IP Library Granted Patent US 9,485,254
Granted Patent B2
US 9,485,254 · App. 14/636,154 · Granted Nov 1, 2016

Method and system for authenticating a security device

Inventors: Randy Kuang (Kanata, CA); Stanislus Kisito Xavier (Kanata, CA); David Michael Mann (Ottawa, CA); Robert Frank Steklasa (Ottawa, CA); Stephen George Wilson (Ottawa, CA); He Zhu (Ottawa, CA); Nicolas Johannes Sebastian Bettenburg (Ottawa, CA)
Assignee: INBAY TECHNOLOGIES INC.
H04L63/0884G06F21/44H04L9/0861H04L9/3226H04L63/062H04L63/0853H04L63/0869H04L63/0876H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,485,254
App. No.
14/636,154
Granted
Nov 1, 2016
Kind
B2
Abstract

Methods for authenticating a security device at a local network location for providing a secure access from the local network location to a remote network location are provided. A security device is registered by installing private security software on the security device that generates an asymmetrical encryption key pair including an encryption key and a decryption key. The encryption key is stored only on the security device and the decryption key is stored only on a remote server. Embodiments of the present invention provide increased security by not storing the encryption key on the remote server so that attackers stealing data from the server cannot pretend to a user having the registered security device. A corresponding system for authenticating a security device is also provided.

Claims (81)

1. A method for authenticating a security device at a local network location for providing a secure access from the local network location to a remote network location, the method comprising:

at the security device, having a UID (global unique identifier), a processor and a memory:

obtaining, from the remote network location, a private security software, and causing the private security software to obtain a user selectable PIN (personal identification number), and the UID of the security device, the UID uniquely identifying the security device and being permanently associated with the security device;

generating a device ID serial number corresponding to the UID;

forwarding the PIN, the device ID serial number, and the UID to the remote network location,

at the remote location:

generating a seed;

generating a user-personalized credential code using the PIN, the UID, and the seed; and

generating, from the seed, an asymmetric encryption key pair including an encryption key and a decryption key;

storing the decryption key in a memory at the remote location; and

deleting the seed and the encryption key from any memory at the remote location, and at the security device:

obtaining the user-personalized credential code from the remote network location; and

verifying an authenticity of the user selectable PIN and the UID from the personalized credential code, without communicating over a network.

2. The method of claim 1 , wherein a type of the seed is chosen from the group consisting of random number, pseudo random number, and one-time pad.

3. The method of claim 1 wherein the generating the asymmetric encryption key pair comprises generating the asymmetric encryption key pair using an RSA (Rivest, Shami and Adleman) algorithm.

4. The method of claim 1 , further comprising:

at the security device:

obtaining the seed from the user-personalized credential code;

generating, from the seed, the encryption key and the decryption key;

storing the encryption key in a memory at the security device; and

deleting the decryption key from any memory at the security device.

5. The method of claim 4 , further comprising:

at the security device:

generating an encrypted client OTA by encrypting a client one-time-authorization (OTA) code; and

sending the device ID serial number, the client OTA, and the encrypted client OTA to the remote location,

at the remote location:

retrieving the decryption key using the device ID serial number;

decrypting the encrypted client OTA using the decryption key; and

verifying the client OTA using a server OTA.

6. The method of claim 1 , further comprising:

at the remote location:

storing the device ID serial number and the seed in a database stored in a memory at the remote location.

7. The method of claim 6 , further comprising:

at the remote location:

encrypting the database, and storing an algorithm for decrypting the database in the memory at the remote location.

8. The method of claim 1 , wherein the security device is one of the following:

a computing device, comprising a processor, at the local network location; or

a portable device having a memory, the portable device being different from the computing device, and being operably coupled to the computing device.

