IP Library Granted Patent US 9,992,189
Granted Patent B2
US 9,992,189 · App. 15/676,689 · Granted Jun 5, 2018

Generation and validation of derived credentials

Inventors: Chris Hayes (Danielson, CT); Garret Florian Grajek (Aliso Viejo, CA); Jeffrey Chiwai Lo (Irvine, CA); Allen Yu Quach (Rosemead, CA); Firas Shbeeb (Tustin, CA)
Assignee: SecureAuth Corporation
H04L63/0823G06F21/33G06F21/41H04L9/321H04L9/3228H04L9/3265H04L9/3268H04L63/0846
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,992,189
App. No.
15/676,689
Granted
Jun 5, 2018
Kind
B2
Abstract

A CAC/PIV certificate associated with a HSPD-12 identity is used to generate a derived credential for storage on a device, such as a mobile device, that lacks a CAC/PIV card reader. The derived credential (which is distinct from the original CAC/PIV certificate) may then be used to grant the device access to secure resources that may otherwise require a CAC/PIV certificate. Embodiments of the present disclosure also relate to systems and methods for authenticating or validating a derived credential stored on a mobile device.

Claims (32)

1. A method of enabling a user of a CAC/PIV (Common Access Card or Personal Identity Verification) card to obtain access to a secure resource from a computing device that lacks a CAC/PIV card reader, the method comprising, by execution of program code by a server system:

receiving, over a network, a CAC/PIV certificate from a first computing device associated with the user, the CAC/PIV certificate read from the CAC/PIV card by a CAC/PIV card reader of the first computing device;

validating the received CAC/PIV certificate;

generating a derived credential that corresponds to, and is derived using, the received CAC/PIV certificate, the derived credential being distinct from the received CAC/PIV certificate;

sending a passcode to the first computing device for entry by the user on a second computing device, the passcode being one or both of (a) a one-time-use passcode that is valid only for a single use, and (b) a time limited passcode that is valid for a limited time period;

receiving the passcode from the second computing device;

validating the received passcode, wherein validating the received passcode comprises one or both of: determining whether the received passcode has been used, and determining whether the received passcode has expired; and

after validating the received passcode, transmitting the derived credential to the second computing device associated with the user, said second computing device lacking a CAC/PIV card reader;

wherein the derived credential enables the user to access, from the second computing device, a secure network resource that is accessible from the first computing device using the CAC/PIV card.

2. The method of claim 1 , wherein the derived credential is an X.509 certificate.

3. The method of claim 1 , wherein the derived credential is an X.509 certificate mapped to a HSPD-12 (Homeland Security Presidential Directive 12) identity.

4. The method of claim 1 , wherein the derived credential comprises a public/private key pair.

5. The method of claim 1 , further comprising receiving the derived credential from the second computing device, validating the derived credential received from the second computing device, and at least partly in response to validating the derived credential, providing to the second computing device access data that enables the second computing device to access the secure network resource.

6. The method of claim 5 , wherein validating the derived credential comprises comparing attributes of the derived credential to attributes of the CAC/PIV certificate.

7. The method of claim 1 , wherein the derived credential has an expiration attribute that matches an expiration attribute of the CAC/PIV certificate.

8. The method of claim 1 , wherein the derived credential has a name that matches a name of the CAC/PIV certificate.

9. A method of enabling a user of a smart card that stores a certificate to obtain access to a secure resource from a computing device that lacks a smart card reader capable of reading the smart card, the method comprising, by execution of program code by a server system:

receiving, over a network, the certificate from a first computing device associated with the user, the certificate read from the smart card by a smart card reader of the first computing device;

validating the received certificate, wherein validating the received certificate comprises validating the received certificate against a certificate chain, expiration date and revocation list, and comprises validating a common name of the received certificate;

generating a derived credential that corresponds to, and is derived using, the received certificate, the derived credential being distinct from the received certificate;

sending a passcode to the first computing device for entry on a second computing device associated with the user, the passcode being one or both of (a) a one-time-use passcode that is valid only for a single use, and (b) a time limited passcode that is valid for a limited time period;

receiving the passcode from the second computing device;

validating the received passcode, wherein validating the received passcode comprises one or both of: determining whether the received passcode has been used, and determining whether the received passcode has expired; and

after validating the received passcode, transmitting the derived credential to the second computing device, said second computing device lacking a smart card reader capable of reading the smart card;

wherein the derived credential enables the user to access, from the second computing device, a secure network resource that is accessible from the first computing device using the smart card.

10. The method of claim 9 , wherein the smart card is a Common Access Card (CAC) smart card.

11. The method of claim 9 , wherein the smart card is a Personal Identity Verification (PIV) smart card.

12. The method of claim 9 , wherein the certificate is a X.509 certificate.

13. The method of claim 9 , further comprising receiving the derived credential from the second computing device, validating the derived credential received from the second computing device, and at least partly in response to validating the derived credential, providing to the second computing device access data that enables the second computing device to access the secure network resource.

14. The method of claim 13 , wherein validating the derived credential comprises comparing attributes of the derived credential to attributes of the certificate.

15. The method of claim 9 , wherein the derived credential has an expiration attribute that matches an expiration attribute of the certificate.

16. The method of claim 9 , wherein the derived credential has a name that matches a name of the certificate.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 070086/0011 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 070086/0158 →
RELEASE OF SECURITY INTEREST Recorded Aug 14, 2024
From: MIDTOWN MADISON MANAGEMENT LLC (AS SUCCESSOR TO ELM PARK CAPITAL MANAGEMENT, LLC)
To: SECUREAUTH CORPORATION
Reel/Frame 068288/0856 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2024
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 068251/0496 →
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
SECURITY INTEREST Recorded Oct 27, 2021
From: SECUREAUTH CORPORATION
To: ELM PARK CAPITAL MANAGEMENT, LLC
Reel/Frame 057937/0732 →
SECURITY INTEREST Recorded Jan 3, 2018
From: SECUREAUTH CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 044522/0031 →
Continuity (3)
Continuation 14815699 · Jul 31, 2015
Provisional Application 62032483 · Aug 1, 2014
Related Publication 20180091499A1 · Mar 29, 2018