IP Library › Granted Patent US 8,095,792
Granted Patent B2
US 8,095,792 · App. 11/542,106 · Granted Jan 10, 2012

One way authentication

Assignee: Certicom Corp.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,095,792
App. No.
11/542,106
Granted
Jan 10, 2012
Kind
B2
Abstract

A cryptosystem prevents replay attacks within existing authentication protocols, susceptible to such attacks but containing a random component, without requiring modification to said protocols. The entity charged with authentication maintains a list of previously used bit patterns, extracted from a portion of the authentication message connected to the random component. If the bit pattern has been seen before, the message is rejected; if the bit pattern has not been seen before, the bit pattern is added to the stored list and the message is accepted.

Claims (29)

1. A method performed by one correspondent in a data communication system for confirming the originality and authenticity of messages generated by other correspondents in the data communication system, the method comprising:

a cryptographic processor at the one correspondent obtaining a signed message, said signed message comprising information and a signature signing said information, from another correspondent in the data communication system via a communication link, wherein said information was generated by said other correspondent, and wherein a first component of the signature comprises random data generated by said other correspondent and a second component of the signature comprises a calculated value generated from the information and the random data in accordance with a particular cryptographic protocol;

said cryptographic processor verifying said signature to authenticate said signed message, wherein said verifying utilizes said random data and said information;

said cryptographic processor extracting from said signature, a bit pattern representative of said random data and comparing said bit pattern to one or more previously extracted bit patterns stored in a memory of the correspondent, said previously extracted bit patterns previously received with signed messages received from said other correspondent; and,

said cryptographic processor confirming said originality and said authenticity of said signed message if said signature is verified and said extracted bit pattern is not matched to said previously extracted bit patterns.

2. The method according to claim 1 wherein said previously extracted bit patterns are maintained in a database at said one correspondent.

3. The method according claim 2 wherein when said extracted bit pattern is not matched to said previously extracted bit patterns, said extracted bit pattern is added to said database.

4. The method according to claim 2 wherein said database is organized to conduct a comparison with bit patterns previously obtained from said other correspondents.

5. The method according to claim 1 wherein said random data is derived from an ephemeral public key.

6. The method according to claim 5 wherein said signed message includes information to be exchanged between said one correspondent and said other correspondent.

7. The method according to claim 1 wherein said verifying said signature is performed according to a protocol for verifying an ECDSA signature.

8. The method according to claim 1 wherein said verifying said signature is performed according to protocol for verifying an RSA signature.

9. The method according to claim 1 wherein said random data is utilized to verify said signature prior to extracting said bit pattern.

10. The method according to claim 1 wherein said bit pattern is extracted prior to verifying said signature.

11. A computing device comprising a processor and a memory, said computing device being connectable to a data communication system, and being configured for confirming originality and authenticity of messages generated by other correspondents in said data communication system by operating said processor to perform acts of:

obtaining a signed message, said signed message comprising information and a signature signing said information, from another correspondent in the data communication system via a communication link, wherein said information was generated by said other correspondent, and wherein a first component of the signature comprises random data generated by said other correspondent and a second component of the signature comprises a calculated value generated from the information and the random data in accordance with a particular cryptographic protocol;

verifying said signature to authenticate said signed message, wherein said verifying utilizes said random data and said information;

extracting from said signature, a bit pattern representative of said random data;

comparing said bit pattern to one or more previously extracted bit patterns stored in a memory of the correspondent, said previously extracted bit patterns previously received with signed messages received from said other correspondent; and

confirming said originality and said authenticity of said signed message if said signature is verified and said extracted bit pattern is not matched to said previously extracted bit patterns.

12. The computing device according to claim 11 wherein said previously extracted bit patterns are maintained in a database at said one correspondent.

13. The computing device according claim 12 wherein when said extracted bit pattern is not matched to said previously extracted bit patterns, said extracted bit pattern is added to said data base.

14. The computing device according to claim 12 wherein said database is organized to conduct a comparison with bit patterns previously obtained from said other correspondents.

15. The computing device according to claim 11 wherein said random data is derived from an ephemeral public key.

16. The computing device according to claim 15 wherein said signed message includes information to be exchanged between said one correspondent and said other correspondent.

17. The computing device according to claim 11 wherein said verifying said signature is performed according to a protocol for verifying an ECDSA signature.

18. The computing device according to claim 11 wherein said verifying said signature is performed according to protocol for verifying an RSA signature.

19. The computing device according to claim 11 wherein said random data is utilized to verify said signature prior to extracting said bit pattern.

20. The computing device according to claim 11 wherein said bit pattern is extracted prior to verifying said signature.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2006
From: SHANNON-VANSTONE, SHERRY E.; VANSTONE, SCOTT A.
To: CERTICOM CORP.
Reel/Frame 018581/0376 →
Continuity (3)
Continuation PCTCA2005000180 · Feb 14, 2005
Provisional Application 60543914 · Feb 13, 2004
Related Publication 20070124590A1 · May 31, 2007