IP Library Granted Patent US 12,047,372
Granted Patent B2
US 12,047,372 · App. 17/367,860 · Granted Jul 23, 2024

Resource access management and secure authorization systems and methods

Inventors: Peng Yang (Beijing, CN); Jiahua Gong (Beijing, CN); Chitai Kenny Huang (Beijing, CN)
Assignee: Intertrust Technologies Corporation
H04L63/0838H04L63/0807H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,047,372
App. No.
17/367,860
Granted
Jul 23, 2024
Kind
B2
Abstract

Systems and methods for secure user authentication are described. In certain embodiments, a client device such as a smartphone may be provisioned with a secure key and/or other secret information. The client device may be used to generate unique secure tokens and/or other credentials used in connection with an authentication process. A user may provide the generated tokens and/or other credentials to a service provider in connection with a request to access a managed service. The validity of the generated tokens and/or other credentials may be verified by an authentication service in communication with the service provider.

Claims (34)

1. A method performed by a client device for authenticating a right of a user of the client device to access a resource managed by a service provider system, the method comprising:

receiving a first secure key;

receiving, from an authentication service system, at least one of a shared secret value common to the authentication service system and the client device and information that may be used to generate the shared secret value;

securely storing the first secure key and at least one of the shared secret value and the information that may be used to generate the shared secret value in a protected processing environment of the client device;

receiving a request from the user to access the resource managed by the service provider system;

generating, in response to the request, a first secure token using, at least in part, the first secure key and the shared secret value;

sending, to the authentication service system, an authentication request requesting authentication for access to the resource managed by the service provider system, the authentication request comprising one or more authentication credentials, the one or more authentication credentials comprising the first secure token; and

receiving access to the resource managed by the service provider system based on successful authentication of the one or more authentication credentials by the authentication service system.

2. The method of claim 1 , wherein the first secure key is received from the authentication service system.

3. The method of claim 1 , wherein the method further comprises generating the shared secret value using the information that may be used to generate the shared secret value.

4. The method of claim 1 , wherein generating the first secure token comprises performing a computation using the first secure key and the shared secret value as inputs to the computation.

5. The method of claim 1 , wherein the shared secret value comprises at least one of a pseudorandom value and a random value.

6. The method of claim 1 , wherein the managed resource comprises an online service.

7. The method of claim 1 , wherein the managed resource comprises an inventory resource and the service provider system comprises an inventory control system.

8. The method of claim 1 , wherein the managed resource comprises a protected area and the service provider system comprises a physical access control system.

9. The method of claim 1 , wherein the one or more authentication credentials further comprise at least one of user identification information and a password.

10. The method of claim 4 , wherein the computation comprises at least one of a cryptographic hash computation, a digest computation, a time-based one-time password computation, and a HMAC-based one-time password computation.

11. A computer readable storage medium storing instructions that, when executed by a client device comprising a processor, cause the client device to engage in an authentication process of a right of a user of the client device to access a resource managed by a service provider system comprising:

receiving a first secure key;

receiving, from an authentication service system, at least one of a shared secret value common to the authentication service system and the client device and information that may be used to generate the shared secret value;

securely storing the first secure key and at least one of the shared secret value and the information that may be used to generate the shared secret value in a protected processing environment of the client device;

receiving a request from the user to access the resource managed by the service provider system;

generating, in response to the request, a first secure token using, at least in part, the first secure key and the shared secret value;

sending, to the authentication service system, an authentication request requesting authentication for access to the resource managed by the service provider system, the authentication request comprising one or more authentication credentials, the one or more authentication credentials comprising the first secure token; and

receiving access to the resource managed by the service provider system based on successful authentication of the one or more authentication credentials by the authentication service system.

12. The computer readable storage medium of claim 11 , wherein the first secure key is received from the authentication service system.

13. The computer readable storage medium of claim 11 , wherein the authentication process further comprises generating the shared secret value using the information that may be used to generate the shared secret value.

14. The computer readable storage medium of claim 11 , wherein generating the first secure token comprises performing a computation using the first secure key and the shared secret value as inputs to the computation.

15. The computer readable storage medium of claim 11 , wherein the shared secret value comprises at least one of a pseudorandom value and a random value.

16. The computer readable storage medium of claim 11 , wherein the managed resource comprises an online service.

17. The computer readable storage medium of claim 11 , wherein the managed resource comprises an inventory resource and the service provider system comprises an inventory control system.

18. The computer readable storage medium of claim 11 , wherein the managed resource comprises a protected area and the service provider system comprises a physical access control system.

19. The computer readable storage medium of claim 11 , wherein the authentication credentials further comprise at least one of user identification information and a password.

20. The computer readable storage medium of claim 14 , wherein the computation comprises at least one of a cryptographic hash computation, a digest computation, a time-based one-time password computation, and a HMAC-based one-time password computation.

Assignments (4)
SECURITY INTEREST Recorded Mar 25, 2026
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JAMSTER CAPITAL LLC
Reel/Frame 075228/0345 →
RELEASE OF SECURITY INTEREST Recorded Feb 14, 2023
From: ORIGIN FUTURE ENERGY PTY LTD.
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 062747/0742 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2021
From: YANG, PENG; GONG, JIAHUA; HUANG, CHITAI KENNY
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 056797/0657 →
SECURITY INTEREST Recorded Jul 8, 2021
From: INTERTRUST TECHNOLOGIES CORPORATION
To: ORIGIN FUTURE ENERGY PTY LTD.
Reel/Frame 056808/0317 →
Continuity (4)
Continuation 16006389 · Jun 12, 2018
Continuation 14286618 · May 23, 2014
Provisional Application 61826613 · May 23, 2013
Related Publication 20210344669A1 · Nov 4, 2021