IP Library Granted Patent US 10,291,567
Granted Patent B2
US 10,291,567 · App. 15/153,081 · Granted May 14, 2019

System and method for resetting passwords on electronic devices

Inventors: Robert Philip Gallant (Corner Brook, CA); Robert John Lambert (Cambridge, CA)
Assignee: ETAS Embedded System Canada Inc.
H04L51/22G06F21/31H04L51/04H04L63/083H04L63/123G06F2221/2131
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,291,567
App. No.
15/153,081
Granted
May 14, 2019
Kind
B2
Abstract

A system and method are provided for enabling a password reset mechanism for a secured device that verifies a digital signature on a password reset message. The password reset message has been generated by a password reset service for an authorized administrator associated with the secured device. The password reset mechanism allows the authorized administrator to make a request to the password reset service for a password reset, and receive the password reset message such that a password reset can be performed at the secured device. In this way, the secured device's password can be reset absent a connection to a command and control center or other service.

Claims (34)

1. A method of resetting a password used by a secured device, the method comprising:

receiving at the secured device, a password reset message and a new password, the password reset message comprising an encoded value derived using the new password, wherein a password image has been signed, and the password reset message includes a digital signature and an encoded value derived using the password, wherein the password image further comprises the device identifier and a replay protection value, wherein the replay protection value comprises a counter or random value or a combination of the counter and random value;

comparing the encoded value in the password reset message to a second encoded value generated at the secured device using the new password; and

enabling a password reset operation when the encoded values match.

2. The method of claim 1 , further comprising verifying the signature.

3. The method of claim 1 , wherein the password reset message comprises the counter, the method comprising the secured device comparing the counter against a locally stored counter, wherein the password reset message is processed only if the counter value in the password reset message is larger than the locally maintained counter, and wherein if processed, the locally maintained counter is set to the larger value contained in the password reset message.

4. The method of claim 1 , wherein the password reset message further comprises a time-frame indicator, and wherein the secured device processes the password reset message only if a locally available time is within a time-frame provided in the password reset message.

5. The method of claim 1 , wherein at least a portion of the password reset message is encrypted.

6. The method of claim 1 , wherein the received new password is encrypted or a hashed password image is generated, by the administrator.

7. A non-transitory computer readable medium comprising computer executable instructions for resetting a password used by a secured device, the computer readable medium comprising instructions for:

receiving at the secured device, a password reset message and a new password, the password reset message comprising an encoded value derived using the new password, wherein a password image has been signed, and the password reset message includes a digital signature and an encoded value derived using the password, wherein the password image further comprises the device identifier and a replay protection value, wherein the replay protection value comprises a counter or random value or a combination of the counter and random value;

comparing the encoded value in the password reset message to a second encoded value generated at the secured device using the new password; and

enabling a password reset operation when the encoded values match.

8. The non-transitory computer readable medium of claim 7 , further comprising instructions for verifying the signature.

9. The non-transitory computer readable medium of claim 7 , wherein the password reset message comprises the counter, the computer readable medium comprising instructions for the secured device comparing the counter against a locally stored counter, wherein the password reset message is processed only if the counter value in the password reset message is larger than the locally maintained counter, and wherein if processed, the locally maintained counter is set to the larger value contained in the password reset message.

10. The non-transitory computer readable medium of claim 7 , wherein the password reset message further comprises a time-frame indicator, and wherein the secured device processes the password reset message only if a locally available time is within a time-frame provided in the password reset message.

11. The computer readable medium of claim 7 , wherein at least a portion of the password reset message is encrypted.

12. The computer readable medium of claim 7 , wherein the received new password is encrypted or a hashed password image is generated, by the administrator.

13. A method of resetting a password used by a secured device, the method comprising:

receiving at the secured device, a password reset message and a new password, the password reset message comprising an encoded value derived using the new password, wherein the password reset message further comprises a counter;

comparing the counter against a locally stored counter, wherein the password reset message is processed only if the counter value in the password reset message is larger than the locally maintained counter, and wherein if processed, the locally maintained counter is set to the larger value contained in the password reset message;

comparing the encoded value in the password reset message to a second encoded value generated at the secured device using the new password; and

enabling a password reset operation when the encoded values match.

14. The method of claim 13 , wherein a password image has been signed, and the password reset message includes a digital signature.

15. The method of claim 14 , wherein the password image comprises an encoded value derived using the new password.

16. The method of claim 15 , wherein the password image further comprises the device identifier and a replay protection value, wherein the replay protection value comprises a counter or random value or a combination of the counter and random value.

17. A non-transitory computer readable medium comprising computer executable instructions for resetting a password used by a secured device, the computer readable medium comprising instructions for:

receiving at the secured device, a password reset message and a new password, the password reset message comprising an encoded value derived using the new password, wherein the password reset message further comprises a counter;

comparing the counter against a locally stored counter, wherein the password reset message is processed only if the counter value in the password reset message is larger than the locally maintained counter, and wherein if processed, the locally maintained counter is set to the larger value contained in the password reset message;

comparing the encoded value in the password reset message to a second encoded value generated at the secured device using the new password; and

enabling a password reset operation when the encoded values match.

18. The non-transitory computer readable medium of claim 17 , wherein a password image has been signed, and the password reset message includes a digital signature.

19. The non-transitory computer readable medium of claim 18 , wherein the password image comprises an encoded value derived using the new password.

20. The non-transitory computer readable medium of claim 19 , wherein the password image further comprises the device identifier and a replay protection value, wherein the replay protection value comprises a counter or random value or a combination of the counter and random value.

Assignments (2)
MERGER Recorded May 11, 2017
From: TRUSTPOINT INNOVATION TECHNOLOGIES, LTD.
To: ETAS EMBEDDED SYSTEMS CANADA INC.
Reel/Frame 042447/0359 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2016
From: GALLANT, ROBERT PHILIP; LAMBERT, ROBERT JOHN
To: TRUSTPOINT INNOVATION TECHNOLOGIES, LTD.
Reel/Frame 039778/0545 →
Continuity (3)
Provisional Application 62242867 · Oct 16, 2015
Provisional Application 62169208 · Jun 1, 2015
Related Publication 20160352702A1 · Dec 1, 2016