IP Library › Granted Patent US 11,757,637
Granted Patent B2
US 11,757,637 · App. 17/204,634 · Granted Sep 12, 2023

Token node locking with signed fingerprints offloaded to clients

Inventors: Jason A. Pasion (San Diego, CA); John Okimoto (San Diego, CA); Xin Qiu (San Diego, CA); Alexander Medvinsky (San Diego, CA); Ting Yao (San Diego, CA); Jinsong Zheng (San Diego, CA); Oscar Jiang (West Covina, CA)
Assignee: ARRIS Enterprises LLC
H04L9/3213H04L9/3247H04L9/3263H04L9/3268H04L9/3297H04L63/166H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,757,637
App. No.
17/204,634
Filed
Mar 17, 2021
Granted
Sep 12, 2023
Kind
B2
Art Unit
2493
USPC
713/159
Abstract

A system and method for providing secure data to a client device having a token is disclosed. In one embodiment, the method comprises: (a) binding the token to the client device according to first token binding information comprising a first token identifier (ID), first client device fingerprint data, and a first timestamp, (b) receiving a request to provide secure data to the client device in a service, the request comprising the signed first token binding information and timestamp, (c) determining if the request to provide the secure data to the client device was received within an acceptable temporal range of the stored timestamp; and (d) providing the requested secure data according to the determination.

Claims (108)

1. A method of providing secure data to a client device having a token, comprising:

(a) binding the token to the client device according to first token binding information comprising a first token identifier (ID), first client device fingerprint data, and a first timestamp, comprising:

receiving the first token binding information from the client device in a token binding service;

determining if the first token ID does not match a previously stored token ID;

if the first token ID does not match a previously stored token ID, associatively storing the first token ID with the first client device fingerprint data, and the first timestamp;

signing the first token binding information; and

returning the signed first token binding information to the client device;

(b) receiving a request to provide secure data to the client device in a service, the request comprising the signed first token binding information and timestamp;

(c) determining if the request to provide the secure data to the client device was received within an acceptable temporal range of the stored timestamp; and

(d) providing the requested secure data according to the determination, comprising:

if the request to provide the secure data to the client device was received within an acceptable temporal range of the first timestamp, providing the requested secure data;

if the request to provide the secure data to the client device was not received within an acceptable temporal range of the first timestamp:

rejecting the request to provide the secure data;

receiving second token binding information from the client device in a token binding service, the second token binding information comprising a second token ID and second client device fingerprint data and a second timestamp; and

providing the requested secure data according to the received second token binding information.

2. The method of claim 1 , wherein providing the requested secure data according to the received second token binding information comprises:

determining if the second token ID does not match a previously stored token ID;

if the second token ID does not match a previously stored token ID:

associatively storing the second token ID with the second client device fingerprint data, and the second timestamp;

signing the second token binding information;

returning the signed second token binding information to the client device;

if the second token ID matches the first token ID:

determining if the first client device fingerprint data matches the second client device fingerprint data:

if the first fingerprint data matches the second client device fingerprint data:

updating the stored timestamp to a current timestamp;

modifying the first token binding information by substituting the second time stamp for the first timestamp in the first token binding information;

signing the modified first token binding information;

returning the signed first token binding information to the client device; and

repeating (b)-(d);

if the first client device fingerprint data does not match the second client device fingerprint data, determining if differences between the first client device fingerprint data and the second client device fingerprint data are acceptable;

if differences between the first client device fingerprint data and the second client device fingerprint data are acceptable:

associatively storing the second token ID with the second client device fingerprint data, and the current timestamp;

signing the modified first token binding information;

returning the signed first token binding information to the client device; and

repeating (b)-(d);

if the differences between the first client device fingerprint data and the second client device fingerprint data are not acceptable, performing at least one of:

returning an error to the client device; and

logging the error to the service.

3. The method of claim 2 , wherein:

the first fingerprint data comprises N first client device parameters;

the second client device fingerprint data comprises N second client device parameters;

the not acceptable differences between first client device fingerprint data and the second client device fingerprint data comprises at least one of

an excessive number of changes between the N first client device parameters and the N second client device parameters over a time period;

more than K changes between the N first client device parameters and the N second client device parameters; and

the N first client device parameters are associated with a different token ID than the second client device parameters.

4. The method of claim 1 , wherein the first token binding information and the second token binding information is received via a secure session in a token binding service.

5. The method of claim 1 , wherein the first token ID and the first token binding information is associatively stored in storage of a secure data service.

6. The method of claim 1 , further comprising:

receiving a request from an administrator of the client device to unbind the token from the client device and rebind the token to a second client device; and

unbinding the token from the first client device by disassociating the first fingerprint data from the stored token ID.

