IP Library Granted Patent US 10,091,204
Granted Patent B1
US 10,091,204 · App. 14/266,192 · Granted Oct 2, 2018

Controlling user access to protected resource based on outcome of one-time passcode authentication token and predefined access policy

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,091,204
App. No.
14/266,192
Granted
Oct 2, 2018
Kind
B1
Abstract

Techniques are provided for controlling user access to a protected resource based on an outcome of a one-time passcode authentication token and one or more predefined access policies. An exemplary method comprises the steps of: providing an authentication passcode generated by a token associated with a user to at least one authentication processing device, wherein the user is attempting to access a protected resource; receiving an authentication outcome from the at least one authentication processing device, the authentication outcome comprising an acceptance outcome of the received authentication passcode and at least one of an acceptance outcome with respect to one or more different signals, such as a silent alarm and an acceptance outcome with respect to a drifting key; and providing access of the user to the protected resource based on the authentication outcome and a predefined access policy. Predefined access policies that are specific to silent alarm alerts and drifting key alerts are also provided.

Claims (34)

1. A method, comprising:

providing an authentication passcode derived from a secret seed and generated by a token associated with a user to at least one authentication processing device, wherein said user is attempting to access a protected resource;

receiving an authentication outcome from said at least one authentication processing device, said authentication outcome comprising an acceptance outcome of the received authentication passcode and at least one of an acceptance outcome with respect to one or more of two different signals, wherein said at least one authentication processing device detects a loss of privacy of said secret seed by extracting and processing a silent alarm signal embedded in said received authentication passcode from said received authentication passcode, and wherein said silent alarm signal indicates an anomalous event detected by said token; and

controlling access of said user to said protected resource based on said authentication outcome and a predefined access policy invoked when said silent alarm signal has a predefined state indicating said detection of said anomalous event.

2. The method of claim 1 , wherein said received authentication passcode further comprises a drifting key signal.

3. The method of claim 1 , wherein said authentication outcome comprises one or more of an allowance of access, a denial of access, a silent alarm alert indicating a potential compromise of said token, a drifting key inconsistency between said received authentication passcode and one or more previously received authentication passcodes and a severe danger alert indicating at least two independent indications of a cloning of said token.

4. The method of claim 1 , wherein said predefined access policy comprises one or more of the following actions: allowing said user full access to said protected resource; allowing said user restricted access to said protected resource; denying said user access to said protected resource; denying said user access to said protected resource and applying an additional secondary step-up authentication mechanism; and allowing said user restricted access to said protected resource in a non-functional manner such that said user is not notified that a potential attack has been detected.

5. The method of claim 1 , wherein said access of said user is provided to said protected resource further based on an event type.

6. The method of claim 1 , wherein said acceptance outcome with respect to said silent alarm signal comprises a silent alarm alert and wherein said predefined access policy comprises one or more of the following actions: allowing said user full access to said protected resource; allowing said user restricted access to said protected resource; and denying said user access to said protected resource.

7. The method of claim 1 , wherein said acceptance outcome with respect to said silent alarm signal comprises a silent alarm alert and wherein said method further comprises a step of logging a silent alarm state.

8. The method of claim 1 , wherein said acceptance outcome with respect to said silent alarm signal comprises a silent alarm alert and wherein said method further comprises one or more of the following steps: disabling said token, monitoring one or more actions of said user and sending a notification of said silent alarm alert to an administrator.

9. The method of claim 2 , wherein said acceptance outcome with respect to said drifting key signal comprises a drifting key alert and wherein said predefined access policy comprises one or more of the following actions: allowing said user restricted access to said protected resource; and denying said user access to said protected resource.

10. The method of claim 2 , wherein said acceptance outcome with respect to said drifting key signal comprises said drifting key alert and wherein said method further comprises a step of logging a drifting key state.

11. The method of claim 2 , wherein said acceptance outcome with respect to said drifting key signal comprises said drifting key alert and wherein said method further comprises one or more of the following steps: disabling said token, disabling said token after a predefined number of failed attempts, monitoring one or more actions of said user and sending a notification of said drifting key alert to an administrator.

