IP Library Granted Patent US 10,708,058
Granted Patent B2
US 10,708,058 · App. 15/798,502 · Granted Jul 7, 2020

Devices and methods for client device authentication

Inventors: Nicolas Le Scouarnec (Liffre, FR); Christoph Neumann (Rennes, FR); Olivier Heen (Domloup, FR); Jean-Ronan Vigouroux (Rennes, FR)
Assignee: INTERDIGITAL CE PATENT HOLDINGS, SAS
H04L9/3226G06F21/31H04L9/0863H04L9/0891H04L9/3242H04L9/3271H04L63/061H04L63/083H04L63/0876H04W12/04H04W12/06H04W84/12H04W88/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,708,058
App. No.
15/798,502
Granted
Jul 7, 2020
Kind
B2
Abstract

An access point receives from a client a first nonce and a first cryptographic hash for the first nonce, the first cryptographic hash calculated using a first key derived from a second key, the second key input on the client or derived from a passphrase input on the client, derives first keys from each of a stored primary input and at least one stored secondary input valid at the deriving, the stored primary input and the at least one stored secondary input each being one of a second key and a passphrase, verifies the cryptographic hash using each derived first key to find a derived first key that checks the first cryptographic hash, generates a third key and a second cryptographic hash using the derived first key that checks the first cryptographic hash, and sends the third key and the second cryptographic hash to the client.

Claims (31)

1. A method for client authentication at an access point, the method comprising, in at least one hardware processor of the access point:

receiving from a client a first cryptographic hash for the first nonce, the first cryptographic hash calculated using a first key derived from a second key, the second key input on the client or derived from a passphrase input on the client;

deriving first keys from each of a stored primary input and at least one stored secondary input valid at the deriving, the stored primary input and the at least one stored secondary input each being one of a second key and a passphrase;

verifying the cryptographic hash using each derived first key to find a derived first key that checks the first cryptographic hash;

generating a third key and a second cryptographic hash using the derived first key that checks the first cryptographic hash;

sending the third key, encrypted using an encryption key generated from the derived first key that checks the first cryptographic hash, and the second cryptographic hash to the client; and

renewing the third key when a stored secondary input becomes invalid.

2. The method of claim 1 , each stored secondary input having a defined, limited period of validity or each stored secondary input corresponding to the primary input with at least one typing error.

3. The method of claim 1 , wherein the access point is a Wi-Fi access point and the method further comprises receiving a first nonce from the client and sending a second nonce to the client and wherein the first keys are further derived from the first nonce and the second nonce.

4. An access point comprising:

a communications interface configured to:

receive from a client a first cryptographic hash for the first nonce, the first cryptographic hash calculated using a first key derived from a second key, the second key input on the client or derived from a passphrase input on the client; and

send to the client a third key and a second cryptographic hash;

memory configured to store a primary input and at least one secondary input, the primary input and the at least one secondary input each being one of a second key and a passphrase; and

at least one hardware processor configured to:

derive first keys from each of the stored primary input and at least one secondary input valid at the deriving;

verify the cryptographic hash using each derived first key to find a derived first key that checks the first cryptographic hash;

generate the third key and the second cryptographic hash using the derived first key that checks the first cryptographic hash;

encrypt the third key using an encryption key generated from the derived first key that checks the first cryptographic hash before transmission to the client; and

renew the third key when a stored secondary input becomes invalid.

5. The access point of claim 4 , each stored secondary input having a defined, limited period of validity or each stored secondary input corresponding to the primary input with at least one typing error.

6. The access point of claim 5 , wherein the at least one hardware processor is further configured to renew the third key when a stored secondary input becomes invalid.

7. The access point of claim 4 , wherein the access point is a Wi-Fi access point and the communications interface is further configured to receive a first nonce from the client and to send a second nonce to the client and wherein the at least one hardware processor is configured to derive the first keys further from the first nonce and the second nonce.

8. The access point of claim 7 , wherein the at least one hardware processor is further configured to derive first keys from a stored secondary input only during the period of validity for the stored secondary input.

9. Computer program product which is stored on a non-transitory computer readable medium and comprises program code instructions executable by a processor to:

receive from a client a first cryptographic hash for the first nonce, the first cryptographic hash calculated using a first key derived from a second key, the second key input on the client or derived from a passphrase input on the client;

derive first keys from each of a stored primary input and at least one stored secondary input valid at the deriving, the stored primary input and the at least one stored secondary input each being one of a second key and a passphrase;

verify the cryptographic hash using each derived first key to find a derived first key that checks the first cryptographic hash;

generate a third key, and a second cryptographic hash using the derived first key that checks the first cryptographic hash;

send the third key, encrypted using an encryption key generated from the derived first key that checks the first cryptographic hash, and the second cryptographic hash to the client; and

renew the third key when a stored secondary input becomes invalid.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2019
From: THOMSON LICENSING
To: INTERDIGITAL CE PATENT HOLDINGS
Reel/Frame 049561/0201 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 045843 FRAME 0314. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 21, 2018
From: VIGOUROUX, JEAN-RONAN
To: THOMSON LICENSING
Reel/Frame 046195/0482 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2018
From: VIGOUROUX, JEAN-RONAN
To: THOMSON LISENSING
Reel/Frame 045843/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2018
From: LE SCOUARNEC, NICOLAS; NEUMANN, CHRISTOPH; HEEN, OLIVIER
To: THOMSON LICENSING
Reel/Frame 044745/0214 →
Priority Claims (2)
EP 16306445 · Nov 4, 2016 · regional
EP 17305661 · Jun 6, 2017 · regional
Continuity (1)
Related Publication 20180131519A1 · May 10, 2018
Cited By (1)
US 12,452,660