IP Library Granted Patent US 11,139,982
Granted Patent B2
US 11,139,982 · App. 16/261,916 · Granted Oct 5, 2021

Communication-efficient device delegation

Inventors: Zulfikar A. Ramzan (Saratoga, CA); Salah E. Machani (Medford, CA)
Assignee: RSA Security LLC
H04L9/3247H04L9/0643H04L9/0819H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,139,982
App. No.
16/261,916
Granted
Oct 5, 2021
Kind
B2
Abstract

Techniques are provided for communication-efficient device delegation. One method comprises, in response to a request for a new signing key of a given device, determining a number of new signing key requests received for the user of the given device; determining a new public verification key of the given device for an identity-based signature scheme by traversing a cryptographic hash chain backwards from a position of an initial selected value of the cryptographic hash chain; computing a new signing key based on public parameters and secret parameters of a backup component and the initial selected value; and providing the new public verification key and the new signing key to the given device. The given device authenticates to an authentication service using an identity-based signature computed using the new signing key. The request for the new signing key is submitted, for example, when the given device is lost, damaged, unavailable or stolen.

Claims (36)

1. A method, comprising:

in response to a request for a new signing key of a given device, at least one processing device of a backup component performs the following steps:

determining a number of new signing key requests that have been received for a user of the given device;

determining a new public verification key of the given device for an identity-based signature scheme by traversing a cryptographic hash chain comprised of a plurality of hash values, from a position of an initial selected value of the cryptographic hash chain backwards in the cryptographic hash chain based on the number of new signing key requests, wherein the cryptographic hash chain is computed from a seed value construct of the backup component and is traversed by skipping a number of hash values of the chain to determine the new public verification key;

computing a new signing key of the given device based on one or more public parameters of the backup component, one or more secret parameters of the backup component, the number of hash values of the chain to be skipped, and the initial selected value; and

providing the new public verification key of the given device and the new signing key of the given device to the given device, wherein the given device authenticates to an authentication service for the identity-based signature scheme using an identity-based signature that is computed by the given device using the new signing key, the one or more public parameters of the backup component and an authentication challenge string.

2. The method of claim 1 , further comprising a step of the backup component providing the number of new signing key requests to the given device.

3. The method of claim 1 , wherein the given device provides the number of new signing key requests to the authentication service and wherein the authentication service validates the provided number of new signing key requests.

4. The method of claim 1 , wherein the given device provides the new public verification key of the given device to the authentication service and wherein the authentication service validates the new public verification key of the given device by comparing the new public verification key of the given device to at least one prior version of the public verification key of the user of the given device.

5. The method of claim 4 , wherein the authentication service validates the new public verification key of the given device, the one or more public parameters of the backup component and the authentication challenge string using the new public verification key of the given device.

6. The method of claim 4 , wherein the authentication service authenticates the given device upon validating the new public verification key of the given device.

7. The method of claim 1 , wherein the request for the new signing key of the given device is submitted when the given device is one or more of lost, damaged, unavailable and stolen.

8. A system, comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps: in response to a request for a new signing key of a given device, a backup component performs the following steps:

determining a number of new signing key requests that have been received for a user of the given device;

determining a new public verification key of the given device for an identity-based signature scheme by traversing a cryptographic hash chain comprised of a plurality of hash values, from a position of an initial selected value of the cryptographic hash chain backwards in the cryptographic hash chain based on the number of new signing key requests, wherein the cryptographic hash chain is computed from a seed value construct of the backup component and is traversed by skipping a number of hash values of the chain to determine the new public verification key;

computing a new signing key of the given device based on one or more public parameters of the backup component, one or more secret parameters of the backup component, the number of hash values of the chain to be skipped, and the initial selected value; and

providing the new public verification key of the given device and the new signing key of the given device to the given device, wherein the given device authenticates to an authentication service for the identity-based signature scheme using an identity-based signature that is computed by the given device using the new signing key, the one or more public parameters of the backup component and an authentication challenge string.

9. The system of claim 8 , further comprising a step of the backup component providing the number of new signing key requests to the given device.

10. The system of claim 8 , wherein the given device provides the number of new signing key requests to the authentication service and wherein the authentication service validates the provided number of new signing key requests.

11. The system of claim 8 , wherein the given device provides the new public verification key of the given device to the authentication service and wherein the authentication service validates the new public verification key of the given device by comparing the new public verification key of the given device to at least one prior version of the public verification key of the user of the given device.

12. The system of claim 11 , wherein the authentication service validates the new public verification key of the given device, the one or more public parameters of the backup component and the authentication challenge string using the new public verification key of the given device.

13. The system of claim 11 , wherein the authentication service authenticates the given device upon validating the new public verification key of the given device.

14. The system of claim 8 , wherein the request for the new signing key of the given device is submitted when the given device is one or more of lost, damaged, unavailable and stolen.

15. A computer program product, comprising a tangible machine-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device perform the following steps:

in response to a request for a new signing key of a given device, a backup component performs the following steps:

determining a number of new signing key requests that have been received for a user of the given device;

determining a new public verification key of the given device for an identity-based signature scheme by traversing a cryptographic hash chain comprised of a plurality of hash values, from a position of an initial selected value of the cryptographic hash chain backwards in the cryptographic hash chain based on the number of new signing key requests, wherein the cryptographic hash chain is computed from a seed value construct of the backup component and is traversed by skipping a number of hash values of the chain to determine the new public verification key;

computing a new signing key of the given device based on one or more public parameters of the backup component, one or more secret parameters of the backup component, the number of hash values of the chain to be skipped, and the initial selected value; and

providing the new public verification key of the given device and the new signing key of the given device to the given device, wherein the given device authenticates to an authentication service for the identity-based signature scheme using an identity-based signature that is computed by the given device using the new signing key, the one or more public parameters of the backup component and an authentication challenge string.

16. The computer program product of claim 15 , further comprising a step of the backup component providing the number of new signing key requests to the given device.

17. The computer program product of claim 15 , wherein the given device provides the number of new signing key requests to the authentication service and wherein the authentication service validates the provided number of new signing key requests.

18. The computer program product of claim 15 , wherein the given device provides the new public verification key of the given device to the authentication service and wherein the authentication service validates the new public verification key of the given device by comparing the new public verification key of the given device to at least one prior version of the public verification key of the user of the given device.

19. The computer program product of claim 18 , wherein the authentication service validates the new public verification key of the given device, the one or more public parameters of the backup component and the authentication challenge string using the new public verification key of the given device, and authenticates the given device upon validating the new public verification key of the given device.

20. The computer program product of claim 15 , wherein the request for the new signing key of the given device is submitted when the given device is one or more of lost, damaged, unavailable and stolen.

Assignments (16)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 70587/0885 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075031/0394 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 21, 2025
From: RSA SECURITY LLC; RSA SECURITY USA LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 070587/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2019
From: RAMZAN, ZULFIKAR A.; MACHANI, SALAH E.
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 049442/0069 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
Continuity (1)
Related Publication 20200244465A1 · Jul 30, 2020