12. An apparatus, the apparatus comprising:

a memory; and

at least one hardware device, coupled to the memory, operative to:

provide an authentication passcode derived from a secret seed and generated by a token associated with a user to at least one authentication processing device, wherein said user is attempting to access a protected resource;

receive an authentication outcome from said at least one authentication processing device, said authentication outcome comprising an acceptance outcome of the received authentication passcode and at least one of an acceptance outcome with respect to one or more of two different signals, wherein said at least one authentication processing device detects a loss of privacy of said secret seed by extracting and processing a silent alarm signal embedded in said received authentication passcode from said received authentication passcode, and wherein said silent alarm signal indicates an anomalous event detected by said token; and

control access of said user to said protected resource based on said authentication outcome and a predefined access policy invoked when said silent alarm signal has a predefined state indicating said detection of said anomalous event.

13. The apparatus of claim 12 , wherein said received authentication passcode further comprises a drifting key signal.

14. The apparatus of claim 12 , wherein said authentication outcome comprises one or more of an allowance of access, a denial of access, a silent alarm alert indicating a potential compromise of said token, a drifting key inconsistency between said received authentication passcode and one or more previously received authentication passcodes and a severe danger alert indicating at least two independent indications of a cloning of said token.

15. The apparatus of claim 12 , wherein said predefined access policy comprises one or more of the following actions: allowing said user full access to said protected resource; allowing said user restricted access to said protected resource; denying said user access to said protected resource; denying said user access to said protected resource and applying an additional secondary step-up authentication mechanism; and allowing said user restricted access to said protected resource in a non-functional manner such that said user is not notified that a potential attack has been detected.

16. The apparatus of claim 12 , wherein said access of said user is provided to said protected resource further based on an event type.

17. The apparatus of claim 12 , wherein said acceptance outcome with respect to said silent alarm signal comprises a silent alarm alert and wherein said predefined access policy comprises one or more of the following actions: allowing said user full access to said protected resource; allowing said user restricted access to said protected resource; and denying said user access to said protected resource.

18. The apparatus of claim 12 , wherein said acceptance outcome with respect to said silent alarm signal comprises a silent alai in alert and wherein said apparatus is further configured to log a silent alarm state.

19. The apparatus of claim 12 , wherein said acceptance outcome with respect to said silent alarm signal comprises a silent alarm alert and wherein said apparatus is further configured to perform one or more of the following steps: disabling said token, monitoring one or more actions of said user and sending a notification of said silent alarm alert to an administrator.

20. The apparatus of claim 13 , wherein said acceptance outcome with respect to said drifting key signal comprises a drifting key alert and wherein said predefined access policy comprises one or more of the following actions: allowing said user restricted access to said protected resource; and denying said user access to said protected resource.

21. The apparatus of claim 13 , wherein said acceptance outcome with respect to said drifting key signal comprises a drifting key alert and wherein said apparatus is further configured to log a drifting key state.

22. The apparatus of claim 13 , wherein said acceptance outcome with respect to said drifting key signal comprises a drifting key alert and wherein said apparatus is further configured to perform one or more of the following steps: disabling said token, disabling said token after a predefined number of failed attempts, monitoring one or more actions of said user and sending a notification of said drifting key alert to an administrator.

23. An article of manufacture, comprising a non-transitory machine readable recordable medium containing one or more programs which, when executed, implement the steps of:

providing an authentication passcode derived from a secret seed and generated by a token associated with a user to at least one authentication processing device, wherein said user is attempting to access a protected resource;

receiving an authentication outcome from said at least one authentication processing device, said authentication outcome comprising an acceptance outcome of the received authentication passcode and at least one of an acceptance outcome with respect to one or more of two different signals, wherein said at least one authentication processing device detects a loss of privacy of said secret seed by extracting and processing a silent alarm signal embedded in said received authentication passcode from said received authentication passcode, and wherein said silent alarm signal indicates an anomalous event detected by said token; and

controlling access of said user to said protected resource based on said authentication outcome and a predefined access policy invoked when said silent alarm signal has a predefined state indicating said detection of said anomalous event.

Assignments (16)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2018
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 046433/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2014
From: TRIANDOPOULOS, NIKOLAOS; BRAINARD, JOHN
To: EMC CORPORATION
Reel/Frame 033862/0211 →