IP Library Granted Patent US 8,984,602
Granted Patent B1
US 8,984,602 · App. 13/931,083 · Granted Mar 17, 2015

Protected resource access control utilizing credentials based on message authentication codes and hash chain values

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,984,602
App. No.
13/931,083
Granted
Mar 17, 2015
Kind
B1
Abstract

A processing device comprises a processor coupled to a memory and is configured to receive authentication information from a user, to generate a message authentication code based at least in part on the received authentication information, to generate a credential for a particular access control interval based at least in part on the message authentication code and an intermediate value of a hash chain, and to provide the credential to a user in order to allow the user to access a protected resource in the particular access control interval. The message authentication code may be generated over a message payload that includes a password provided by the user. The credential may comprise a combination of the message authentication code and the intermediate value of the hash chain.

Claims (64)

1. A method comprising:

receiving authentication information from a user;

generating a message authentication code based at least in part on the received authentication information;

associating intermediate values of a hash chain with respective ones of a plurality of access control intervals;

generating a credential for a particular one of the plurality of access control intervals based at least in part on the message authentication code and the intermediate value of the hash chain associated with the particular access control interval; and

providing the credential to a user in order to allow the user to access a protected resource in the particular access control interval;

wherein the receiving, generating, associating and providing are performed by at least one processing device of an information processing system.

2. The method of claim 1 wherein the receiving, generating, associating and providing are performed by a central manager implemented on said at least one processing device.

3. The method of claim 2 further comprising delegating from the central manager to another system entity an ability to generate credentials for one or more other ones of the plurality of access control intervals.

4. The method of claim 1 wherein the authentication information comprises a password provided by the user and wherein access to the protected resource in the particular access control interval requires the user to provide that password and the credential to an access control module associated with the protected resource.

5. The method of claim 1 wherein generating the message authentication code comprises generating the message authentication code using at least one key that is provisioned to the protected resource.

6. The method of claim 5 wherein values of the key used to generate the message authentication code are unique to the protected resource and are periodically rotated.

7. The method of claim 6 wherein the rotated key values comprise respective intermediate values of a hash chain.

8. The method of claim 1 wherein generating the message authentication code comprises:

forming a message payload comprising at least a password provided by the user; and

generating the message authentication code over the message payload.

9. The method of claim 8 wherein the message payload further comprises one or more of:

at least one field providing an indication of a time period for which the credential is valid;

a version indicator field;

a user identifier field; and

a role and activity field providing information for utilization by the protected resource to determine an appropriate level of access for the user.

10. The method of claim 1 wherein generating the credential comprises:

generating the credential in a binary format; and

encoding the credential into an encoded format having a reduced number of digits relative to the binary format;

wherein the credential is provided to the user in at least one of the binary format and the encoded format.

11. The method of claim 1 wherein the credential comprises a combination of the message authentication code and the intermediate value of the hash chain.

12. The method of claim 1 further comprising:

providing a final value of the hash chain to an access control module associated with the protected resource; and

storing an initial value of the hash chain in a secure manner.

13. The method of claim 1 wherein a given one of the intermediate values of the hash chain is generated by:

applying a hash function to a previous value of the hash chain a designated number of times; and

truncating a resulting value to a designated number of bits to obtain the given intermediate value.

14. The method of claim 1 wherein the credential comprises one or more of:

a user identifier field; and

a role and activity field providing information for utilization by the protected resource to determine an appropriate level of access for the user.

15. The method of claim 1 wherein the credential comprises at least one field providing an indication of a time period for which the credential is valid.

16. The method of claim 15 wherein said at least one field providing an indication of the time period for which the credential is valid comprises:

a start time field indicating a start time of the particular access control interval; and

a duration field indicating a duration of the particular access control interval.

17. A computer program product comprising a non-transitory processor-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device cause the method of claim 1 to be performed.

18. The method of claim 1 wherein one or more of the intermediate values of the hash chain associated with respective ones of the plurality of access control intervals comprise truncated values of the hash chain.

19. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the processing device being configured to receive authentication information from a user, to generate a message authentication code based at least in part on the received authentication information, to associate intermediate values of a hash chain with respective ones of a plurality of access control intervals, to generate a credential for a particular one of the plurality of access control intervals based at least in part on the message authentication code and the intermediate value of the hash chain associated with the particular access control interval, and to provide the credential to a user in order to allow the user to access a protected resource in the particular access control interval.

20. The apparatus of claim 19 wherein the protected resource comprises a storage array having an associated access control module implemented using said at least one processing device.

21. A method comprising:

receiving a credential from a user attempting to access a protected resource in a particular one of a plurality of access control intervals;

generating a message authentication code based at least in part on the credential;

utilizing the generated message authentication code to identify an intermediate value of a hash chain in the credential; and

if the identified intermediate value of the hash chain matches an expected intermediate value of the hash chain associated with the particular access control interval, granting the user access to the protected resource in the particular access control interval;

wherein intermediate values of the hash chain are associated with respective ones of the plurality of access control intervals; and

wherein the receiving, generating, utilizing and granting are performed by at least one processing device of an information processing system.

22. The method of claim 21 wherein if the identified intermediate value of the hash chain matches the expected intermediate value of the hash chain, the identified intermediate value is associated with a high water mark indicator.

23. The method of claim 21 wherein if the identified intermediate value of the hash chain matches the expected intermediate value of the hash chain, a stored final value of the hash chain is updated to the identified intermediate value.

24. The method of claim 21 wherein the receiving, generating, utilizing and granting are performed by an access control module implemented on said at least one processing device.

25. The method of claim 21 further comprising:

storing information indicative of a latest access control interval for which a valid credential has been received from a user;

comparing a current access control interval associated with a given received credential with the stored information indicative of the latest access control interval; and

denying access to the protected resource if the current access control interval precedes in time the latest access control interval indicated by the stored information.

26. A computer program product comprising a non-transitory processor-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device cause the steps of the method of claim 21 to be performed.

27. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the processing device being configured to receive a credential from a user attempting to access a protected resource in a particular one of a plurality of access control intervals, to generate a message authentication code based at least in part on the credential, to utilize the generated message authentication code to identify an intermediate value of a hash chain in the credential, and if the identified intermediate value of the hash chain matches an expected intermediate value of the hash chain associated with the particular access control interval, granting the user access to the protected resource in the particular access control interval, wherein intermediate values of the hash chain are associated with respective ones of the plurality of access control intervals.

28. The apparatus of claim 27 wherein the protected resource comprises a storage array having an associated access control module implemented using said at least one processing device.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2013
From: BAILEY, DANIEL V.; DUANE, WILLIAM M.; KATZ, AARON
To: EMC CORPORATION
Reel/Frame 031585/0887 →