IP Library Granted Patent US 11,032,271
Granted Patent B2
US 11,032,271 · App. 16/264,925 · Granted Jun 8, 2021

Authentication based on shared secret seed updates for one-time passcode generation

Inventors: Brian C. Mullins (Burlington, MA); Kevin Bowers (Melrose, MA)
Assignee: RSA Security LLC
H04L63/0838H04L9/085H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,032,271
App. No.
16/264,925
Granted
Jun 8, 2021
Kind
B2
Abstract

Techniques are provided for authenticating a user using shared secret seed updates for one-time passcode (OTP) generation. One method comprises, in response to a first authentication of a client using a given OTP derived from a given shared secret seed, updating, by a server, the given shared secret seed using the given OTP and/or a timestamp from the first authentication to generate an updated given shared secret seed; and evaluating a second authentication using a new OTP derived from the updated given shared secret seed. An anomaly may be detected when the client attempts the second authentication using an OTP and the server determines that the OTP was generated by a previously used shared secret seed. The server may store a set of previously accepted OTPs, and evaluate the previously accepted OTPs to validate the new OTP.

Claims (28)

1. A method, comprising:

in response to a first authentication of a client using a given one-time passcode derived from a given shared secret seed, updating, using at least one processing device of a server, the given shared secret seed using one or more of the given one-time passcode and a timestamp from the first authentication as part of a secret update protocol to generate an updated given shared secret seed; and

evaluating a second authentication using a new one-time passcode derived from the updated given shared secret seed, wherein an anomaly is detected when the client attempts the second authentication using a one-time passcode and the server determines that the one-time passcode was generated by a previously used shared secret seed.

2. The method of claim 1 , wherein, in response to the anomaly being detected, the server initiates a predefined recovery workflow.

3. The method of claim 1 , wherein the server detects a breach of shared secret seeds of multiple users by monitoring a number of said detected anomalies across a user population.

4. The method of claim 1 , wherein the update comprises one or more of an exclusive OR operation and a hash operation applied to one or more of:

(i) at least a portion of the given shared secret seed, and

(ii) one or more of a timestamp of the first authentication, the given one-time passcode

from the first authentication and an expanded version of the given one-time passcode from the first authentication.

5. The method of claim 1 , wherein a client token displays a result of an exclusive OR operation applied to the given one-time passcode and the new one-time passcode and wherein the server receives the result from the client as part of the second authentication.

6. The method of claim 1 , wherein the server sends the client a notification of one or more of that the first authentication succeeded and that the given shared secret seed needs to be updated.

7. The method of claim 1 , wherein the given shared secret seed and the updated shared secret seed are part of a chain of shared secret seed values.

8. The method of claim 1 , wherein the server stores the timestamp of the first authentication when the given shared secret seed was used, and wherein the server receives, from the client, the timestamp of the first authentication from the client as part of the second authentication and the server uses the timestamp of the first authentication to retrieve the given shared secret seed.

9. The method of claim 1 , wherein a token that generates the given one-time passcode and the new one-time passcode requires a user to authenticate before a one-time passcode is presented and provides a mechanism for the user to indicate whether an authentication was successful.

10. The method of claim 1 , wherein the server stores a set of previously accepted one-time passcodes, wherein the server evaluates one or more of the previously accepted one-time passcodes to validate the new one-time passcode.

11. The method of claim 1 , wherein, in response to an undo operation initiated by the client, the given shared secret seed is restored upon a successful authentication of the client.

12. A system, comprising:

a memory; and

at least one processor, coupled to the memory, operative to implement the following steps:

in response to a first authentication of a client using a given one-time passcode derived from a given shared secret seed, updating, by a server, the given shared secret seed using one or more of the given one-time passcode and a timestamp from the first authentication as part of a secret update protocol to generate an updated given shared secret seed; and

evaluating a second authentication using a new one-time passcode derived from the updated given shared secret seed, wherein an anomaly is detected when the client attempts the second authentication using a one-time passcode and the server determines that the one-time passcode was generated by a previously used shared secret seed.

13. The system of claim 12 , wherein a token that generates the given one-time passcode and the new one-time passcode requires a user to authenticate before a one-time passcode is presented and provides a mechanism for the user to indicate whether an authentication was successful.

14. The system of claim 12 , wherein a token that generates the given one-time passcode and the new one-time passcode requires a user to authenticate before a one-time passcode is presented and provides a mechanism for the user to indicate whether an authentication was successful.

15. The system of claim 12 , wherein, in response to an undo operation initiated by the client, the given shared secret seed is restored upon a successful authentication of the client.

16. A computer program product, comprising a non-transitory machine-readable medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device perform the following steps:

in response to a first authentication of a client using a given one-time passcode derived from a given shared secret seed, updating, by a server, the given shared secret seed using one or more of the given one-time passcode and a timestamp from the first authentication as part of a secret update protocol to generate an updated given shared secret seed; and

evaluating a second authentication using a new one-time passcode derived from the updated given shared secret seed, wherein an anomaly is detected when the client attempts the second authentication using a one-time passcode and the server determines that the one-time passcode was generated by a previously used shared secret seed.

17. The computer program product of claim 16 , wherein the server stores a set of previously accepted one-time passcodes, wherein the server evaluates one or more of the previously accepted one-time passcodes to validate the new one-time passcode.

Assignments (16)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 70587/0885 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075031/0394 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 21, 2025
From: RSA SECURITY LLC; RSA SECURITY USA LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 070587/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2019
From: MULLINS, BRIAN C.; BOWERS, KEVIN
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 048217/0415 →
Continuity (1)
Related Publication 20200252392A1 · Aug 6, 2020