IP Library Granted Patent US 10,491,384
Granted Patent B2
US 10,491,384 · App. 15/155,550 · Granted Nov 26, 2019

Device for secure multi-party cryptographic authorization

Inventors: George French (London, GB); Evan Hood (London, GB); Peter Dooman (London, GB); David Taylor (London, GB)
Assignee: BARCLAYS SERVICES LIMITED
H04L9/0861G06Q20/10G06Q20/3278G06Q20/4012G09C1/00H04L9/00H04L9/3066H04L9/32H04L9/3234H04W12/06H04L2209/46H04L2209/56H04W4/80H04W12/00512H04W12/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,491,384
App. No.
15/155,550
Granted
Nov 26, 2019
Kind
B2
Abstract

An electronic device that implements each module of a plurality of modules to jointly perform a secure multiparty cryptographic process to generate authorisation data based on input data, the authorisation data being suitable for use in authorising the electronic device, wherein each module uses secure data that is not shared outside that module to generate intermediate data for use in the secure multiparty cryptographic process to generate authentication data.

Claims (49)

1. An electronic device comprising:

a memory;

a processor coupled to the memory; and

a virtual secure element stored on the memory, the virtual secure element executed by the processor, the virtual secure element comprising:

a first party application having programmed instructions to:

conceal first secret data from a second party application;

generate first intermediate data based on the first secret data;

pass the first intermediate data to the second party application;

authenticate second intermediate data received from the second party application;

generate a first authentication value based, at least in part, on the first intermediate data;

pass the first authentication value to the second party application;

receive a second authentication value from the second party application;

calculate a first check value based on the second intermediate data; and

compare the first check value to the second authentication value; and

the second party application having programmed instructions to:

conceal second secret data from the first party application;

generate the second intermediate data based on the second secret data;

pass the second intermediate data to the first party application;

authenticate the first intermediate data;

generate the second authentication value based, at least in part, on the second intermediate data;

pass the second authentication value to the first party application;

receive the first authentication value from the first party application;

calculate a second check value based on the first intermediate data; and

compare the second check value to the first authentication value,

wherein the first secret data is different from the second secret data.

2. The electronic device of claim 1 ,

wherein the virtual secure element further comprises a calling module application,

wherein the first party application having programmed instructions to:

compute a first authentication data based on the first intermediate data and the second intermediate data in response to authenticating the second intermediate data; and

send the first authentication data to the calling module application, wherein the second party application having programmed instructions to:

compute a second authentication data based on the first intermediate data and the second intermediate data in response to authenticating the first intermediate data; and

send the second authentication data to the calling module application, and

wherein the calling module application having programmed instructions to compare the first authentication data and the second authentication data.

3. The electronic device of claim 2 , wherein the first authentication data comprises at least one of a message authentication code (MAC), an authorization request cryptogram (ARQC), a digital signature, and cipher text.

4. The electronic device of claim 1 , wherein the first party application having programmed instructions to determine, via elliptic curve cryptography, whether the first intermediate data is on a first elliptic curve, and wherein, the second party application having programmed instructions to determine, via the elliptic curve cryptography, whether the second intermediate data is on a second elliptic curve.

5. The electronic device of claim 1 ,

wherein the first party application having programmed instructions to:

generate a first public key corresponding to the first secret data;

share the first public key with the second party application, and

wherein the second party application having programmed instructions to:

generate a second public key corresponding to the second secret data;

share the second public key with the second party application.

6. The electronic device of claim 5 , wherein the first authentication value is based, at least in part, on the first public key, and wherein the second authentication value is based, at least in part, on the second public key.

7. The electronic device of claim 1 , wherein the first check value is based, at least in part, on the second public key, and wherein the second check value is based, at least in part, on the first public key.

8. The electronic device of claim 7 , wherein the first party application having programmed instructions to perform a first hash to obtain the first authentication value, and wherein the second party application having programmed instructions to perform a second hash to obtain the second authentication value.

9. The electronic device of claim 8 , wherein the first party application having programmed instructions to perform a third hash to obtain the first check value, and wherein the second party application having programmed instructions to perform a fourth hash to obtain the second check value.

10. The electronic device of claim 9 , wherein the virtual secure element further comprises a calling module application, wherein the first party application having programmed instructions to send an authentication failure notification to the calling module application in response to the first check value being different than the second authentication value, and wherein the second party application having programmed instructions to send the authentication failure notification to the calling module application in response to the second check value being different than the first authentication value.

11. The electronic device of claim 9 , wherein the virtual secure element further comprises a calling module application, wherein the first party application having programmed instructions to send an authentication pass notification to the calling module application in response to:

the first check value being same as the second authentication value, and the second check value being same as than the first authentication value.

Assignments (3)
CHANGE OF NAME Recorded Nov 22, 2019
From: BARCLAYS SERVICES LIMITED
To: BARCLAYS EXECUTION SERVICES LIMITED
Reel/Frame 051085/0309 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2018
From: BARCLAYS BANK PLC
To: BARCLAYS SERVICES LIMITED
Reel/Frame 047400/0169 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2016
From: FRENCH, GEORGE; HOOD, EVAN; DOOMAN, PETER; TAYLOR, DAVID
To: BARCLAYS BANK PLC
Reel/Frame 038614/0351 →
Continuity (2)
Continuation PCTGB2015051200 · Apr 23, 2015
Related Publication 20160261409A1 · Sep 8, 2016
Cited By (2)
US 12,200,113 US 12,530,283