IP Library Granted Patent US 9,154,302
Granted Patent B2
US 9,154,302 · App. 13/749,408 · Granted Oct 6, 2015

System and method for secure two-factor authenticated ID-based key exchange and remote login using an insecure token and simple second-factor such as a PIN number

Inventors: Brian P. Spector (Seattle, WA); Michael Scott (Dublin, IE)
Assignee: CERTIVOX LTD.
H04L9/32H04L9/0844H04L9/3073H04L9/321H04L9/3226H04L9/3234G06F21/445G06F2207/7204
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,154,302
App. No.
13/749,408
Granted
Oct 6, 2015
Kind
B2
Abstract

A system and method of authenticated ID-based key exchange and remote login with insecure token and PIN number can provide an authenticated key agreement protocol based on an elliptic curve bilinear type-3 pairing. A server acts as an Authentication Service to Clients and a Trusted Authority (TA) issues identity based secret numbers to Clients and Authentication Services. Included in the system and method is the capability for the Client to split their secret number into two parts, a Client selected PIN number, and the larger number, the Token.

Claims (29)

1. A method comprising:

finding, at a trusted authority, a non-supersingular curve with an even k for which no distortion map exists, the curve having a base field F p and an extension field F p2 and a curve order c.q;

generating a master secret s;

choosing hash function H 1 : {0,1}*→E(F p );

publishing public parameters;

identifying and authenticating an authentication service to the trusted authority;

taking, at the trusted authority, an identity IDs of the authentication service as input and mapping the identity IDs to a point, S, on the curve;

using, over the extension field F p2 , a second hash function of H 2 : {0,1}*→E(F p2 ) such that S=H 2 (ID s ) so s, a secret number, is a point on the curve E(F p2 );

issuing back to the authentication service over a secure network connection the secret number s, parameters of the curve and the H 2 hash function along with a location of the public parameters;

authenticating, at a client, an identity to the trusted authority;

taking, at the trusted authority, a client's identity ID a as input;

hashing, at the trusted authority, the identity ID a and mapping to a point A of large prime order on the curve;

receiving, at the client, from the trusted authority over the secure network connection A and s, where A=c.H 1 (ID a ) is a point of order q over the base field of the curve E(F p );

taking, at the client, as input a PIN number, α, and calculating αA;

producing, at the client, a number (s−α)A;

storing, at the client, both (s−α)A and A in a browser storage of the client;

using an authentication program at the client to prompt a user of the client for their PIN and their identifier;

using, at the client, the authentication program to hash ID a ;

using, at the client, the hash function H 1 , and to look up a key/value pair to obtain (s−α)A and A;

sending identities ID a and ID s , between the client and authentication service;

generating values of x<q at the client and y<q at the authentication service;

calculating, at the client, S where S=H 2 (ID s ) and A where A=H 1 (ID a ) to achieve P a =xA while, at the authentication service, calculating A where A=H 1 (ID a ) and S where S=H2(IDs) to achieve Ps=yS;

exchanging P a and P s between the client and authentication service;

calculating r a= H q (P a |P s ) and r s =H q (P s |P a ) at the client and the authentication service;

calculating, at the client, k=e((x+r a )((s−α)A+αA),r s S+P s ) to obtain K=H 3 (k) and M=H 3 (ID a , ID s , K);

at the authentication service, calculating k=e(r a A+P a (y+r s )sS) to obtain K=H 3 (k) and N=H 3 (ID a , ID s , K);

sending, at the client, M over the secure connection to the authentication service;

sending N to the client in response to a comparison, N=M, at the authentication service indicating a match; and

determining, at the client, that the client and authentication service have successfully mutually authenticated each other and have a mutually agreed upon session key N in response to a comparison of N to M at the client indicating a match.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2026
From: OMLIS LIMITED
To: MIRACL DIGITAL SERVICES LIMITED
Reel/Frame 073951/0712 →
CORRECTIVE ASSIGNMENT TO CORRECT THE LISTING OF PROPERTIES TO REMOVE PATENT NO. 7860247 FROM THE LISTING PREVIOUSLY RECORDED ON REEL 049711 FRAME 0872. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 15, 2019
From: MIRACL UK LIMITED; MIRACL LIMITED
To: OMLIS LIMITED
Reel/Frame 052657/0276 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2019
From: MIRACL UK LIMITED; MIRACL LIMITED
To: OMLIS LIMITED
Reel/Frame 049711/0872 →
CHANGE OF NAME Recorded Jan 25, 2016
From: CERTIVOX LIMITED
To: MIRACL LIMITED
Reel/Frame 037581/0221 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2013
From: SPECTOR, BRIAN P.; SCOTT, MICHAEL
To: CERTIVOX LTD.
Reel/Frame 030150/0923 →
Continuity (2)
Provisional Application 61590699 · Jan 25, 2012
Related Publication 20130191638A1 · Jul 25, 2013