IP Library Granted Patent US 9,917,694
Granted Patent B1
US 9,917,694 · App. 14/092,028 · Granted Mar 13, 2018

Key provisioning method and apparatus for authentication tokens

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,917,694
App. No.
14/092,028
Granted
Mar 13, 2018
Kind
B1
Abstract

A processing device is configured to obtain an address and a public key, both associated with an authentication service, to generate a symmetric key as a function of the public key, to configure an authentication token to incorporate the symmetric key, to encrypt the symmetric key utilizing the public key, and to transmit the encrypted symmetric key to the address so as to permit the authentication service to bind the symmetric key to an identifier of the authentication token. By way of example, the authentication token may comprise a software authentication token implemented on the processing device. One or more tokencodes generated by the authentication token utilizing the symmetric key are transmitted to the authentication service for authentication. The authentication by the authentication service is based on the symmetric key bound to the identifier of the authentication token.

Claims (61)

1. A method comprising:

obtaining an address associated with an authentication service over a channel not secured by the authentication service, wherein obtaining the address comprises receiving a link, to a secured website administered by the authentication service, that is customized by the authentication service for a given user of an authentication token;

utilizing the customized link to obtain a public key associated with the authentication service via the secured website administered by the authentication service;

generating a symmetric key as a function of the public key and a value generated by the authentication token;

configuring the authentication token to incorporate the symmetric key;

encrypting the symmetric key utilizing the public key; and

binding the symmetric key to an identifier of the authentication token and to an identity of the given user of the authentication token by:

transmitting the encrypted symmetric key to the address associated with the authentication service via the secured website administered by the authentication service;

recording an association between the authentication token and the symmetric key; and

authenticating the given user to the authentication service, in conjunction with recording the association between the authentication token and the symmetric key, utilizing a proof of identity of the given user provided to the authentication service via the secured website administered by the authentication service;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 wherein the authentication token comprises a software authentication token implemented on the processing device.

3. The method of claim 2 wherein the software authentication token implemented on the processing device comprises an application running on the processing device.

4. The method of claim 1 further comprising:

generating a tokencode in the authentication token utilizing the symmetric key; and

transmitting the tokencode to the authentication service for authentication.

5. The method of claim 1 wherein obtaining the address and the public key comprises:

receiving the address in a message;

utilizing the address to establish a connection with a server;

receiving a certificate from the server; and

extracting the public key from the certificate.

6. The method of claim 5 wherein the message comprises one of an email message, a text message and a multimedia message.

7. The method of claim 1 wherein obtaining the address and the public key comprises obtaining the address and the public key utilizing information presented on a display of the processing device.

8. The method of claim 1 wherein obtaining the address and the public key comprises:

decoding a coded representation; and

obtaining the address and the public key from a result of the decoding.

9. The method of claim 8 wherein the coded representation comprises a QR code.

10. The method of claim 1 wherein the address comprises a network address of an authentication server providing the authentication service.

11. The method of claim 1 wherein the address comprises an HTTPS address.

12. The method of claim 1 wherein generating a symmetric key as a function of the public key comprises conditioning the symmetric key on the public key itself.

13. The method of claim 1 wherein generating a symmetric key as a function of the public key comprises conditioning the symmetric key on a certificate containing the public key.

14. The method of claim 1 wherein authenticating the given user to the authentication service in conjunction with recording the association between the authentication token and the symmetric key comprises authenticating the given user to the authentication service prior to recording the association between the authentication token and the symmetric key.

15. The method of claim 1 wherein the proof of identity of the given user comprises a password supplied via an out-of-band channel.

16. The method of claim 1 wherein generating the symmetric key comprises generating the symmetric key as a function of the public key, the value generated by the authentication token and a value supplied by the authentication service.

17. An article of manufacture comprising a non-transitory processor-readable storage medium having embodied therein one or more software programs, wherein the one or more software programs when executed by at least one processing device cause the at least one processing device:

to obtain an address associated with an authentication service over a channel not secured by the authentication service, wherein obtaining the address comprises receiving a link, to a secured website administered by the authentication service, that is customized by the authentication service for a given user of an authentication token;

to utilize the customized link to obtain a public key associated with the authentication service via the secured website administered by the authentication service;

to generate a symmetric key as a function of the public key and a value generated by the authentication token;

to configure the authentication token to incorporate the symmetric key;

to encrypt the symmetric key utilizing the public key; and

to bind the symmetric key to an identifier of the authentication token and to an identity of the given user of the authentication token by:

transmitting the encrypted symmetric key to the address associated with the authentication service via the secured website administered by the authentication service;

recording an association between the authentication token and the symmetric key; and

authenticating the given user to the authentication service, in conjunction with recording the association between the authentication token and the symmetric key, utilizing a proof of identity of the given user provided to the authentication service via the secured website administered by the authentication service.

18. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

wherein said at least one processing device is configured:

to obtain an address associated with an authentication service over a channel not secured by the authentication service, wherein obtaining the address comprises receiving a link, to a secured website administered by the authentication service, that is customized by the authentication service for a given user of an authentication token;

to utilize the customized link to obtain a public key associated with the authentication service via the secured website administered by the authentication service;

to generate a symmetric key as a function of the public key and a value generated by the authentication token;

to configure the authentication token to incorporate the symmetric key;

to encrypt the symmetric key utilizing the public key; and

to bind the symmetric key to an identifier of the authentication token and to an identity of the given user of the authentication token by:

transmitting the encrypted symmetric key to the address associated with the authentication service via the secured website administered by the authentication service;

recording an association between the authentication token and the symmetric key; and

authenticating the given user to the authentication service, in conjunction with recording the association between the authentication token and the symmetric key, utilizing a proof of identity of the given user provided to the authentication service via the secured website administered by the authentication service.

19. The apparatus of claim 18 wherein the processing device comprises one of a mobile telephone and a computer.

20. The apparatus of claim 18 wherein the authentication token comprises a software authentication token implemented on the processing device.

21. A method comprising: providing an address associated with an authentication service over a channel not secured by the authentication service, wherein providing the address comprises sending a link, to a secured website administered by the authentication service, that is customized by the authentication service for a given user of an authentication token; utilizing the customized link to provide a public key associated with the authentication service via the secured website administered by the authentication service; and binding a symmetric key to an identifier of the authentication token and to an identity of the given user of the authentication token by: receiving, via the secured website administered by the authentication service, an encrypted symmetric key generated as a function of the public key and a value generated by the authentication token; recording an association between the authentication token and the symmetric key; and authenticating the given user to the authentication service, in conjunction with recording the association between the authentication token and the symmetric key, utilizing a proof of identity of the given user received by the authentication service via the secured website administered by the authentication service; wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

22. An article of manufacture comprising a non-transitory processor-readable storage medium having embodied therein one or more software programs, wherein the one or more software programs when executed by at least one processing device cause the at least one processing device: to provide an address associated with an authentication service over a channel not secured by the authentication service, wherein providing the address comprises sending a link, to a secured website administered by the authentication service, that is customized by the authentication service for a given user of an authentication token; to utilize the customized link to provide a public key associated with the authentication service via the secured website administered by the authentication service; and to bind a symmetric key to an identifier of the authentication token and to an identity of the given user of the authentication token by: receiving, via the secured website administered by the authentication service, an encrypted symmetric key generated as a function of the public key and a value generated by the authentication token; recording an association between the authentication token and the symmetric key; and authenticating the given user to the authentication service, in conjunction with recording the association between the authentication token and the symmetric key, utilizing a proof of identity of the given user received by the authentication service via the secured website administered by the authentication service.

23. An apparatus comprising: at least one processing device comprising a processor coupled to a memory; wherein said at least one processing device is configured: to provide an address associated with an authentication service over a channel not secured by the authentication service, wherein providing the address comprises sending a link, to a secured website administered by the authentication service, that is customized by the authentication service for a given user of an authentication token; to utilize the customized link to provide a public key associated with the authentication service via the secured website administered by the authentication service; and to bind a symmetric key to an identifier of the authentication token and to an identity of the given user of the authentication token by: receiving, via the secured website administered by the authentication service, an encrypted symmetric key generated as a function of the public key and a value generated by the authentication token; recording an association between the authentication token and the symmetric key; and authenticating the given user to the authentication service, in conjunction with recording the association between the authentication token and the symmetric key, utilizing a proof of identity of the given user received by the authentication service via the secured web site administered by the authentication service.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2014
From: JUELS, ARI; TAKU, DAVID D.
To: EMC CORPORATION
Reel/Frame 033005/0793 →