IP Library Granted Patent US 10,951,412
Granted Patent B2
US 10,951,412 · App. 16/249,474 · Granted Mar 16, 2021

Cryptographic device with administrative access interface utilizing event-based one-time passcodes

Inventor: Piers Bowness (Boxboro, MA)
Assignee: RSA Security LLC
H04L9/3228H04L9/3213H04L9/3234
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,951,412
App. No.
16/249,474
Granted
Mar 16, 2021
Kind
B2
Abstract

A cryptographic device comprises a processor coupled to a memory and is configured to maintain an event counter characterizing a number of successful administrative accesses to the cryptographic device. The cryptographic device is further configured to receive an event-based one-time passcode for a given administrative access attempt, to compare the received event-based one-time passcode to an expected event-based one-time passcode determined as a function of a current value of the event counter, and to grant or deny the given administrative access attempt based at least in part on a result of the comparing. The cryptographic device may store an administrative seed value, with the expected event-based one-time passcode being determined as a function of the administrative seed value and the current value of the event counter. The cryptographic device illustratively comprises a smartcard, a hardware or software authentication token, an Internet-of-Things (IoT) device, or other type of processor-based device having an administrative access interface.

Claims (40)

1. An apparatus comprising:

a cryptographic device comprising a processor coupled to a memory;

the cryptographic device being configured:

to maintain an event counter characterizing a number of successful administrative accesses to the cryptographic device;

to receive an event-based one-time passcode for a given administrative access attempt;

to compare the received event-based one-time passcode to an expected event-based one-time passcode determined as a function of a current value of the event counter by:

identifying a window of having a plurality of acceptable event counter values as a function of the current value of the event counter, and,

determining if an event counter value of the received event-based one-time passcode falls within the identified window; and

to grant or deny the given administrative access attempt based at least in part on a result of the comparing.

2. The apparatus of claim 1 wherein the cryptographic device is further configured to store an administrative seed value.

3. The apparatus of claim 2 wherein the expected event-based one-time passcode is determined as a function of the administrative seed value and the current value of the event counter.

4. The apparatus of claim 1 wherein the cryptographic device comprises a smartcard.

5. The apparatus of claim 1 wherein the cryptographic device comprises at least one of a hardware authentication token and a software authentication token.

6. The apparatus of claim 1 wherein the cryptographic device comprises an Internet-of-Things (IoT) device.

7. The apparatus of claim 1 wherein the cryptographic device comprises an administrative access interface via which the event-based one-time passcode is received.

8. The apparatus of claim 7 wherein the administrative access interface does not require submission of a static unlock code for a successful administrative access.

9. The apparatus of claim 1 wherein the event counter is set to an initial value in conjunction with manufacture of the cryptographic device.

10. The apparatus of claim 9 wherein the initial value comprises one of zero and a random value.

11. The apparatus of claim 1 wherein maintaining the event counter comprises incrementing the event counter for each of a plurality of successful administrative accesses to the cryptographic device.

12. The apparatus of claim 1 wherein maintaining the event counter comprises incrementing the event counter responsive to grant of the given administrative access so as to thereby prevent utilization of the event-based one-time passcode in a subsequent successful administrative access to the cryptographic device.

13. The apparatus of claim 1 wherein an initial value of the event counter and an administrative seed value are provided to an administrative entity via an out-of-band channel for use by the administrative entity in generating event-based one-time passcodes for respective administrative access attempts.

14. A method comprising:

maintaining an event counter characterizing a number of successful administrative accesses to a cryptographic device comprising a processor coupled to a memory;

receiving an event-based one-time passcode for a given administrative access attempt;

comparing the received event-based one-time passcode to an expected event-based one-time passcode determined as a function of a current value of the event counter by:

identifying a window having a plurality of acceptable event counter values as a function of the current value of the event counter, and

determining if an event counter value of the received event-based one-time passcode falls within the identified window; and

granting or denying the given administrative access attempt based at least in part on a result of the comparing;

wherein the maintaining, receiving, comparing and granting or denying are performed by the cryptographic device.

15. The method of claim 14 wherein the cryptographic device is further configured to store an administrative seed value.

16. The method of claim 15 wherein the expected event-based one-time passcode is determined as a function of the administrative seed value and the current value of the event counter.

17. A computer program product comprising a non-transitory processor-readable storage medium having embodied therein one or more software programs, wherein the one or more software programs when executed by a cryptographic device comprising a processor coupled to a memory cause the cryptographic device:

to maintain an event counter characterizing a number of successful administrative accesses to the cryptographic device;

to receive an event-based one-time passcode for a given administrative access attempt;

to compare the received event-based one-time passcode to an expected event-based one-time passcode determined as a function of a current value of the event counter by:

identifying a window having a plurality of acceptable event counter values as a function of the current value of the event counter, and

determining if an event counter value of the received event-based one-time passcode falls within the identified window; and

to grant or deny the given administrative access attempt based at least in part on a result of the comparing.

18. The computer program product of claim 17 wherein the cryptographic device is further configured to store an administrative seed value.

19. The computer program product of claim 18 wherein the expected event-based one-time passcode is determined as a function of the administrative seed value and the current value of the event counter.

Assignments (16)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2019
From: BOWNESS, PIERS
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 048035/0983 →