IP Library Granted Patent US 10,673,832
Granted Patent B2
US 10,673,832 · App. 16/104,280 · Granted Jun 2, 2020

Predefined access policy implementation based on auxiliary information embedded in one-time authentication passcodes

Inventors: Kevin Bowers (Melrose, MA); Nikolaos Triandopoulos (Arlington, MA); John Brainard (Sudbury, MA)
Assignee: EMC IP Holding Company LLC
H04L63/0807G06F21/31G06F21/33H04L9/0662H04L9/12H04L9/3228H04L63/0838H04L63/10H04L63/1441G06F2221/2137H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,673,832
App. No.
16/104,280
Granted
Jun 2, 2020
Kind
B2
Abstract

Techniques are provided for implementing predefined access policies based on auxiliary information embedded in one-time passcode authentication tokens. An exemplary method comprises receiving an authentication passcode generated by a token of a user, wherein the received authentication passcode is derived from a secret seed and based on at least one protocode and embedded auxiliary information; processing the received authentication passcode to extract the embedded auxiliary information from the received authentication passcode, wherein the embedded auxiliary information comprises (i) a silent alarm signal indicating a potential compromise of the token, and (ii) a drifting key signal indicating a current drifting key state of the token, wherein the drifting key signal is processed to detect a cloning of the token; and implementing a predefined access policy (e.g., replace or disable the token of one or more users) based on respective values of the silent alarm signal and the drifting key signal.

Claims (31)

1. A method, comprising:

receiving an authentication passcode generated by a token associated with a user, wherein the received authentication passcode is derived from a secret seed and based on at least one protocode and embedded auxiliary information;

processing the received authentication passcode to extract said embedded auxiliary information from the received authentication passcode, wherein said embedded auxiliary information comprises (i) a silent alarm signal indicating a potential compromise of said token, and (ii) a drifting key signal indicating a current drifting key state of said token that evolves over time, wherein said drifting key signal is processed to detect a cloning of said token using a copy of said secret seed; and

implementing a predefined access policy based on respective values of said silent alarm signal and said drifting key signal.

2. The method of claim 1 , wherein said predefined access policy monitors one or more actions of said user when said silent alarm signal indicates said potential compromise of said token and said drifting key signal does not indicate said cloning of said token.

3. The method of claim 1 , wherein said predefined access policy one or more of replaces and disables said token when said silent alarm signal indicates said potential compromise of said token and said drifting key signal indicates said cloning of said token.

4. The method of claim 1 , wherein said predefined access policy one or more of replaces and disables a plurality of tokens for users of an enterprise when said silent alarm signal does not indicate said potential compromise of said token and said drifting key signal indicates said cloning of said token for at least some of said plurality of said tokens.

5. The method of claim 4 , wherein said plurality of said tokens are replaced or disabled only when a number of said tokens having said drifting key signal indicate said cloning of said respective token satisfies one or more of a minimum number criteria and a minimum time criteria.

6. The method of claim 1 , wherein said predefined access policy increases a server security when said silent alarm signal does not indicate said potential compromise of said token and said drifting key signal indicates said cloning of said token for at least some of a plurality of said tokens for users of an enterprise.

7. The method of claim 1 , wherein said predefined access policy comprises one or more of the following actions: allowing said user full access to said protected resource; allowing said user restricted access to said protected resource; denying said user access to said protected resource; denying said user access to said protected resource and applying an additional secondary step-up authentication mechanism; and allowing said user restricted access to said protected resource in a non-functional manner such that said user is not notified that a potential attack has been detected.

8. A system, comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

receiving an authentication passcode generated by a token associated with a user, wherein the received authentication passcode is derived from a secret seed and based on at least one protocode and embedded auxiliary information;

processing the received authentication passcode to extract said embedded auxiliary information from the received authentication passcode, wherein said embedded auxiliary information comprises (i) a silent alarm signal indicating a potential compromise of said token, and (ii) a drifting key signal indicating a current drifting key state of said token that evolves over time, wherein said drifting key signal is processed to detect a cloning of said token using a copy of said secret seed; and

implementing a predefined access policy based on respective values of said silent alarm signal and said drifting key signal.

9. The system of claim 8 , wherein said predefined access policy monitors one or more actions of said user when said silent alarm signal indicates said potential compromise of said token and said drifting key signal does not indicate said cloning of said token.

10. The system of claim 8 , wherein said predefined access policy one or more of replaces and disables said token when said silent alarm signal indicates said potential compromise of said token and said drifting key signal indicates said cloning of said token.

11. The system of claim 8 , wherein said predefined access policy one or more of replaces and disables a plurality of tokens for users of an enterprise when said silent alarm signal does not indicate said potential compromise of said token and said drifting key signal indicates said cloning of said token for at least some of said plurality of said tokens.

12. The system of claim 11 , wherein said plurality of said tokens are replaced or disabled only when a number of said tokens having said drifting key signal indicate said cloning of said respective token satisfies one or more of a minimum number criteria and a minimum time criteria.

13. The system of claim 8 , wherein said predefined access policy increases a server security when said silent alarm signal does not indicate said potential compromise of said token and said drifting key signal indicates said cloning of said token for at least some of a plurality of said tokens for users of an enterprise.

14. The system of claim 8 , wherein said predefined access policy comprises one or more of the following actions: allowing said user full access to said protected resource; allowing said user restricted access to said protected resource; denying said user access to said protected resource; denying said user access to said protected resource and applying an additional secondary step-up authentication mechanism; and allowing said user restricted access to said protected resource in a non-functional manner such that said user is not notified that a potential attack has been detected.

15. A computer program product, comprising a non-transitory machine-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device perform the following steps:

receiving an authentication passcode generated by a token associated with a user, wherein the received authentication passcode is derived from a secret seed and based on at least one protocode and embedded auxiliary information;

processing the received authentication passcode to extract said embedded auxiliary information from the received authentication passcode, wherein said embedded auxiliary information comprises (i) a silent alarm signal indicating a potential compromise of said token, and (ii) a drifting key signal indicating a current drifting key state of said token that evolves over time, wherein said drifting key signal is processed to detect a cloning of said token using a copy of said secret seed; and

implementing a predefined access policy based on respective values of said silent alarm signal and said drifting key signal.

16. The computer program product of claim 15 , wherein said predefined access policy monitors one or more actions of said user when said silent alarm signal indicates said potential compromise of said token and said drifting key signal does not indicate said cloning of said token.

17. The computer program product of claim 15 , wherein said predefined access policy one or more of replaces and disables said token when said silent alarm signal indicates said potential compromise of said token and said drifting key signal indicates said cloning of said token.

18. The computer program product of claim 15 , wherein said predefined access policy one or more of replaces and disables a plurality of tokens for users of an enterprise when said silent alarm signal does not indicate said potential compromise of said token and said drifting key signal indicates said cloning of said token for at least some of said plurality of said tokens.

19. The computer program product of claim 18 , wherein said plurality of said tokens are replaced or disabled only when a number of said tokens having said drifting key signal indicate said cloning of said respective token satisfies one or more of a minimum number criteria and a minimum time criteria.

20. The computer program product of claim 15 , wherein said predefined access policy increases a server security when said silent alarm signal does not indicate said potential compromise of said token and said drifting key signal indicates said cloning of said token for at least some of a plurality of said tokens for users of an enterprise.

Assignments (16)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2018
From: BOWERS, KEVIN; TRIANDOPOULOS, NIKOLAOS; BRAINARD, JOHN
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 047704/0130 →