IP Library Granted Patent US 10,637,818
Granted Patent B2
US 10,637,818 · App. 16/371,990 · Granted Apr 28, 2020

System and method for resetting passwords on electronic devices

Inventors: Robert Philip Gallant (Corner Brook, CA); Robert John Lambert (Cambridge, CA)
Assignee: ETAS Embedded Systems Canada Inc.
H04L51/22G06F21/31H04L51/04H04L63/083H04L63/123G06F2221/2131
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,637,818
App. No.
16/371,990
Granted
Apr 28, 2020
Kind
B2
Abstract

A system and method are provided for enabling a password reset mechanism for a secured device that verifies a digital signature on a password reset message. The password reset message has been generated by a password reset service for an authorized administrator associated with the secured device. The password reset mechanism allows the authorized administrator to make a request to the password reset service for a password reset, and receive the password reset message such that a password reset can be performed at the secured device. In this way, the secured device's password can be reset absent a connection to a command and control center or other service.

Claims (41)

1. A method of generating a password reset message for resetting a password for a secured device, the method comprising:

receiving a device identifier for the secured device and a new password;

signing a password image;

generating the password reset message using the device identifier and the new password, wherein the password reset message includes a digital signature and an encoded value derived using the new password, wherein the password image further comprises the device identifier and a replay protection value, wherein the replay protection value comprises a counter or random value or a combination of the counter and random value; and

providing the password reset message to an administrator for the secured device.

2. The method of claim 1 , further comprising encrypting at least a portion of the password reset message.

3. The method of claim 1 , wherein the received new password is encrypted or a hashed password image is generated, by the administrator.

4. The method of claim 1 , wherein the password reset message further comprises the counter to enable the secured device to compare the counter against a locally stored counter, wherein the password reset message is processed only if the counter value in the password reset message is larger than the locally maintained counter, and wherein if processed, the locally maintained counter is set to the larger value contained in the password reset message.

5. The method of claim 1 , wherein the password reset message further comprises a time-frame indicator to enable the secured device to process the password reset message only if a locally available time is within a time-frame provided in the password reset message.

6. A non-transitory computer readable medium comprising computer executable instructions for generating a password reset message for resetting a password for a secured device, the computer readable medium comprising instructions for:

receiving a device identifier for the secured device and a new password;

signing a password image;

generating the password reset message using the device identifier and the new password, wherein the password reset message includes a digital signature and an encoded value derived using the new password, wherein the password image further comprises the device identifier and a replay protection value, wherein the replay protection value comprises a counter or random value or a combination of the counter and random value; and

providing the password reset message to an administrator for the secured device.

7. The non-transitory computer readable medium of claim 6 , further comprising instructions for encrypting at least a portion of the password reset message.

8. The non-transitory computer readable medium of claim 6 , wherein the received new password is encrypted or a hashed password image is generated, by the administrator.

9. The non-transitory computer readable medium of claim 6 , wherein the password reset message further comprises the counter to enable the secured device to compare the counter against a locally stored counter, wherein the password reset message is processed only if the counter value in the password reset message is larger than the locally maintained counter, and wherein if processed, the locally maintained counter is set to the larger value contained in the password reset message.

10. The non-transitory computer readable medium of claim 6 , wherein the password reset message further comprises a time-frame indicator to enable the secured device to process the password reset message only if a locally available time is within a time-frame provided in the password reset message.

11. A system for generating a password reset message for resetting a password for a secured device, the system comprising a processor and memory, the memory storing computer executable instructions that when executed by the processor cause the system to:

receive a device identifier for the secured device and a new password;

sign a password image;

generate the password reset message using the device identifier and the new password, wherein the password reset message includes a digital signature and an encoded value derived using the new password, wherein the password image further comprises the device identifier and a replay protection value, wherein the replay protection value comprises a counter or random value or a combination of the counter and random value; and

provide the password reset message to an administrator for the secured device.

12. The system of claim 11 , further comprising instructions for encrypting at least a portion of the password reset message.

13. The system of claim 11 , wherein the received new password is encrypted or a hashed password image is generated, by the administrator.

14. The system of claim 11 , wherein the password reset message further comprises the counter to enable the secured device to compare the counter against a locally stored counter, wherein the password reset message is processed only if the counter value in the password reset message is larger than the locally maintained counter, and wherein if processed, the locally maintained counter is set to the larger value contained in the password reset message.

15. The system of claim 11 , wherein the password reset message further comprises a time-frame indicator to enable the secured device to process the password reset message only if a locally available time is within a time-frame provided in the password reset message.

16. A method of generating a password reset message for resetting a password for a secured device, the method comprising:

receiving a device identifier for the secured device and a new password;

generating the password reset message using the device identifier and the new password, wherein the password reset message further comprises a counter to enable the secured device to compare the counter against a locally stored counter, wherein the password reset message is processed only if the counter value in the password reset message is larger than the locally maintained counter, and wherein if processed, the locally maintained counter is set to the larger value contained in the password reset message; and

providing the password reset message to an administrator for the secured device.

17. The method of claim 16 , further comprising signing a password image and including a digital signature in the password reset message.

18. The method of claim 17 , wherein the password image comprises an encoded value derived using the new password.

19. The method of claim 18 , wherein the password image further comprises the device identifier, a replay protection value, and a random value.

20. The method of claim 16 , further comprising encrypting at least a portion of the password reset message.

21. The method of claim 16 , wherein the received new password is encrypted or a hashed password image is generated, by the administrator.

22. The method of claim 16 , wherein the password reset message further comprises a time-frame indicator to enable the secured device to process the password reset message only if a locally available time is within a time-frame provided in the password reset message.

23. A system for generating a password reset message for resetting a password for a secured device, the system comprising a processor and memory, the memory storing computer executable instructions that when executed by the processor cause the system to:

receive a device identifier for the secured device and a new password;

generate the password reset message using the device identifier and the new password, wherein the password reset message further comprises a counter to enable the secured device to compare the counter against a locally stored counter, wherein the password reset message is processed only if the counter value in the password reset message is larger than the locally maintained counter, and wherein if processed, the locally maintained counter is set to the larger value contained in the password reset message; and

provide the password reset message to an administrator for the secured device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2019
From: GALLANT, ROBERT PHILIP; LAMBERT, ROBERT JOHN
To: TRUSTPOINT INNOVATION TECHNOLOGIES, LTD.
Reel/Frame 048758/0853 →
MERGER Recorded Apr 1, 2019
From: TRUSTPOINT INNOVATION TECHNOLOGIES, LTD.
To: ETAS EMBEDDED SYSTEMS CANADA INC.
Reel/Frame 048759/0476 →
Continuity (4)
Division 15153081 · May 12, 2016
Provisional Application 62169208 · Jun 1, 2015
Provisional Application 62242867 · Oct 16, 2015
Related Publication 20190230057A1 · Jul 25, 2019