7. The method of claim 1 , further comprising:

generating a token report describing a history of token binding information of the token.

8. The method of claim 1 , wherein the token comprises a hardware token communicatively coupleable to the client device.

9. An apparatus for providing secure data to a client device having a token, comprising:

a processor;

a memory, communicatively coupled to the processor, the memory storing processor instructions comprising processor instructions for:

(a) binding the token to the client device according to first token binding information comprising a first token identifier (ID), first client device fingerprint data, and a first timestamp, comprising:

receiving the first token binding information from the client device in a token binding service;

determining if the first token ID does not match a previously stored token ID;

if the first token ID does not match a previously stored token ID, associatively storing the first token ID with the first client device fingerprint data, and the first timestamp;

signing the first token binding information; and

returning the signed first token binding information to the client device;

(b) receiving a request to provide secure data to the client device in a service, the request comprising the signed first token binding information and timestamp;

(c) determining if the request to provide the secure data to the client device was received within an acceptable temporal range of the stored timestamp; and

(d) providing the requested secure data according to the determination, comprising:

if the request to provide the secure data to the client device was received within an acceptable temporal range of the first timestamp, providing the requested secure data;

if the request to provide the secure data to the client device was not received within an acceptable temporal range of the first timestamp:

rejecting the request to provide the secure data;

receiving second token binding information from the client device in a token binding service, the second token binding information comprising a second token ID and second client device fingerprint data and a second timestamp; and

providing the requested secure data according to the received second token binding information.

10. The apparatus of claim 9 , wherein the processor instructions for providing the requested secure data according to the received second token binding information comprise processor instructions for:

determining if the second token ID does not match a previously stored token ID;

if the second token ID does not match a previously stored token ID:

associatively storing the second token ID with the second client device fingerprint data, and the second timestamp;

signing the second token binding information;

returning the signed second token binding information to the client device;

if the second token ID matches the first token ID:

determining if the first client device fingerprint data matches the second client device fingerprint data:

if the first fingerprint data matches the second client device fingerprint data:

updating the stored timestamp to a current timestamp;

modifying the first token binding information by substituting the second time stamp for the first timestamp in the first token binding information;

signing the modified first token binding information;

returning the signed first token binding information to the client device; and

repeating (b)-(d);

if the first client device fingerprint data does not match the second client device fingerprint data, determining if differences between the first client device fingerprint data and the second client device fingerprint data are acceptable;

if differences between the first client device fingerprint data and the second client device fingerprint data are acceptable:

associatively storing the second token ID with the second client device fingerprint data, and the current timestamp;

signing the modified first token binding information;

returning the signed first token binding information to the client device; and

repeating (b)-(d);

if the differences between the first client device fingerprint data and the second client device fingerprint data are not acceptable, performing at least one of:

returning an error to the client device; and

logging the error to the service.

11. The apparatus of claim 10 , wherein:

the first fingerprint data comprises N first client device parameters;

the second client device fingerprint data comprises N second client device parameters;

the not acceptable differences between first client device fingerprint data and the second client device fingerprint data comprises at least one of

an excessive number of changes between the N first client device parameters and the N second client device parameters over a time period;

more than K changes between the N first client device parameters and the N second client device parameters; and

the N first client device parameters are associated with a different token ID than the second client device parameters.

12. The apparatus of claim 9 , wherein the first token binding information and the second token binding information is received via a secure session in a token binding service.

13. The apparatus of claim 9 , wherein the first token ID and the first token binding information is associatively stored in storage of a secure data service.

14. The apparatus of claim 9 , wherein the processor instructions further comprise processor instructions for:

receiving a request from an administrator of the client device to unbind the token from the client device and rebind the token to a second client device; and

unbinding the token from the first client device by disassociating the first fingerprint data from the stored token ID.

15. The apparatus of claim 9 , wherein the processor instructions further comprise processor instructions for:

generating a token report describing a history of token binding information of the token.

16. The apparatus of claim 9 , wherein the token comprises a hardware token communicatively coupleable to the client device.

Assignments (8)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058843/0712 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA); COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 074591/0389 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058875/0449 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069743/0057 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
TERM LOAN SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058875/0449 →
ABL SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058843/0712 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2021
From: PASION, JASON A.; OKIMOTO, JOHN; QIU, XIN; MEDVINSKY, ALEXANDER; YAO, TING; ZHENG, JINSONG; JIANG, OSCAR
To: ARRIS ENTERPRISES LLC
Reel/Frame 055628/0657 →
Continuity (2)
Provisional Application 62990448 · Mar 17, 2020
Related Publication 20210297254A1 · Sep 23, 2021