IP Library Granted Patent US 10,333,700
Granted Patent B2
US 10,333,700 · App. 16/055,368 · Granted Jun 25, 2019

Method and system for exchanging cryptographic keys with an unauthenticated device

Inventors: Juan Garay (San Francisco, CA); Payman Mohassel (San Jose, CA); David Gil (San Francisco, CA)
Assignee: OATH INC.
H04L9/0819G09C5/00H04L9/0841H04L9/0861H04L63/061H04W12/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,333,700
App. No.
16/055,368
Granted
Jun 25, 2019
Kind
B2
Abstract

The present teaching relates to exchanging a key with a device. In one example, a secret value is generated. A message is transmitted to the device. The message includes information related to the secret value based on which the device is to create a cryptographic key. A visual code displayed on the device is captured. The visual code includes a first piece of information and a second piece of information. A key value is generated based on the first piece of information and the secret value. A test value is calculated based on the key value. It is determined whether the device is securely connected based on the test value.

Claims (70)

1. A method, implemented on a machine having at least one processor, storage, and a communication platform connected to a network for exchanging a key with a device, the method comprising:

receiving a message from the device;

generating a secret value;

creating a cryptographic key based on the message and the secret value;

generating a visual code based on the secret value, wherein the visual code includes first information and second information; and

providing, for display, the visual code which is to be captured by the device, wherein the device is to calculate a test value based on the first information and determine whether the device is securely connected based on the test value.

2. The method of claim 1 , wherein the message is received over an insecure channel on the network.

3. The method of claim 1 , wherein the visual code is a one-dimensional barcode or two-dimensional barcode and is to be scanned by the device with a camera.

4. The method of claim 1 , wherein the test value is calculated by at least the following:

generating a key value based on the first information;

calculating a parameter based on a key derivation function and the key value; and

calculating the test value based on the parameter and a pseudorandom function.

5. The method of claim 1 , wherein whether the device is securely connected is determined by at least the following:

extracting a check value from the second information;

comparing the test value with the check value to generate a comparison result; and

determining whether the device is securely connected based on the comparison result.

6. The method of claim 1 , further comprising:

obtaining an indication regarding whether the device is securely connected from a user who has access to the device.

7. The method of claim 1 , further comprising:

receiving a coded value from the device over an insecure channel on the network, wherein the coded value is calculated by the device based on a first check value included in the second information;

determining whether the message is verified based on the message and the coded value;

transmitting third information to the device over an insecure channel on the network, when the message is verified; and

dropping the message when the message is not verified.

8. The method of claim 7 , wherein whether the device is securely connected is determined by at least the following:

extracting a second check value from the third information;

comparing the test value with the second check value to generate a comparison result; and

determining whether the device is securely connected based on the comparison result.

9. A system, having at least one processor, storage, and a communication platform connected to a network for exchanging a key with a device, the system comprising:

a communication unit configured for receiving a message from the device;

a secret value generator configured for generating a secret value;

a key value generator configured for creating a cryptographic key based on the message and the secret value;

a visual code generator configured for generating a visual code based on the secret value, wherein the visual code includes first information and second information; and

an input/output unit configured for providing, for display, the visual code which is to be captured by the device, wherein the device is to calculate a test value based on the first information and determine whether the device is securely connected based on the test value.

10. The system of claim 9 , wherein the message is received over an insecure channel on the network.

11. The system of claim 9 , wherein the visual code is a one-dimensional barcode or two-dimensional barcode and is to be scanned by the device with a camera.

12. The system of claim 9 , wherein the test value is calculated by at least one of the following:

generating a key value based on the first information;

calculating a parameter based on a key derivation function and the key value; and

calculating the test value based on the parameter and a pseudorandom function.

13. The system of claim 9 , wherein whether the device is securely connected is determined by at least the following:

an information extractor configured for extracting a check value from the second information; and

a comparison unit configured for:

comparing the test value with the check value to generate a comparison result; and

determining whether the device is securely connected based on the comparison result.

14. The system of claim 9 , wherein the input/output unit is further configured for:

obtaining an indication regarding whether the device is securely connected from a user who has access to the device.

15. The system of claim 9 , further comprising a message verification unit, wherein:

the communication unit is further configured for receiving a coded value from the device over an insecure channel on the network, wherein the coded value is calculated by the device based on a check value included in the second information;

the message verification unit is configured for determining whether the message is verified based on the message and the coded value;

the communication unit is further configured for transmitting third information to the device over an insecure channel on the network, when the message is verified; and

the message verification unit is further configured for dropping the message when the message is not verified.

16. The system of claim 15 , wherein whether the device is securely connected is determined by at least the following:

an information extractor configured for extracting a second check value from the third information; and

a comparison unit configured for:

comparing the test value with the second check value to generate a comparison result; and

determining whether the device is securely connected based on the comparison result.

17. A machine-readable tangible and non-transitory medium having instructions for exchanging a key with a device, wherein the instructions, when read by the machine, causes the machine to perform the following:

receiving a message from the device;

generating a secret value;

creating a cryptographic key based on the message and the secret value;

generating a visual code based on the secret value, wherein the visual code includes first information and second information; and

providing, for display, the visual code which is to be captured by the device, wherein the device is to calculate a test value based on the first information and determine whether the device is securely connected based on the test value.

18. The machine-readable tangible and non-transitory medium of claim 17 , wherein the visual code is a one-dimensional barcode or two-dimensional barcode and is to be scanned by the device with a camera.

19. The machine-readable tangible and non-transitory medium of claim 17 , wherein the instructions, when read by the machine, causes the machine to further perform the following:

obtaining an indication regarding whether the device is securely connected from a user who has access to the device.

20. The machine-readable tangible and non-transitory medium of claim 17 , wherein the instructions, when read by the machine, causes the machine to further perform the following:

receiving a coded value from the device over an insecure channel on the network, wherein the coded value is calculated by the device based on a first check value included in the second information;

determining whether the message is verified based on the message and the coded value;

transmitting third information to the device over an insecure channel on the network, when the message is verified; and

dropping the message when the message is not verified.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2021
From: VERIZON MEDIA INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 057453/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2020
From: OATH INC.
To: VERIZON MEDIA INC.
Reel/Frame 054258/0635 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2018
From: GARAY, JUAN; MOHASSEL, PAYMAN; GIL, DAVID
To: YAHOO! INC.
Reel/Frame 046560/0214 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2018
From: YAHOO! INC.
To: YAHOO HOLDINGS, INC.
Reel/Frame 046720/0459 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2018
From: YAHOO HOLDINGS, INC.
To: OATH INC.
Reel/Frame 046722/0001 →
Continuity (2)
Division 14853087 · Sep 14, 2015
Related Publication 20180343112A1 · Nov 29, 2018