IP Library Granted Patent US 10,958,632
Granted Patent B1
US 10,958,632 · App. 15/882,503 · Granted Mar 23, 2021

Authentication methods and apparatus using key-encapsulating ciphertexts and other techniques

Inventors: Daniel V. Bailey (Pepperell, MA); John G. Brainard (Sudbury, MA); Ari Juels (Brookline, MA); Burton S. Kaliski, Jr. (Wellesley, MA)
Assignee: EMC IP Holding Company LLC
H04L63/068H04L9/088H04L9/0861H04L9/0877H04L9/0891H04L9/0897H04L9/3226H04L9/3228H04L9/3234H04L63/0492H04L63/08H04W12/06H04L63/0838H04L2209/805
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,958,632
App. No.
15/882,503
Granted
Mar 23, 2021
Kind
B1
Abstract

In one aspect, one or more key-encapsulating ciphertexts are generated and stored in a processing device. The processing device receives authentication information from another processing device, and utilizes the authentication information to decrypt at least one of the key-encapsulating ciphertexts to recover an associated key. The authentication information may comprise, for example, a tokencode. In an illustrative embodiment, the authentication information may comprise a plurality of gradually rotating keys with overlapping refresh intervals. As a more particular example, the authentication information may comprise a plurality of hash chains wherein successive ones of the hash chains overlap one another in a designated number of time steps.

Claims (34)

1. A method comprising the steps of:

generating a designated number of key-encapsulating ciphertexts, the designated number comprising an integer greater than one;

storing the designated number of key-encapsulating ciphertexts in a processing device;

receiving first and at least second authentication information from another processing device, the first authentication information being refreshed at first time steps that are respective first multiples of the designated number, the second authentication information being refreshed at second time steps that are respective second multiples of the designated number, the second multiples being different than the first multiples; and

utilizing one of the first and at least second authentication information to decrypt one of the designated number of key-encapsulating ciphertexts to recover an associated key.

2. The method of claim 1 wherein the designated number of key-encapsulating ciphertexts comprise respective independent key-encapsulating ciphertexts.

3. The method of claim 1 wherein the first and at least second authentication information comprise first and at least second tokencodes.

4. The method of claim 1 wherein the first and at least second authentication information comprise first and at least second keys.

5. The method of claim 1 wherein the first and at least second authentication information comprise first and at least second hash chains.

6. The method of claim 5 wherein elements of a given one of the first and at least second hash chains are computed one time step at a time, starting at a tail of the given hash chain, and when a particular one of the elements is output, an associated memory location is released so as to be made available for storage of other elements of the first and at least second hash chains.

7. The method of claim 1 wherein the processing devices jointly associate a unique identity with a given one of a plurality of time steps over which the at least a portion of the first and at least second authentication information is released such that public keys can be computed for respective ones of the time steps and utilized for identity-based encryption without knowledge of corresponding secret keys.

8. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by a processing device causes the processing device to perform steps of:

generating a designated number of key-encapsulating ciphertexts, the designated number comprising an integer greater than one;

storing the designated number of key-encapsulating ciphertexts in a processing device;

receiving first and at least second authentication information from another processing device, the first authentication information being refreshed at first time steps that are respective first multiples of the designated number, the second authentication information being refreshed at second time steps that are respective second multiples of the designated number, the second multiples being different than the first multiples; and

utilizing one of the first and at least second authentication information to decrypt one of the designated number of key-encapsulating ciphertexts to recover an associated key.

9. The computer program product of claim 8 wherein the designated number of key-encapsulating ciphertexts comprise respective independent key-encapsulating ciphertexts.

10. The computer program product of claim 8 wherein first and at least second authentication information comprise first and at least second tokencodes.

11. The computer program product of claim 8 wherein the first and at least second authentication information comprise first and at least second keys.

12. The computer program product of claim 8 wherein the first and at least second authentication information comprise first and at least second hash chains.

13. The computer program product of claim 12 wherein elements of a given one of the first and at least second hash chains are computed one time step at a time, starting at a tail of the given hash chain, and when a particular one of the elements is output, an associated memory location is released so as to be made available for storage of other elements of the first and at least second hash chains.

14. The computer program product of claim 8 wherein the processing devices jointly associate a unique identity with a given one of a plurality of time steps over which the at least a portion of the first and at least second authentication information is released such that public keys can be computed for respective ones of the time steps and utilized for identity-based encryption without knowledge of corresponding secret keys.

15. An apparatus comprising:

a processing device comprising a processor coupled to a memory;

the processing device being configured to perform steps of:

generating a designated number of key-encapsulating ciphertexts, the designated number comprising an integer greater than one;

storing the designated number of key-encapsulating ciphertexts in a processing device;

receiving first and at least second authentication information from another processing device, the first authentication information being refreshed at first time steps that are respective first multiples of the designated number, the second authentication information being refreshed at second time steps that are respective second multiples of the designated number, the second multiples being different than the first multiples; and

utilizing one of the first and at least second authentication information to decrypt one of the designated number of key-encapsulating ciphertexts to recover an associated key.

16. The apparatus of claim 15 wherein the designated number of key-encapsulating ciphertexts comprise respective independent key-encapsulating ciphertexts.

17. The apparatus of claim 15 wherein the first and at least second authentication information comprise first and at least second tokencodes.

18. The apparatus of claim 15 wherein the first and at least second authentication information comprise a plurality of gradually rotating first and at least second keys with overlapping refresh intervals.

19. The apparatus of claim 15 wherein the first and at least second authentication information comprise first and at least second hash chains, wherein elements of a given one of the first and at least second hash chains are computed one time step at a time, starting at a tail of the given hash chain, and when a particular one of the elements is output, an associated memory location is released so as to be made available for storage of other elements of the first and at least second hash chains.

20. The apparatus of claim 15 wherein the processing devices jointly associate a unique identity with a given one of a plurality of time steps over which the at least a portion of the first and at least second authentication information is released such that public keys can be computed for respective ones of the time steps and utilized for identity-based encryption without knowledge of corresponding secret keys.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 061749/0924 →
RELEASE OF SECURITY INTEREST AT REEL 045482 FRAME 0395 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0314 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
Continuity (3)
Division 13961319 · Aug 7, 2013
Continuation 11671264 · Feb 5, 2007
Provisional Application 60764826 · Feb 3, 2006