IP Library Granted Patent US 9,503,431
Granted Patent B2
US 9,503,431 · App. 14/936,351 · Granted Nov 22, 2016

Simple protocol for tangible security

Inventors: YuQun Chen (Seattle, WA); Michael J. Sinclair (Kirkland, WA); Josh D. Benaloh (Redmond, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/0428H04L9/0869H04L63/0492H04L63/0853H04W12/06H04L2209/24H04W88/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,503,431
App. No.
14/936,351
Granted
Nov 22, 2016
Kind
B2
Abstract

The claimed subject matter provides systems and/or methods that effectuate a simple protocol for tangible security on mobile devices. The system can include devices that generate sets of keys and associated secret identifiers, employs the one or more keys to encrypt a secret and utilizes the identifiers and encryptions of the secret to populate a table associated with a security token device that is used in conjunction with a mobile device to release sensitive information persisted on the mobile device for user selected purposes.

Claims (66)

1. A security token device comprising:

one or more processors; and

memory communicatively coupled to the one or more processors and storing instructions that, when executed, configure the one or more processors to perform acts comprising:

receiving, from a mobile device, a secret while the security token device is within a predetermined proximity to the mobile device;

storing the secret;

receiving, from the mobile device, a request for use of the secret;

based at least in part on the request for use of the secret and determining that the security token device is within the predetermined proximity to the mobile device:

retrieving the secret; and

sending the secret to the mobile device.

2. The security token device of claim 1 , wherein at least one of receiving the request or sending the secret is performed over at least one of:

a personal area network (PAN);

a local area network (LAN);

a campus area network (CAN);

metropolitan area network (MAN);

an extranet;

an intranet;

the Internet; or

a wide area network (WAN).

3. The security token device of claim 1 , where at least one of receiving the request or sending the secret is performed using near-field communication.

4. The security token device of claim 1 , wherein the acts further comprise:

receiving, from the mobile device, a secret identifier associated with a key used to encrypt the secret to create an encrypted version of the secret; and

storing the secret identifier together with the encrypted version of the secret.

5. The security token device of claim 4 wherein the acts further comprise:

retrieving the secret identifier; and

sending, to the mobile device, the secret identifier to decrypt the encrypted version of the secret at the mobile device.

6. The security token device of claim 1 , wherein the secret comprises a password.

7. The security token device of claim 1 , wherein at least one of receiving the request or sending the secret is performed using at least one of:

direct electrical contact communication;

radio frequency identification communication;

acoustical communication; or

optical communication.

8. A method comprising:

receiving, by a security device and from a mobile device, a secret;

storing, in memory of the security device, the secret;

receiving, by the security device and from the mobile device, a request for use of the secret; and

based at least in part on the request for use of the secret and when the security device is within a predetermined proximity to the mobile device:

retrieving the secret from the memory; and

sending, by the security device and to the mobile device, the secret.

9. The method of claim 8 , wherein at least one of receiving the request or sending the secret is performed using near field communications.

10. The method of claim 8 , wherein the secret comprises a password.

11. The method of claim 8 , wherein the secret comprises information associated with purchasing a good or service.

12. The method of claim 8 , wherein the security device comprises at least one of a watch, a watchband, a bracelet, a necklace, a cufflink, a tie clip, a key fob, or a card.

13. A wristband comprising:

one or more processors; and

memory communicatively coupled to the one or more processors and storing instructions that, when executed, configure the one or more processors to perform acts comprising:

receiving a secret from a portable device;

storing the secret;

receiving, from the portable device, a request for use of the secret;

based at least in part on the request for use of the secret and determining that the wristband is within a predetermined proximity to the portable device:

retrieving the secret; and

sending the secret to the portable device.

14. The wristband of claim 13 , wherein the secret comprises at least one of a password or user identification information.

15. The wristband of claim 13 , wherein the secret comprises information associated with purchasing a good or service.

16. The wristband of claim 15 , wherein the information associated with purchasing a good or service comprises at least one of credit card information, debit card information, or bank account information.

17. The wristband of claim 13 , wherein at least one of receiving the request or sending the secret is performed using at least one of near-field communication or communication over a personal area network.

18. The wristband of claim 13 , wherein the acts further comprise:

receiving, from the portable device, a secret identifier associated with a key used to encrypt the secret to create an encrypted version of the secret; and

storing the secret identifier together with the encrypted version of the secret.

19. The wristband of claim 18 , wherein the acts further comprise:

retrieving the secret identifier; and

sending, to the portable device, the secret identifier for use in decrypting the encrypted version of the secret.

20. The wristband of claim 13 , wherein at least one of receiving the request or sending the secret is performed using at least one of:

direct electrical contact communication;

radio frequency identification communication;

acoustical communication; or

optical communication.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2016
From: CHEN, YUQUN; SINCLAIR, MICHAEL J.; BENALOH, JOSH D.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 038994/0714 →
Continuity (2)
Continuation 12250308 · Oct 13, 2008
Related Publication 20160065544A1 · Mar 3, 2016