IP Library Granted Patent US 9,015,490
Granted Patent B2
US 9,015,490 · App. 14/105,070 · Granted Apr 21, 2015

Secure credential unlock using trusted execution environments

Inventors: Stefan Thom (Snohomish, WA); Robert K. Spiger (Seattle, WA); Magnus NystrÖm (Sammamish, WA); Himanshu Soni (Bothell, WA); Marc R. Barbour (Woodinville, WA); Nick Voicu (Bellevue, WA); Xintong Zhou (Bellevue, WA); Kirk Shoop (Seattle, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F21/30G06F21/31G06F2221/2103H04L9/0822H04L9/0861H04L9/3271G06F2221/2107G06F2221/2131H04L2209/127G06F21/57
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,015,490
App. No.
14/105,070
Granted
Apr 21, 2015
Kind
B2
Abstract

Computing devices utilizing trusted execution environments as virtual smart cards are designed to support expected credential recovery operations when a user credential, e.g., personal identification number (PIN), password, etc. has been forgotten or is unknown. A computing device generates a cryptographic key that is protected with a PIN unlock key (PUK) provided by an administrative entity. If the user PIN cannot be input to the computing device the PUK can be input to unlock the locked cryptographic key and thereby provide access to protected data. A computing device can also, or alternatively, generate a group of challenges and formulate responses thereto. The formulated responses are each used to secure a computing device cryptographic key. If the user PIN cannot be input to the computing device an entity may request a challenge. The computing device issues a challenge from the set of generated challenges. Upon receiving a valid response back, the computing device can unlock the secured computing device cryptographic key associated with the issued challenge and subsequently provide access to protected data.

Claims (45)

1. A method performed on a computing device that includes a trusted platform module (“TPM”), the method comprising:

generating, by the computing device, an authentropy;

generating, by the TPM, a virtual smart card key;

locking, by the TPM, the virtual smart card key;

encrypting, by the TPM, the authentropy with the virtual smart card key;

storing, by the TPM, the encrypted authentropy and the locked virtual smart card key in the TPM; and

protecting a user key based on the authentropy.

2. The method of claim 1 where the locking is based on a personal identification number (“PIN”) of a user.

3. The method of claim 1 where the generating the authentropy is performed by the computing device or by a user.

4. The method of claim 1 where the virtual smart card key is configured for use in accessing to the authentropy.

5. The method of claim 2 further comprising removing, subsequent to the locking, the PIN from the computing device.

6. The method of claim 1 further comprising receiving a PIN unlock key (“PUK”).

7. The method of claim 6 further comprising:

storing, by the TPM in the TPM, the authentropy encrypted with an unblock key; and

storing, by the TPM in the TPM, the unblock key locked with the PUK.

8. A system comprising a computing device and program code that are together configured for performing actions, the computing device comprising a trusted platform module (“TPM”), the actions comprising:

generating, by the computing device, an authentropy;

generating, by the TPM, a virtual smart card key;

locking, by the TPM, the virtual smart card key;

encrypting, by the TPM, the authentropy with the virtual smart card key;

storing, by the TPM, the encrypted authentropy and the locked virtual smart card key in the TPM; and

protecting a user key based on the authentropy.

9. The system of claim 8 where the locking is based on a personal identification number (“PIN”) of a user.

10. The system of claim 8 where the generating the authentropy is performed by the computing device or by a user.

11. The system of claim 8 where the virtual smart card key is configured for use in accessing to the authentropy.

12. The system of claim 9 , the actions further comprising removing, subsequent to the locking, the PIN from the computing device.

13. The system of claim 8 , the actions further comprising receiving a PIN unlock key (“PUK”).

14. The system of claim 13 , the actions further comprising:

storing, by the TPM in the TPM, the authentropy encrypted with an unblock key; and

storing, by the TPM in the TPM, the unblock key locked with the PUK.

15. A system comprising a computing device and program code that are together configured for performing actions, the computing device comprising a trusted platform module (“TPM”), the actions comprising:

generating, by the computing device, an authentropy;

generating, by the TPM, a virtual smart card key;

locking, by the TPM, the virtual smart card key;

encrypting, by the TPM, the authentropy with the virtual smart card key;

storing, by the TPM, the encrypted authentropy and the locked virtual smart card key in the TPM; and

protecting a user key based on the authentropy.

16. The system of claim 15 where the locking is based on a personal identification number (“PIN”) of a user.

17. The system of claim 15 where the generating the authentropy is performed by the computing device or by a user.

18. The system of claim 15 where the virtual smart card key is configured for use in accessing to the authentropy.

19. The system of claim 16 , the actions further comprising removing, subsequent to the locking, the PIN from the computing device.

20. The system of claim 15 , the actions further comprising:

receiving a PIN unlock key (“PUK”);

storing, by the TPM in the TPM, the authentropy encrypted with an unblock key; and

storing, by the TPM in the TPM, the unblock key locked with the PUK.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2015
From: THOM, STEFAN; SPIGER, ROBERT K.; NYSTROM, MAGNUS; SHOOP, KIRK; VOICU, NICK; BARBOUR, MARC R.; SONI, HIMANSHU; ZHOU, XINTONG
To: MICROSOFT CORPORATION
Reel/Frame 035183/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034544/0541 →
Continuity (2)
Continuation 13176735 · Jul 5, 2011
Related Publication 20140101454A1 · Apr 10, 2014