IP Library Granted Patent US 9,172,698
Granted Patent B1
US 9,172,698 · App. 14/052,065 · Granted Oct 27, 2015

System and method for key generation in security tokens

Inventors: Philip G. Evans (Knoxville, TN); Travis S. Humble (Knoxville, TN); Nathanael R. Paul (Knoxville, TN); Raphael C. Pooser (Knoxville, TN); Stacy J. Prowell (Knoxville, TN)
Assignee: UT-Battelle, LLC
H04L63/0853G06F21/34H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,172,698
App. No.
14/052,065
Granted
Oct 27, 2015
Kind
B1
Abstract

Functional randomness in security tokens (FRIST) may achieve improved security in two-factor authentication hardware tokens by improving on the algorithms used to securely generate random data. A system and method in one embodiment according to the present invention may allow for security of a token based on storage cost and computational security. This approach may enable communication where security is no longer based solely on onetime pads (OTPs) generated from a single cryptographic function (e.g., SHA-256).

Claims (28)

1. A security token for generating a onetime pad (OTP), said security token being physically associated with an entity, wherein said OTP is used in conjunction with one or more factors to form an authentication request to authenticate the entity, said security token comprising:

a processor operable to execute preprogrammed instructions;

a memory operable to store a sequence of randomness and computer programmed instructions executable by said processor for performing the steps of:

segmenting said sequence of randomness into a plurality of seeds;

selecting a first seed from among said plurality of seeds;

hashing an input to generate an output of a first hash chain based on said first seed, said output of said first hash chain being based on at least one of a first plurality of hash functions, wherein said first hash chain is producible by successively hashing said output as said input, wherein, in said first hash chain, each of said first plurality of hash functions is applied to at least one input to generate at least one output;

iteratively hashing said input to generate said output, wherein said input for each successive hash is a previous output;

promoting each successive output generated by hashing said input as said OTP for use in the authentication request;

in response to a hash modification event, switching from said first hash chain to a second hash chain based on a second seed, wherein said second seed is selected from among said plurality of seeds, wherein an output of said second hash chain is based on at least one of a second plurality of hash functions, wherein said second hash chain is producible by successively hashing said output of said second hash chain as an input to at least one of said second plurality of hash functions, wherein, in said second hash chain, each of said second plurality of hash functions is applied to at least one input to generate at least one output;

wherein switching from said first hash chain to said second hash chain includes hashing said second seed according to at least one hash function of said second plurality of hash functions;

wherein one or more hash iterations occur in response to a new OTP event; and

wherein said first plurality of hash functions are different from one another, wherein said second plurality of hash functions are different from one another, and wherein said first seed of said first hash chain and said second seed of said second hash chain are both different from each other and selected from segments of said sequence of randomness.

2. The security token of claim 1 wherein said new OTP event includes at least one of a time-based event, a number of uses associated with said OTP exceeding a threshold, and said hash modification event.

3. The security token of claim 1 wherein said hash modification event includes at least one of a time-based event, a number of outputs used from said hash function exceeding a threshold, and reception of a remote command.

4. A security token for generating a onetime pad (OTP), said security token being physically associated with an entity, wherein said OTP is used in conjunction with one or more factors to form an authentication request to authenticate the entity, said security token comprising:

a processor operable to execute preprogrammed instructions;

a memory operable to store a sequence of randomness and computer programmed instructions executable by said processor for performing the steps of:

segmenting said sequence of randomness into a plurality of seeds;

selecting a first seed from among said plurality of seeds;

generating a first hash chain including at least two hash chain outputs based on said first seed, wherein, in said first hash chain, each of a first plurality of hash functions is applied to at least one input to generate at least one hash chain output, wherein said first plurality of hash functions are different from one another;

selecting a second seed from among said plurality of seeds, said second seed being different from said first seed;

generating a second hash chain including at least two hash chain outputs based on said second seed, wherein, in said second hash chain, each of said second plurality of hash functions is applied to at least one input to generate at least one hash chain output, wherein said second plurality of hash functions are different from one another;

promoting a hash chain output as said OTP for use in the authentication request;

switching from promotion of a hash chain output of said first hash chain to promotion of a hash chain output of said second hash chain;

wherein said first hash chain is generated by applying said first seed as an input to at least one of said first plurality of hash functions to generate an output, and successively applying said output as said input to at least one of said first plurality of hash functions;

wherein said second hash chain is generated by applying said second seed as an input to at least one of said second plurality of hash functions to generate an output, and successively applying said output as said input to at least one of said second plurality of hash functions; and

wherein said security token is configured to switch from promotion of a hash chain output of said first hash chain to promotion of a hash chain output from said second hash chain in response to a hash modification event.

5. The security token of claim 4 wherein said hash modification event includes at least one of a time-based event, a number of outputs used from said first hash chain exceeding a threshold, and reception of a remote command.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2014
From: EVANS, PHILIP G.; HUMBLE, TRAVIS S.; PAUL, NATHANAEL R.; POOSER, RAPHAEL C.; PROWELL, STACY J.
To: UT-BATTELLE, LLC
Reel/Frame 034260/0204 →
CONFIRMATORY LICENSE Recorded Sep 11, 2014
From: UT-BATTELLE, LLC
To: U.S. DEPARTMENT OF ENERGY
Reel/Frame 033721/0075 →
Continuity (1)
Provisional Application 61712855 · Oct 12, 2012