IP Library Granted Patent US 11,463,430
Granted Patent B2
US 11,463,430 · App. 16/264,897 · Granted Oct 4, 2022

Authentication based on shared secret updates

Inventors: Brian C. Mullins (Burlington, MA); Kevin Bowers (Melrose, MA)
Assignee: RSA Security LLC
H04L63/083H04L9/085
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,463,430
App. No.
16/264,897
Granted
Oct 4, 2022
Kind
B2
Abstract

Techniques are provided for authenticating a user using shared secret updates. One method comprises, in response to a first authentication of a client using a given shared secret, updating, by the server, the given shared secret using information from the first authentication as part of a secret update protocol to generate an updated shared secret; and evaluating a second authentication using the updated shared secret. An anomaly may be detected when the client attempts the second authentication using a shared secret and the server determines that the shared secret was previously used for an authentication. The server may detect a breach of shared secrets of multiple users by monitoring a number of the detected anomalies across a user population and initiate a predefined recovery flow depending upon a number of impacted users.

Claims (44)

1. A method comprising:

in response to a first authentication using a given shared secret received from a user operating a user device, updating, using at least one processing device of a server, the given shared secret using information from the first authentication as part of a secret update protocol to generate a first updated shared secret;

receiving a second authentication using the givenfirst updated shared secret;

updating, using the at least one processing device, the first updated secret to generate a second updated shared secret; and

receiving a third authentication using the first updated shared secret, wherein:

evaluating the second authentication using the given shared secret, wherein:

the first authentication is a request for user access to a computer resource;

the second authentication is a request for user access to the same computer resource;

the third authentication is a request for user access to the same computer resource; and

the server is an authentication server configured to detect an attack when the third authentication uses the first updated shared secret and the server determines that the first updated shared secret was previously used for the second authentication and that the second updated secret has been generated.

2. The method of claim 1 , wherein, in response to the attack being detected, the server imitates a predefined recovery workflow.

3. The method of claim 1 , wherein, the detection can be performed at the time of one or more of the secondthird authentication and a subsequent batch processing.

4. The method of claim 1 , wherein the server detects a breach of shared secrets of multiple users by monitoring a number of said detected attacks across a user population and initiates a predefined recovery flow depending upon a number of impacted users.

5. The method of claim 1 , wherein the update comprises one or more of an exclusive OR operation and a hashtag operation applied to the given shared secret and the information from the first authentication.

6. The method of claim 1 , wherein the information from the first authentication comprises one or more of a timestamp of the first authentication, a random value used in the first authentication, and a substantially unique value used in the first authentication.

7. The method of claim 1 , wherein the given shared secret comprises one or more of a password, a cryptographic key, a cryptographic symmetric key, a personal identification number, and a shared secret seed used to derive one-time passcodes.

8. The method of claim 1 , wherein the server sends the client a notification of one or more of that the first authentication succeeded and that the given shared secret needs to be updated.

9. The method of claim 1 , wherein the given shared secret, the first updated shared secret, and the second updated shared secret are part of a chain of shared secret values.

10. The method of claim 1 , wherein the server stores a timestamp of the first authentication when the given shared secret was used, and wherein the server receives, from the client, the timestamp of the first authentication as part of the second authentication and the server uses the received timestamp of the first authentication to retrieve the given shared secret.

11. A system comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

in response to a first authentication using a given shared secret received from a user operating a user device, updating, by the server, the given shared secret using information from the first authentication as part of a secret update protocol to generate a first updated shared secret;

receiving a second authentication using the givenfirst updated shared secret;

updating, using the at least one processing device, the first updated secret to generate a second updated shared secret; and

receiving a third authentication using the first updated shared secret, wherein:

the first authentication is a request for user access to a computer resource;

the second authentication is a request for user access to the same computer resource;

the third authentication is a request for user access to the same computer resource; and

the server is an authentication server configured to detect an attack when the third authentication uses the first updated shared secret and the server determines that the first updated shared secret was previously used for the first authentication and that the second updated shared secret has been generated.

12. The system of claim 11 , wherein the server detects a breach of shared secrets of multiple users by monitoring a number of said detected attacks across a user population and initiates a predefined recovery flow depending upon a number of impacted users.

13. The system of claim 11 , wherein the given shared secret, and the first updated shared secret, and the second updated shared secret are part of a chain of shared secret values.

14. The system of claim 11 , wherein the server stores a timestamp of the first authentication when the given shared secret was used, and wherein the server receives, from the client, the timestamp of the first authentication as part of the second authentication and the server uses the received timestamp of the first authentication to retrieve the given shared secret.

15. A computer program product, comprising a tangible machine-readable storage medium having encoded therein executable code of one or more software programs, wherein one or more software programs when executed by at least one processing device perform the following steps:

in response to a first authentication using a given shared secret received from a user operating a user device, updating, by the server, the given shared secret using information from the first authentication as part of a secret update protocol to generate a first updated shared secret;

receiving a second authentication using the givenfirst updated shared secret;

updating, using the at least one processing device, the first updated secret to generate a second updated shared secret;

receiving a third authentication using the first updated shared secret, wherein:

the first authentication is a request for user access to a computer resource;

the second authentication is a request for user access to the same computer resource;

the third authentication is a request for user access to the same computer resource; and

the server is an authentication server configured to detect an attack when the third authentication uses the first updated shared secret and the server determines that the first updated shared secret was previously used for the second authentication and that the second updated secret has been generated.

16. The computer program product of claim 15 , wherein the given shared secret, the first updated shared secret, and the second updated shared secret are part of a chain of shared secret values.

17. The computer program product of claim 15 , wherein the server stores a timestamp of the first authentication when the given shared secret was used, and wherein the server receives, from the client, the timestamp of the first authentication as part of the second authentication and the server uses the received timestamp of the first authentication to retrieve the given shared secret.

Assignments (16)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 70587/0885 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075031/0394 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 21, 2025
From: RSA SECURITY LLC; RSA SECURITY USA LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 070587/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2019
From: MULLINS, BRIAN C.; BOWERS, KEVIN
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 048217/0190 →