IP Library Granted Patent US 9,043,605
Granted Patent B1
US 9,043,605 · App. 14/031,628 · Granted May 26, 2015

Online and offline validation of tokencodes

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,043,605
App. No.
14/031,628
Granted
May 26, 2015
Kind
B1
Abstract

An apparatus comprises a processing device configured to receive a request for access to a given protected resource, to receive a tokencode for validating the request for access to the given protected resource, to determine whether the processing device is connected to a network, to send the tokencode to a remote server over the network for validation responsive to determining that the processing device is connected to the network, and to validate the tokencode in the processing device to access the given protected resource responsive to determining that the processing device is not connected to the network.

Claims (56)

1. An apparatus comprising:

a processing device configured to:

receive a request for access to a given protected resource;

receive, from an authentication token, a tokencode for validation in conjunction with the request for access to the given protected resource;

determine whether the processing device is connected to a network;

perform online validation responsive to determining that the processing device is connected to the network; and

perform offline validation responsive to determining that the processing device is not connected to the network by validating the received tokencode in the processing device;

wherein the processing device is configured to perform online validation by one of:

generating an additional tokencode in the processing device and sending the received tokencode and the additional tokencode to a server over the network for validation; and

generating an additional tokencode in the processing device based at least in part on the received tokencode and sending the additional tokencode to a server over the network for validation.

2. The apparatus of claim 1 , wherein the processing device comprises an authentication module configured to validate the received tokencode in the processing device.

3. The apparatus of claim 2 , wherein the authentication module runs in a trusted platform module of the processing device.

4. The apparatus of claim 2 , wherein the authentication module runs in a trusted execution environment of the processing device.

5. The apparatus of claim 2 , wherein the apparatus further comprises an embedded secure element, and wherein the authentication module runs on the embedded secure element.

6. The apparatus of claim 5 , wherein the embedded secure element comprises one of a smartcard and a subscriber identity module card.

7. The apparatus of claim 2 , wherein the additional tokencode is generated based at least in part on a cryptographic key provisioned in the authentication module.

8. The apparatus of claim 1 , wherein the received tokencode comprises a time-based tokencode and the processing device is configured to synchronize time with the authentication token for use in validating the received tokencode in the processing device and to synchronize time with the server for use in generating the additional tokencode sent to the server for validation.

9. The apparatus of claim 1 , wherein the received tokencode comprises an event-based tokencode and the processing device is configured to maintain a first counter for use in validating the received tokencode in the processing device and to maintain a second counter for use in generating the additional tokencode sent to the server for validation, the first counter being different than the second counter.

10. The apparatus of claim 1 , wherein the protected resource comprises another processing device.

11. The apparatus of claim 1 , wherein the processing device is configured to:

store data associated with one or more protected resources in a local memory;

sync the data stored in the local memory with data stored on the server over the network;

access the data stored on the server responsive to a successful online validation; and

access the data stored in the local memory responsive to a successful offline validation.

12. The apparatus of claim 11 , wherein the processing device is configured to access the local memory without connecting to the network.

13. The apparatus of claim 1 , wherein the processing device comprises one of: a smartphone, a tablet, a laptop computing device and a desktop computing device.

14. The apparatus of claim 1 , wherein the received tokencode and the additional tokencode are generated using at least one of: independent and unique keys; and different moving factors.

15. A method performed by a processing device comprising:

receiving a request for access to a given protected resource;

receiving, from an authentication token, a tokencode for validation in conjunction with the request for access;

determining whether the processing device is connected to a network;

performing online validation responsive to determining that the processing device is connected to the network; and

performing offline validation responsive to determining that the processing device is not connected to the network by validating the received tokencode in the processing device;

wherein performing online validation comprises one of:

generating an additional tokencode in the processing device and sending the received tokencode and the additional tokencode to a server over the network for validation; and

generating an additional tokencode in the processing device based at least in part on the received tokencode and sending the additional tokencode to a server over the network for validation.

16. The method of claim 15 , further comprising:

storing data associated with one or more protected resources in a local memory of the processing device;

syncing the data stored in the local memory with data stored on the server over the network;

accessing the data stored on the server responsive to a successful online validation; and

accessing the data stored in, the local memory responsive to a successful offline validation;

wherein the local memory is accessible without connecting to the network.

17. An article of manufacture comprising a processor-readable storage medium having processor-readable program code embodied therein, which, when executed by a processor, causes the processor to perform the method of claim 15 .

18. The method of claim 15 , wherein receiving the tokencode further comprises:

sending a challenge to the authentication token; and

receiving the tokencode from the authentication token.

19. A method performed by a processing device comprising:

receiving a request for access to a given protected resource;

receiving a tokencode for validating the request for access;

determining whether the processing device is connected to a network;

sending the tokencode to a server for validation responsive to determining that the processing device is connected to the network; and

validating the tokencode in the processing device responsive to determining that the processing device is not connected to the network;

wherein receiving the tokencode comprises receiving a first tokencode from an authentication token and generating a second tokencode in the processing device;

wherein sending the tokencode to the server comprises sending the first tokencode and the second tokencode to the server; and

wherein validation by the server comprises validating the first tokencode and the second tokencode.

20. The method of claim 19 , wherein the first tokencode and the second tokencode are generated using independent and unique keys and one or more moving factors, the one or more moving factors comprising at least one of a time value and a counter value.

Assignments (22)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2013
From: MACHANI, SALAH
To: EMC CORPORATION
Reel/Frame 031242/0235 →