IP Library › Granted Patent US 11,290,271
Granted Patent B2
US 11,290,271 · App. 16/803,462 · Granted Mar 29, 2022

Secure storage enhancements for authentication systems

Inventors: Ali Hassani (Ann Arbor, MI); Ryan Edwin Hanson (Livonia, MI); Daniel M. King (Northville, MI); Hamid M. Golgiri (Livonia, MI); Cameron Smyth (Wyandotte, MI)
Assignee: Ford Global Technologies, LLC
H04L9/0894H04L9/0643H04L9/0866H04L9/0891H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,290,271
App. No.
16/803,462
Granted
Mar 29, 2022
Kind
B2
Abstract

A secured device has a secure storage area and is configured to communicate with an authentication manager of a key server. A salt and a key identifier of a key are received to the secured device from the key server. Information corresponding to the key identifier is embedded into the salt to create a combined identifier-salt value. The combined identifier-salt value is stored in the secure storage area. The combined identifier-salt value is utilized as additional input to a hash function along with a password. The key is identified using the information corresponding to the key identifier embedded into the salt.

Claims (57)

1. A method for efficient use of secure storage space, comprising:

receiving, to a secured device having a secure storage area, a salt value and a key identifier of a key from a key server;

embedding information corresponding to the key identifier into the salt value to create a combined identifier-salt value;

storing the combined identifier-salt value in the secure storage area;

utilizing the combined identifier-salt value as additional input to a hash function along with a password; and

identifying the key using the information corresponding to the key identifier embedded into the salt value.

2. The method of claim 1 , further comprising sending, to the key server, a slot identifier of a key slot of the secure storage area into which the combined identifier-salt value is placed.

3. The method of claim 2 , further comprising:

receiving, from the key server, a message to revoke the key, the message including the key identifier and the slot identifier;

confirming that the key identifier of the key slot indicated by the slot identifier matches the information corresponding to the key identifier embedded into the salt stored to the key slot;

if the key identifier matches, revoking the key; and

if the key identifier does not match, indicating an error condition.

4. The method of claim 2 , further comprising:

receiving, from the key server, a message to update the key, the message including the key identifier and the slot identifier;

confirming that the key identifier of the key slot indicated by the slot identifier matches the information corresponding to the key identifier embedded into the salt stored to the key slot;

if the key identifier matches, updating the key; and

if the key identifier does not match, indicating an error condition.

5. The method of claim 1 , further comprising reducing the key identifier into a reduced form factor key identifier by sampling a subset of bits of the key identifier to create a short key identifier, wherein the short key identifier is the information corresponding to the key identifier.

6. The method of claim 1 , wherein the information corresponding to the key identifier is the key identifier in its entirety.

7. The method of claim 1 , wherein the information corresponding to the key identifier is a lossless compressed version of the key identifier.

8. The method of claim 1 , wherein the information corresponding to the key identifier is embedded into the salt at a predefined location in the salt.

9. The method of claim 1 , further comprising:

responsive to being reset, sending a reset flag to the key server; and

receiving from the key server responsive to the send of the reset flag, redeployment of keys to the secured device.

10. The method of claim 1 , further comprising:

receiving a request for a password entry for a requested key identifier;

responsive to the request, sending a generated nonce and a requested salt corresponding to the requested key identifier retrieved from the secure storage area; and

generating a second none, to replace the generated nonce, for a next request for password entry.

11. A system for efficient use of secure storage space, comprising:

a secured device having a secure storage area, the secured device configured to communicate with an authentication manager of a key server, the secured device programmed to:

receive a salt and a key identifier of a key from the key server;

embed information corresponding to the key identifier into the salt to create a combined identifier-salt value;

store the combined identifier-salt value in the secure storage area;

utilize the combined identifier-salt value as additional input to a hash function along with a password; and

identify the key using the information corresponding to the key identifier embedded into the salt.

12. The system of claim 11 , wherein the secured device is further programmed to send, to the key server, a slot identifier of a key slot of the secure storage area into which the combined identifier-salt value is placed.

13. The system of claim 12 , wherein the secured device is further programmed to:

receive, from the key server, a message to revoke the key, the message including the key identifier and the slot identifier;

confirm that the key identifier of the key slot indicated by the slot identifier matches the information corresponding to the key identifier embedded into the salt stored to the key slot;

if the key identifier matches, revoke the key; and

if the key identifier does not match, indicate an error condition.

14. The system of claim 12 , wherein the secured device is further programmed to:

receive, from the key server, a message to update the key, the message including the key identifier and the slot identifier;

confirm that the key identifier of the key slot indicated by the slot identifier matches the information corresponding to the key identifier embedded into the salt stored to the key slot;

if the key identifier matches, update the key; and

if the key identifier does not match, indicate an error condition.

15. The system of claim 11 , wherein the secured device is further programmed to reduce the key identifier into a reduced form factor key identifier by sampling a subset of bits of the key identifier to create a short key identifier, wherein the short key identifier is the information corresponding to the key identifier.

16. The system of claim 11 , wherein the information corresponding to the key identifier is the key identifier in its entirety.

17. The system of claim 11 , wherein the information corresponding to the key identifier is a lossless compressed version of the key identifier.

18. The system of claim 11 , wherein the information corresponding to the key identifier is embedded into the salt at a predefined location in the salt.

19. The system of claim 11 , wherein the secured device is further programmed to:

responsive to being reset, send a reset flag to the key server; and

receive from the key server responsive to the send of the reset flag, redeployment of keys to the secured device.

20. The system of claim 11 , wherein the secured device is further programmed to:

receive a request for a password entry for a requested key identifier;

responsive to the request, send a generated nonce value and a requested salt corresponding to the requested key identifier retrieved from the secure storage area; and

generate a second nonce value, to replace the generated nonce value, for a next request for password entry.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2020
From: HASSANI, ALI; HANSON, RYAN EDWIN; KING, DANIEL M.; GOLGIRI, HAMID M.; SMYTH, CAMERON
To: FORD GLOBAL TECHNOLOGIES, LLC
Reel/Frame 051954/0976 →
Continuity (1)
Related Publication 20210273800A1 · Sep 2, 2021