storage medium having instruction code embodied therein which when executed by a first processing device causes the first processing device to:

obtain a cryptographic value from a second processing device; and

utilize the cryptographic value in authenticating to an authentication server;

wherein the cryptographic value is derived from a shared secret established between the authentication server and a near field communication (NFC) tag connected to a second processing device using an NFC connection, the NFC tag being distinct from the first processing device and the second processing device;

wherein the second processing device utilizes the NFC tag to perform an authentication protocol with the authentication server, the shared secret being established between the NFC tag and the authentication server in conjunction with the authentication protocol;

wherein the first processing device is not configured to communicate with the NFC tag;

wherein at least one of a length and a complexity of the cryptographic value obtained at the first processing device from the second processing device is determined based on a mode of connection between the first processing device and the second processing device; and

wherein said at least one of the length and the complexity of the cryptographic value is greater in a connected mode than in an unconnected mode.

22. An apparatus comprising:

a first processing device comprising:

near field communication (NFC) interface circuitry;

a memory; and

a processor coupled to the memory;

the first processing device being configured to:

establish an NFC connection with an NFC tag using the NFC interface circuitry;

utilize the NFC tag to perform an authentication protocol with an authentication server;

receive a shared secret established between the NFC tag and the authentication server in conjunction with the authentication protocol; and

present a cryptographic value derived from the shared secret to an authentication token other than the NFC tag, the authentication token not being configured to communicate with the NFC tag;

wherein the authentication token is configured to generate one-time passcodes from a seed value, the cryptographic value being utilizable by the authentication token for establishing the seed value;

wherein at least one of a length and a complexity of the cryptographic value presented to the authentication token is determined based on a mode of connection between the first processing device and the authentication token; and

wherein said at least one of the length and the complexity of the cryptographic value is greater in a connected mode than in an unconnected mode.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2013
From: LUO, GUOYING; JUELS, ARI; QIAO, YONG
To: EMC CORPORATION
Reel/Frame 031453/0299 →