IP Library Granted Patent US 9,967,251
Granted Patent B1
US 9,967,251 · App. 14/266,201 · Granted May 8, 2018

Security-aware single-server passcode verification for one-time authentication tokens

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,967,251
App. No.
14/266,201
Granted
May 8, 2018
Kind
B1
Abstract

Techniques are provided for security-aware single-server passcode verification for one-time authentication tokens. An exemplary method comprises the steps of: receiving an authentication passcode generated by a token associated with a user, wherein the received authentication passcode is based on at least one protocode and embedded auxiliary information; and processing the received authentication passcode using a single processing device to extract the embedded auxiliary information from the received authentication passcode, wherein the embedded auxiliary information comprises one or more of two different signals, such as a silent alarm signal and a drifting key signal. The single processing device optionally implements software modules of first and second authentication servers. The single processing device optionally comprises one or more sources of pseudorandom information for at least two of an auxiliary channel, a silent alarm and a drifting key.

Claims (31)

1. A method, comprising:

receiving an authentication passcode generated by a token associated with a user, wherein the received authentication passcode is derived from a secret seed and based on at least one protocode and embedded auxiliary information;

processing the received authentication passcode using a single processing device to extract said embedded auxiliary information from the received authentication passcode, wherein said embedded auxiliary information comprises a drifting key signal indicating a current drifting key state of said token that evolves over time; and

detecting a cloning of said token using a copy of said secret seed by extracting said drifting key signal from said received authentication passcode and identifying an inconsistency between said drifting key signal extracted from said received authentication passcode and said drifting key signal extracted from one or more previously received authentication passcodes, wherein said inconsistency indicates that said received authentication passcode was generated by a cloned token, wherein said embedded auxiliary information is not previously known to said single processing device that extracts said embedded auxiliary information from said received authentication passcode.

2. The method of claim 1 , wherein said embedded auxiliary information further comprises a silent alarm signal.

3. The method of claim 1 , wherein said step of processing the received authentication passcode further comprises the step of interacting with at least a second processing device to evaluate said received authentication passcode.

4. The method of claim 1 , wherein said single processing device interacts with a relying party to evaluate said received authentication passcode.

5. The method of claim 1 , wherein said single processing device implements software modules of at least a first authentication server and a second authentication server.

6. The method of claim 2 , wherein said single processing device comprises a single source of pseudorandom information for an auxiliary channel and at least one of said silent alarm signal and said drifting key signal.

7. The method of claim 2 , wherein said single processing device comprises a plurality of sources of pseudorandom information for an auxiliary channel and at least one of said silent alarm signal and said drifting key signal.

8. The method of claim 7 , wherein said single processing device separately maintains seeds corresponding to a first authentication server and a second authentication server and independently extracts said embedded auxiliary information from the received authentication passcode using said sources of pseudorandom information of said first authentication server and said second authentication server.

9. The method of claim 8 , further comprising the step of migrating said single processing device to a multiple server configuration.

10. An apparatus, comprising:

a memory; and

at least one hardware device, coupled to the memory, operative to:

receive an authentication passcode derived from a secret seed and generated by a token associated with a user, wherein the received authentication passcode is based on at least one protocode and embedded auxiliary information;

process the received authentication passcode using a single processing device to extract said embedded auxiliary information from the received authentication passcode, wherein said embedded auxiliary information comprises a drifting key signal indicating a current drifting key state of said token that evolves over time; and

detect a cloning of said token using a copy of said secret seed by extracting said drifting key signal from said received authentication passcode and identifying an inconsistency between said drifting key signal extracted from said received authentication passcode and said drifting key signal extracted from one or more previously received authentication passcodes, wherein said inconsistency indicates that said received authentication passcode was generated by a cloned token, wherein said embedded auxiliary information is not previously known to said single processing device that extracts said embedded auxiliary information from said received authentication passcode.

11. The apparatus of claim 10 , wherein said embedded auxiliary information further comprises a silent alarm signal.

12. The apparatus of claim 10 , wherein received authentication passcode is processed by interacting with at least a second processing device to evaluate said received authentication passcode.

13. The apparatus of claim 10 , wherein said single processing device interacts with a relying party to evaluate said received authentication passcode.

14. The apparatus of claim 10 , wherein said single processing device implements software modules of at least a first authentication server and a second authentication server.

15. The apparatus of claim 11 , wherein said single processing device comprises a single source of pseudorandom information for an auxiliary channel and at least one of said silent alarm signal and said drifting key signal.

16. The apparatus of claim 11 , wherein said single processing device comprises a plurality of sources of pseudorandom information for an auxiliary channel and at least one of said silent alarm signal and said drifting key signal.

17. The apparatus of claim 16 , wherein said single processing device separately maintains seeds corresponding to a first authentication server and a second authentication server and independently extracts said embedded auxiliary information from the received authentication passcode using said sources of pseudorandom information of said first authentication server and said second authentication server.

18. The apparatus of claim 17 , wherein said at least one hardware device is further configured to migrate said single processing device to a multiple server configuration.

19. An article of manufacture, comprising a non-transitory machine readable recordable medium containing one or more programs which, when executed, implement the steps of:

receiving an authentication passcode derived from a secret seed and generated by a token associated with a user, wherein the received authentication passcode is based on at least one protocode and embedded auxiliary information;

processing the received authentication passcode using a single processing device to extract said embedded auxiliary information from the received authentication passcode, wherein said embedded auxiliary information comprises a drifting key signal indicating a current drifting key state of said token that evolves over time; and

detecting a cloning of said token using a copy of said secret seed by extracting said drifting key signal from said received authentication passcode and identifying an inconsistency between said drifting key signal extracted from said received authentication passcode and said drifting key signal extracted from one or more previously received authentication passcodes, wherein said inconsistency indicates that said received authentication passcode was generated by a cloned token, wherein said embedded auxiliary information is not previously known to said single processing device that extracts said embedded auxiliary information from said received authentication passcode.

20. The article of manufacture of claim 19 , wherein said embedded auxiliary information further comprises a silent alarm signal.

Assignments (22)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 9, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 054362/0039 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 053682/0956 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2018
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 045675/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR PREVIOUSLY RECORDED ON REEL 033859 FRAME 0897. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 7, 2014
From: TRIANDOPOULOS, NIKOLAOS; BRAINARD, JOHN
To: EMC CORPORATION
Reel/Frame 033899/0567 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2014
From: TRIANDOPOULOS, NIKOLAOS
To: EMC CORPORATION
Reel/Frame 033859/0897 →