IP Library Granted Patent US 11,750,391
Granted Patent B2
US 11,750,391 · App. 17/128,121 · Granted Sep 5, 2023

System and method for performing a secure online and offline login process

Inventors: Shimrit Tzur-David (Mevaseret Zion, IL); Chen Tetelman (Tel Aviv, IL)
Assignee: SECRET DOUBLE OCTOPUS LTD.
H04L9/3231H04L9/0894H04L9/3073H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,750,391
App. No.
17/128,121
Granted
Sep 5, 2023
Kind
B2
Abstract

A computer-based system and method for performing an offline login to a local device, including: generating a pair of an auxiliary (AUX) public key and an AUX private key; receiving a password at the local device; reconstructing a symmetric key from a first value stored on the local device and a second value stored on an authenticator; encrypting the password with the AUX public key to obtain a locally encrypted password; encrypting the AUX private key with the symmetric key to obtain an encrypted AUX private key; and deleting the symmetric key, and when performing the offline login: reconstructing the symmetric key; decrypting the encrypted AUX private key with the symmetric key to obtain the AUX private key; decrypting the locally encrypted password with the AUX private key to obtain the password; and using the password to perform the offline login.

Claims (88)

1. A method for performing an offline login of a user to a local device, the method comprising:

generating a pair of an auxiliary (AUX) public key and an AUX private key;

receiving, from an authentication service, a password at the local device, wherein the password is associated with the user, wherein receiving the password comprises:

receiving an encrypted password from the authentication service by the local device; and

decrypting the encrypted password with a local private key to obtain the password;

reconstructing a symmetric key;

encrypting the password with the AUX public key to obtain a locally encrypted password, and storing the locally encrypted password on the local device;

encrypting the AUX private key with the symmetric key to obtain an encrypted AUX private key, and storing the encrypted AUX private key on the local device;

deleting the symmetric key; and

performing the offline login of the user when the authentication service is unavailable by:

verifying an identity of the user by an authenticator;

reconstructing the symmetric key from a first value stored on the local device and a second value stored on the authenticator;

decrypting the encrypted AUX private key with the symmetric key to obtain the AUX private key;

decrypting the locally encrypted password with the AUX private key to obtain the password; and

using the password to perform the offline login.

2. The method of claim 1 , comprising, when performing the offline login:

verifying an identity of the user by the authenticator prior to reconstructing the symmetric key.

3. The method of claim 2 , wherein verifying the identity of the user by the authenticator comprises performing biometric authentication.

4. The method of claim 2 , wherein verifying the identity of the user by the authenticator comprises obtaining a PIN code from the user and comparing the obtained PIN code with a stored PIN code.

5. The method of claim 1 , comprising, when performing the offline login:

sending a challenge to the authenticator;

verifying an identity of the user by the authenticator;

signing the challenge by the authenticator;

sending the signed challenge to the local device; and

verifying the signed challenge by the local device.

6. The method of claim 1 , wherein reconstructing the symmetric key comprises:

sending the first value from the local device to the authenticator;

reconstructing the symmetric key by the authenticator; and

sending the symmetric key to the local device.

7. The method of claim 1 , wherein the symmetric key is reconstructed by hashing a concatenation of the first value with the second value.

8. The method of claim 1 , comprising performing online login by:

sending a login request and a username from the local device to the authentication service;

obtaining a challenge from the authentication service;

sending the challenge and the first value to the authenticator;

verifying an identity of the user by the authenticator;

signing the challenge by the authenticator to obtain a signed challenge;

reconstructing the symmetric key by the authenticator using the first value and the second value;

sending from the authenticator to the local device, the signed challenge and the symmetric key;

sending by the local device the signed challenge to the authentication service;

verifying the signed challenge by the authentication service; and

sending the encrypted password from the authentication service to the local device.

9. A system for performing an offline login, the system comprising:

a memory; and

a processor configured to:

generate a pair of an auxiliary (AUX) public key and an AUX private key;

receive a password, from an authentication service by:

receiving an encrypted password from the authentication service; and

decrypting the encrypted password with a local private key to obtain the password;

obtain a symmetric key;

encrypt the password with the AUX public key to obtain a locally encrypted password, and storing the locally encrypted password on the local device;

encrypt the AUX private key with the symmetric key to obtain an encrypted AUX private key, and storing the encrypted AUX private key on the local device; and

delete the symmetric key; and

perform the offline login of the user when the authentication service is unavailable by:

obtaining the symmetric key;

decrypting the encrypted AUX private key with the symmetric key to obtain the AUX private key;

decrypting the locally encrypted password with the AUX private key to obtain the password; and

using the password to perform the offline login.

10. The system of claim 9 , comprising an authenticator, wherein the authenticator is configured to:

obtain a first value from the processor;

verify an identity of the user;

reconstruct the symmetric key from the first value and a second value owned by the authenticator; and

send the symmetric key to the processor.

11. The system of claim 10 , wherein the authenticator is configured to reconstruct the symmetric key by hashing a concatenation of the first value with the second value.

12. The system of claim 10 , wherein the authenticator is configured to verify the identity of the user by performing biometric authentication.

13. The system of claim 10 , wherein the authenticator is configured to verify the identity of the user by obtaining a PIN code from the user and comparing the obtained PIN code with a stored PIN code.

14. The system of claim 9 , comprising an authenticator,

wherein the processor is configured to, when performing the offline login:

send a challenge to the authenticator;

wherein the authenticator is configured to:

verify an identity of the user;

sign the challenge;

send the signed challenge to the processor; and

wherein the processor is configured to:

verify the signed challenge.

15. The system of claim 9 , comprising:

an authenticator;

wherein the processor is configured to perform an online login by:

sending a login request and a username to an authentication service;

obtain a challenge from the authentication service;

send the challenge and the first value to the authenticator;

wherein the authenticator is configured to:

verify an identity of the user;

sign the challenge to obtain a signed challenge;

reconstruct the symmetric key using the first value and the second value;

send the signed challenge and the symmetric key to the processor;

wherein the processor is configured to:

send the signed challenge to the authentication service; and

obtain the encrypted password from the authentication service.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded May 19, 2024
From: BANK LEUMI LE-ISRAEL B.M.
To: SECRET DOUBLE OCTOPUS LTD.
Reel/Frame 067457/0897 →
SECURITY INTEREST Recorded Dec 6, 2023
From: SECRET DOUBLE OCTOPUS LTD
To: BANK LEUMI LE-ISRAEL B.M.
Reel/Frame 065774/0392 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2021
From: TZUR-DAVID, SHIMRIT; TETELMAN, CHEN
To: SECRET DOUBLE OCTOPUS LTD
Reel/Frame 055266/0043 →
Continuity (1)
Related Publication 20220209955A1 · Jun 30, 2022
Cited By (1)
US 12,739,129