IP Library Granted Patent US 10,165,441
Granted Patent B2
US 10,165,441 · App. 15/273,166 · Granted Dec 25, 2018

Simple protocol for tangible security

Inventors: YuQun Chen (Seattle, WA); Michael J. Sinclair (Kirkland, WA); Josh D. Benaloh (Redmond, WA)
Assignee: Microsoft Technology Licensing, LLC
H04W12/06H04L9/0863H04L9/0869H04L9/14H04L63/0428H04L63/0492H04L63/06H04L63/083H04L63/0853H04L2209/24H04W88/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,165,441
App. No.
15/273,166
Granted
Dec 25, 2018
Kind
B2
Abstract

The claimed subject matter provides systems and/or methods that effectuate a simple protocol for tangible security on mobile devices. The system can include devices that generate sets of keys and associated secret identifiers, employs the one or more keys to encrypt a secret and utilizes the identifiers and encryptions of the secret to populate a table associated with a security token device that is used in conjunction with a mobile device to release sensitive information persisted on the mobile device for user selected purposes.

Claims (60)

1. A method comprising:

encrypting, by one or more processor of a computing device, a secret using one or more keys to create one or more encrypted versions of the secret;

sending, to a security token device, the one or more encrypted versions of the secret to be stored on the security token device, the sending being performed while the computing device is within a predetermined proximity to the security token device;

receiving a request for use of the secret; and

in response to receiving the request for use of the secret and based at least in part on determining that the security token device is within the predetermined proximity to the computing device:

retrieving, by the computing device, at least one encrypted version of the secret of the one or more encrypted versions of the secret from the security token device; and

decrypting the at least one encrypted version of the secret using at least one key of the one or more keys.

2. The method of claim 1 , further comprising sending, to the security token device, one or more secret identifiers, each of the one or more secret identifiers being associated with at least one of the one or more keys used to encrypt the secret.

3. The method of claim 1 , wherein at least one of sending the one or more encrypted versions of the secret or the retrieving the at least one encrypted version of the secret is performed over at least one of:

a personal area network (PAN);

a local area network (LAN);

a campus area network (CAN);

metropolitan area network (MAN);

an extranet;

an intranet;

the Internet; or

a wide area network (WAN).

4. The method of claim 2 , wherein the sending the one or more encrypted versions of the secret while the computing device is within the predetermined proximity to the security token device comprises sending the one or more encrypted versions of the secret while the computing device is in electrical contact with the security token device.

5. The method of claim 4 , further comprising supplying power to the security token device while the computing device is in electrical contact with the security token device.

6. The method of claim 1 , wherein the retrieving the at least one encrypted version of the secret of the one or more encrypted versions of the secret from the security token device comprises:

sending, to the security token device, a retrieval request for the at least one encrypted version of the secret; and

receiving, from the security token device, the at least one encrypted version of the secret.

7. The method of claim 1 , wherein the secret comprises a password.

8. A computing device comprising:

one or more processors; and

memory communicatively coupled to the one or more processors and storing instructions that, when executed, configure the one or more processors to perform acts comprising:

encrypting a secret using one or more keys to create one or more encrypted versions of the secret;

sending, to a security token device, the one or more encrypted versions of the secret to be stored on the security token device, the sending being performed while the computing device is within a predetermined proximity to the security token device;

determining that a component of the computing device requests use of the secret; and

based at least in part on the determining that the component requests use of the secret and determining that the security token device is within the predetermined proximity to the computing device:

retrieving at least one encrypted version of the secret of the one or more encrypted versions of the secret from the security token device; and

decrypting the at least one encrypted version of the secret using at least one key of the one or more keys.

9. The computing device of claim 8 , the acts further comprising sending, to the security token device, one or more secret identifiers, each of the one or more secret identifiers being associated with at least one of the one or more keys used to encrypt the secret.

10. The computing device of claim 8 , wherein the secret comprises at least one of a password or user identification information.

11. The computing device of claim 8 , wherein the secret comprises information associated with unlocking an account associated with the computing device.

12. The computing device of claim 8 , wherein the secret comprises information associated with purchasing a good or service.

13. The computing device of claim 8 , wherein at least one of the sending the one or more encrypted versions of the secret or the retrieving the at least one encrypted version of the secret is performed over at least one of:

a personal area network (PAN);

a local area network (LAN);

a campus area network (CAN);

metropolitan area network (MAN);

an extranet;

an intranet;

the Internet; or

a wide area network (WAN).

14. A system comprising:

one or more processors; and

memory communicatively coupled to the one or more processors and storing instructions that, when executed, configure the one or more processors to perform acts comprising:

sending, to a security token device, a secret to be stored on the security token device, the sending being performed while the system is within a predetermined proximity to the security token device;

determining that the secret is being requested;

detecting that the security token device is within the predetermined proximity to the system; and

based at least in part on the determining that the secret is being requested and the detecting that the security token device is within the predetermined proximity to the system:

retrieving the secret from the security token device; and

performing an action using the secret.

15. The system of claim 14 , wherein the sending the secret while the system is within the predetermined proximity to the security token device comprises sending the secret while the system is in electrical contact with the security token device.

16. The system of claim 15 , wherein the acts further comprise supplying power to the security token device while the system is in electrical contact with the security token device.

17. The system of claim 14 , wherein the security token device comprises at least one of a watch, a watchband, a bracelet, a necklace, a cufflink, a key fob, a tie clip, a card, or a phone.

18. The system of claim 14 , wherein the secret comprises at least one of a password or user identification information.

19. The system of claim 14 , wherein the at least one secret comprises at least one of credit card information, debit card information, or bank account information.

20. The system of claim 14 , wherein at least one of the sending the secret or the retrieving the secret is performed using at least one of near-field communication or communication over a personal area network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2016
From: CHEN, YUQUN; SINCLAIR, MICHAEL J.; BENALOH, JOSH D.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 039835/0564 →
Continuity (3)
Continuation 14936351 · Nov 9, 2015
Continuation 12250308 · Oct 13, 2008
Related Publication 20170013459A1 · Jan 12, 2017