9. The method of claim 1 , wherein the security device is a mobile wireless device.

10. The method of claim 1 , wherein the remote network location is a third party location.

11. A system for providing a secure access from a local network location to a remote network location, the system comprising:

a remote server computer at the remote network location; and

a security device at the local network location, the security device having a UID (global unique identifier) uniquely identifying the security device and permanently associated with the security device, a processor and a memory having computer readable instructions stored thereon, causing the processor to:

obtain, from the remote server computer, a private security software;

obtain, from the remote network location, a private security software, and causing the private security software to obtain a user selectable PIN (personal identification number), and the UID of the security device, the UID uniquely identifying the security device and being permanently associated with the security device;

generate a device ID serial number corresponding to the UID;

forward the PIN, the device ID serial number, and the UID to the remote network location,

the remote server computer being configured to:

generate a seed;

generate a user-personalized credential code using the PIN, the UID, and the seed; and

generate, from the seed, an asymmetric encryption key pair including an encryption key and a decryption key;

store the decryption key in a memory at the remote location; and

delete the seed and the encryption key from any memory at the remote location, and

the computer readable instructions being further configured to cause the processor to:

obtain the user-personalized credential code from the remote network location; and

verify an authenticity of the user selectable PIN and the UID from the personalized credential code, without communicating over a network.

12. The system of claim 11 , wherein a type of the seed is chosen from the group consisting of random number, pseudo random number, and one-time pad.

13. The system of claim 11 wherein the remote server computer is configured to generate the asymmetric encryption key pair using an RSA (Rivest, Shami and Adleman) algorithm.

14. The system of claim 11 , wherein the computer readable instructions are further configured to cause the processor to:

obtain the seed from the user-personalized credential code;

generate, from the seed, the encryption key and the decryption key;

store the encryption key in a memory at the security device; and

delete the decryption key from any memory at the security device.

15. The system of claim 14 , wherein the computer readable instructions are further configured to cause the processor to:

generate an encrypted client OTA by encrypting a client one-time-authorization (OTA) code; and

send the device ID serial number, the client OTA, and the encrypted client OTA to the remote location,

the remote server computer being configured to:

retrieve the decryption key using the device ID serial number;

decrypt the encrypted client OTA using the decryption key; and

verify the client OTA using a server OTA.

16. The system of claim 11 , wherein:

the remote server computer is configured to:

store the device ID serial number and the seed in a database stored in a memory at the remote location.

17. The system of claim 16 , wherein:

the remote server computer is configured to:

encrypt the database, and store an algorithm for decrypting the database in the memory at the remote location.

18. The system of claim 11 , wherein the security device is one of the following:

a computing device, comprising a processor, at the local network location; or

a portable device having a memory, the portable device being different from the computing device, and being operably coupled to the computing device.

19. The system of claim 11 , wherein the security device is a mobile wireless device.

20. The system of claim 11 , wherein the remote network location is a third party location.

Assignments (3)
CHANGE OF COMPANY ADDRESS Recorded Apr 20, 2018
From: INBAY TECHNOLOGIES INC.
To: INBAY TECHNOLOGIES INC.
Reel/Frame 045986/0975 →
CHANGE OF ADDRESS Recorded Nov 17, 2015
From: INBAY TECHNOLOGIES INC.
To: INBAY TECHNOLOGIES INC.
Reel/Frame 037127/0488 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2015
From: KUANG, RANDY; XAVIER, STANISLUS KISITO; MANN, DAVID MICHAEL; STEKLASA, ROBERT FRANK; WILSON, STEPHEN GEORGE; ZHU, HE; BETTENBURG, NICOLAS JOHANNES SEBASTIAN
To: INBAY TECHNOLOGIES INC.
Reel/Frame 035694/0433 →
Continuity (16)
Continuation In Part 13913399 · Jun 8, 2013
Continuation 13035830 · Feb 25, 2011
Continuation In Part 12639464 · Dec 16, 2009
Continuation In Part 14636154
Continuation In Part 14309369 · Jun 19, 2014
Continuation In Part 14231545 · Mar 31, 2014
Continuation 13765049 · Feb 12, 2013
Provisional Application 62065699 · Oct 19, 2014
Provisional Application 61416270 · Nov 22, 2010
Provisional Application 61149501 · Feb 3, 2009
Provisional Application 61183830 · Jun 3, 2009
Provisional Application 61247223 · Sep 30, 2009
Provisional Application 61248047 · Oct 2, 2009
Provisional Application 61839218 · Jun 25, 2013
Provisional Application 61599556 · Feb 16, 2012
Related Publication 20150172292A1 · Jun 18, 2015