IP Library Granted Patent US 11,750,389
Granted Patent B2
US 11,750,389 · App. 17/485,080 · Granted Sep 5, 2023

System, method, and computer program product for performing hardware backed symmetric operations for password based authentication

Inventors: Michael Matovsky (Vaughan, CA); Ravi Singh (Toronto, CA); Alexander Sherkin (Vaughan, CA)
Assignee: DIGITAL 14 LLC
H04L9/3226H04L9/0819H04L9/3242H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,750,389
App. No.
17/485,080
Granted
Sep 5, 2023
Kind
B2
Abstract

A system, method, and computer program product are provided for implementing hardware backed symmetric operations for password based authentication. In operation, a system receives a request to access software utilizing password-based authentication. Further, the system receives a password for the password-based authentication. The system computes a hash utilizing the password and a hardware-based authenticator associated with hardware of the system utilizing hardware backed symmetric encryption. Moreover, the system verifies that the hash computed utilizing the password and the hardware-based authenticator is correct for accessing the software.

Claims (34)

1. A method, comprising:

receiving, by a system, a request to access software utilizing password-based authentication;

receiving, by the system, a password for the password-based authentication;

computing, by the system, a hash utilizing the password and a hardware-based authenticator associated with hardware of the system, wherein the hash is computed utilizing a combination of a single implementation of a hardware-based symmetric encryption algorithm provided by a hardware-backed cryptographic module of the system and a single implementation of a software-based one-way pseudorandom function; and

verifying, by the system, that the hash computed utilizing the password and the hardware-based authenticator is correct for accessing the software.

2. The method of claim 1 , wherein the hardware-based authenticator is generated after the password is received.

3. The method of claim 2 , wherein the password is received from a user via a user interface.

4. The method of claim 1 , wherein the hash is computed by utilizing the single implementation of the software-based one-way pseudorandom function after the single implementation of the hardware-based symmetric encryption algorithm.

5. The method of claim 4 , wherein the single implementation of the hardware-based symmetric encryption algorithm is utilized to generate a symmetric encryption of the hardware-based authenticator.

6. The method of claim 5 , wherein the single implementation of the software-based one-way pseudorandom function utilizes the password and the symmetric encryption of the hardware-based authenticator.

7. The method of claim 1 , wherein the hash is computed by utilizing the single implementation of the software-based one-way pseudorandom function before the single implementation of the hardware-based symmetric encryption algorithm.

8. The method of claim 7 , wherein the single implementation of the software-based one-way pseudorandom function generates a hash of the password.

9. The method of claim 8 , wherein the single implementation of the hardware-based symmetric encryption algorithm generates a symmetric encryption of the hardware-based authenticator.

10. The method of claim 1 , wherein the software-based one-way pseudorandom function is associated with HMAC (keyed-hash message authentication code).

11. A non-transitory computer readable medium storing computer code executable by a processor of a system to perform a method comprising:

receiving a request to access software utilizing password-based authentication;

receiving a password for the password-based authentication;

computing a hash utilizing the password and a hardware-based authenticator associated with hardware of the system, wherein the hash is computed utilizing a combination of a single implementation of a hardware-based symmetric encryption algorithm provided by a hardware-backed cryptographic module of the system and a single implementation of a software-based one-way pseudorandom function; and

verifying that the hash computed utilizing the password and the hardware-based authenticator is correct for accessing the software.

12. The non-transitory computer readable medium of claim 11 , wherein the hardware-based authenticator is generated after the password is received.

13. The non-transitory computer readable medium of claim 12 , wherein the password is received from a user via a user interface.

14. The non-transitory computer readable medium of claim 11 , wherein the hash is computed by utilizing the single implementation of the software-based one-way pseudorandom function after the single implementation of the hardware-based symmetric encryption algorithm.

15. The non-transitory computer readable medium of claim 14 , wherein the single implementation of the hardware-based symmetric encryption algorithm is utilized to generate a symmetric encryption of the hardware-based authenticator.

16. The non-transitory computer readable medium of claim 15 , wherein the single implementation of the software-based one-way pseudorandom function utilizes the password and the symmetric encryption of the hardware-based authenticator.

17. The non-transitory computer readable medium of claim 11 , wherein the hash is computed by utilizing the single implementation of the software-based one-way pseudorandom function before the single implementation of the hardware-based symmetric encryption algorithm.

18. The non-transitory computer readable medium of claim 17 , wherein the single implementation of the software-based one-way pseudorandom function generates a hash of the password.

19. The non-transitory computer readable medium of claim 18 , wherein the single implementation of the hardware-based symmetric encryption algorithm generates a symmetric encryption of the hardware-based authenticator.

20. A system, comprising:

a memory storing instructions, and

a computer processor executing the instructions for:

receiving a request to access software utilizing password-based authentication;

receiving a password for the password-based authentication;

computing a hash utilizing the password and a hardware-based authenticator associated with hardware of the system, wherein the hash is computed utilizing a combination of a single implementation of a hardware-based symmetric encryption algorithm provided by a hardware-backed cryptographic module of the system and a single implementation of a software-based one-way pseudorandom function; and

verifying that the hash computed utilizing the password and the hardware-based authenticator is correct for accessing the software.

Assignments (3)
CHANGE OF NAME Recorded Nov 7, 2025
From: DIGITAL 14 - L.L.C.
To: KATIM L.L.C.
Reel/Frame 072834/0247 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2021
From: DARK MATTER L.L.C.
To: DIGITAL 14 LLC
Reel/Frame 057674/0880 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2021
From: MATOVSKY, MICHAEL; SINGH, RAVI; SHERKIN, ALEXANDER
To: DARK MATTER L.L.C.
Reel/Frame 057688/0516 →
Continuity (2)
Continuation 16352498 · Mar 13, 2019
Related Publication 20220014375A1 · Jan 13, 2022