IP Library › Granted Patent US 12,580,738
Granted Patent B1
US 12,580,738 · App. 18/152,660 · Granted Mar 17, 2026

System and method for multi-factor key derivation

Inventor: Vivek Chinar Nair (Santa Clara, CA)
Assignee: Multifactor, Inc.
H04L9/0822H04L63/083H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,738
App. No.
18/152,660
Granted
Mar 17, 2026
Kind
B1
Abstract

A system and method for multi-factor key derivation includes: a user having a plurality of authentication factors; whereby the plurality of authentication factors are converted into key material using intermediate factor-specific functions, and whereby said key material is then converted into a key using a key derivation function.

Claims (24)

1 . A method for multi-factor key derivation comprising:

receiving, by a hardware processor, a plurality of authentication factors, wherein the plurality of authentication factors includes at least two different types of authentication factors;

routing, by the hardware processor, each of the plurality of authentication factors to at least one of a plurality of intermediate factor-specific functions;

converting, by the hardware processor, the plurality of authentication factors into key material using the plurality of intermediate factor-specific functions; and

deriving, by the hardware processor, a cryptographic key from said key material using a key derivation function.

2 . The method for multi-factor key derivation of claim 1 , further comprising an authentication service with the capability of confirming the at least one of the plurality of authentication factors, wherein a derived cryptographic key is used to authenticate the user with the authentication service.

3 . The method for multi-factor key derivation of claim 1 , wherein a salt or a pad is used as a component of the key derivation function.

4 . The method for multi-factor key derivation of claim 1 , wherein the derived key is further used to decrypt an additional key.

5 . The method for multi-factor key of claim 1 , wherein the plurality of authentication factors are selected from a set of authentication factors used to initially establish the cryptographic key, wherein the plurality of authentication factors required to derive the cryptographic key is less than a number of authentication factors in the set of authentication factors.

6 . The method for multi-factor key derivation of claim 1 , wherein at least one other key is used in deriving the cryptographic key.

7 . The method for multi-factor key derivation of claim 1 , wherein a derived key is later modified to change at least one of the plurality of authentication factors used to derive the key.

8 . The method for multi-factor key derivation of claim 1 , wherein a trusted computing system provides at least a portion of the key material used to derive the key.

9 . The method for multi-factor key derivation of claim 1 , wherein multi-party computation or functional encryption is used to provide at least a portion of the key material used to derive the key.

10 . The method for multi-factor key derivation of claim 1 , wherein at least one of the plurality of authentication factors is a fixed string of characters.

11 . The method for multi-factor key derivation of claim 1 , wherein at least one of the plurality of authentication factors is an HMAC-based one-time password (HOTP) code or a time-based one-time password (TOTP) code.

12 . The method for multi-factor key derivation of claim 1 , wherein a hardware token constitutes at least one of the plurality of authentication factors.

13 . The method for multi-factor key derivation of claim 1 , wherein a single sign-on (SSO) process constitutes at least one of the plurality of authentication factors.

14 . The method for multi-factor key derivation of claim 1 , wherein a code sent via out-of-band authentication constitutes at least one of the plurality of authentication factors.

15 . The method for multi-factor key derivation of claim 1 , wherein a mobile application constitutes at least one of the plurality of authentication factors.

16 . The method for multi-factor key derivation of claim 1 , wherein at least one of the plurality of authentication factors is behavioral authentication or biometric authentication.

17 . The method for multi-factor key derivation of claim 1 , wherein a location factor constitutes at least one of the plurality of authentication factors.

18 . The method for multi-factor key derivation of claim 1 , wherein a device identifier or key material stored on a user device constitutes at least one of the plurality of authentication factors.

19 . The method for multi-factor key derivation of claim 1 , wherein an obfuscated program is used to provide at least a portion of the key material.

20 . The method for multi-factor key derivation of claim 1 , further comprising a database configured to store data objects encrypted with one or more multi-factor derived keys.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2025
From: NAIR, VIVEK
To: MULTIFACTOR, INC.
Reel/Frame 072298/0781 →
Continuity (1)
Provisional Application 63266610 · Jan 10, 2022
References Cited (15)
US 6996718B1 · Henry · 2006 [cited by examiner]
US 8656471B1 · Allen · 2014 [cited by examiner]
US 10615975B2 · Jeon · 2020 [cited by examiner]
US 20050047598A1 · Kruegel · 2005 [cited by examiner]
US 20050069138A1 · de Jong · 2005 [cited by examiner]
US 20100100724A1 · Kaliski, Jr. · 2010 [cited by examiner]
US 20100115260A1 · Venkatesan · 2010 [cited by examiner]
US 20130132720A1 · Parsons · 2013 [cited by examiner]
US 20140164768A1 · Kruglick · 2014 [cited by examiner]
US 20150263856A1 · Leboeuf · 2015 [cited by examiner]
US 20160028737A1 · Srinivasan · 2016 [cited by examiner]
US 20190268332A1 · Wang · 2019 [cited by examiner]
US 20200076589A1 · Jeon · 2020 [cited by examiner]
US 20200328896A1 · Pellizzer · 2020 [cited by examiner]
US 20240073693A1 · Vachnish · 2024 [cited by examiner]
Cited By (1)
US 12,719,886