IP Library Granted Patent US 8,972,719
Granted Patent B2
US 8,972,719 · App. 13/312,254 · Granted Mar 3, 2015

Passcode restoration

Inventors: Eugene Shablygin (Bedford, NH); Vasily Zakharov (Moscow, RU); Oleg Bolotov (Moscow, RU); Eric Scace (Cambridge, MA)
Assignee: WWPass Corporation
H04L29/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,972,719
App. No.
13/312,254
Granted
Mar 3, 2015
Kind
B2
Abstract

A system method that includes providing a passcode to a user based on presentation of both a recovery key and an active token is described herein.

Claims (31)

1. A computer-implemented method of providing a passcode for a set of cryptographic tokens, the method comprising:

authenticating, by an authentication service executing on a networked server, a hardware recovery token in the set of cryptographic tokens, the hardware recovery token identifiable by a token identifier, the hardware recovery token having an enabled state associated with the token identifier of the hardware recovery token, the hardware recovery token being enabled to perform recovery functions and unable to perform transactions other than those associated with recovery functions;

authenticating, by the authentication service, an active hardware token in the set of cryptographic tokens, the active hardware token identifiable by a token identifier, the active hardware token having an enabled state associated with the token identifier of the active hardware token, the active hardware token being enabled to perform transactions, wherein authenticating the active hardware token includes verifying that the token has an enabled state; and

providing a passcode to a user based on presentation of both the hardware recovery token and the active hardware token;

wherein each token in the set of cryptographic tokens has the same passcode.

2. The method of claim 1 , wherein authenticating the hardware recovery token comprises determining the enabled state of the hardware recovery token based on information stored in an authentication system storage in an entry associated with the token identifier of the hardware recovery token; and

authenticating the active hardware token comprises determining the enabled state of the active hardware token based on information stored in the authentication system storage in an entry associated with the token identifier of the active hardware token.

3. The method of claim 1 , wherein providing the passcode comprises providing a new passcode to the user.

4. The method of claim 1 , wherein providing the passcode comprises receiving a replacement passcode from the user.

5. The method of claim 1 , wherein a check value of the passcode is stored by the authentication service in a secure storage system in storage entities corresponding to all active and recovery tokens of the same set.

6. The method of claim 1 , wherein the active hardware token is enabled to perform transactions and the hardware recovery token is limited to performing only transactions associated with token and passcode management.

7. A computer program product tangibly embodied in a computer readable medium comprising instruction that when executed by a processing device cause the processing device to provide a passcode for a set of cryptographic tokens, comprising:

authenticating, by an authentication service, a hardware recovery token in the set of cryptographic tokens, the hardware recovery token identifiable by a token identifier, the hardware recovery token having an enabled state associated with the token identifier of the hardware recovery token, the hardware recovery token being enabled to perform recovery functions and unable to perform transactions other than those associated with recovery functions;

authenticating, by the authentication service, an active hardware token in the set of cryptographic tokens, the active hardware token identifiable by a token identifier, the active hardware token having an enabled state associated with the token identifier of the active hardware token, the active hardware token being enabled to perform transactions, wherein authenticating the active hardware token includes verifying that the token has an enabled state; and

providing a passcode to a user based on presentation of both the hardware recovery token and the active hardware token;

wherein each token in the set of cryptographic tokens has the same passcode.

8. The computer program product of claim 7 , wherein the instructions to authenticate the hardware recovery token comprise instructions to determine the enabled state of the hardware recovery token based on information stored in an authentication system storage in an entry associated with the token identifier of the hardware recovery token; and

the instructions to authenticate the active hardware token comprise instructions to determine the enabled state of the active hardware token based on information stored in the authentication system storage in an entry associated with the token identifier of the active hardware token.

9. The computer program product of claim 7 , wherein the instructions to provide the passcode comprise instructions to provide a new passcode to the user.

10. The computer program product of claim 7 , wherein the instructions to provide the passcode comprise instructions to receive a replacement passcode from the user.

11. A system for providing a passcode for a set of cryptographic tokens, the system comprising:

a processing device; and

a memory comprising instructions that when executed by the processing device cause the processing device to:

authenticate, by an authentication service, a hardware recovery token in the set of cryptographic tokens, the hardware recovery token identifiable by a token identifier, the hardware recovery token having an enabled state associated with the token identifier of the hardware recovery token, the hardware recovery token being enabled to perform recovery functions and unable to perform transactions other than those associated with recovery functions;

authenticate, by the authentication service, an active hardware token in the set of cryptographic tokens, the active hardware token identifiable by a token identifier, the active hardware token having an enabled state associated with the token identifier of the active hardware token, the active hardware token being enabled to perform transactions, wherein authenticating the active hardware token includes verifying that the token has an enabled state; and

provide a passcode to a user based on presentation of both the hardware recovery token and the active hardware token;

wherein each token in the set of cryptographic tokens has the same passcode.

12. The system of claim 11 , wherein the instructions to authenticate the hardware recovery token comprise instructions to determine the enabled state of the hardware recovery token based on information stored in an authentication system storage in an entry associated with the token identifier of the hardware recovery token; and

the instructions to authenticate the active hardware token comprises determining the enabled state of the active hardware token based on information stored in the authentication system storage in an entry associated with the token identifier of the active hardware token.

13. The system of claim 11 , wherein the instructions to provide the passcode comprise instructions to provide a new passcode to the user.

14. The system of claim 11 , wherein the instructions to provide the passcode comprise instructions to receive a replacement passcode from the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2012
From: SHABLYGIN, EUGENE; ZAKHAROV, VASILY; BOLOTOV, OLEG; SCACE, ERIC
To: WWPASS CORPORATION
Reel/Frame 028120/0595 →
Continuity (1)
Related Publication 20130145148A1 · Jun 6, 2013