IP Library › Granted Patent US 12,061,684
Granted Patent B2
US 12,061,684 · App. 17/548,905 · Granted Aug 13, 2024

Systems and methods for controlling access to a computing device

Inventors: Michael Hughes (Ottawa, CA); Francisco Afonso Cavedon (Mississauga, CA); Mir Mustafa Ali (Markham, CA); Tarika Chawla (Milton, CA); Alexandre Kaliazine (Toronto, CA)
Assignee: Shopify Inc.
G06F21/40G06F21/602H04L9/0656H04L9/3226G06F21/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,061,684
App. No.
17/548,905
Granted
Aug 13, 2024
Kind
B2
Abstract

A computer-implemented method is disclosed. The method includes: receiving, via a computing device in a locked state, input of a first PIN; determining that the first PIN is associated with a first cryptographic key that is stored in a memory; responsive to determining that the first PIN is associated with the first cryptographic key, retrieving, from the memory, an encrypted form of a first credential that is associated with the first cryptographic key; recovering the first credential from the encrypted form using the first cryptographic key; and causing the computing device to be unlocked using the recovered first credential.

Claims (78)

1. A computer-implemented method, comprising:

receiving, via a computing device in a locked state, input of a first PIN;

determining that the first PIN is associated with a first cryptographic key that is stored in a memory, wherein the determining includes:

computing a unique value based on the first PIN; and

iterating through a plurality of stored cryptographic keys corresponding to authorized PINs for the computing device to determine if any of the cryptographic keys is protected using the unique value, the determining including, for each cryptographic key:

obtaining a ciphertext based on encrypting the cryptographic key using the unique value; and

comparing the ciphertext and a stored encrypted form of the cryptographic key in order to identify a match;

responsive to determining that the first PIN is associated with the first cryptographic key, retrieving, from the memory, an encrypted form of a first credential that is associated with the first cryptographic key;

recovering the first credential from the encrypted form using the first cryptographic key; and

causing the computing device to be unlocked using the recovered first credential.

2. The method of claim 1 , wherein recovering the first credential comprises decrypting the encrypted form using the first cryptographic key.

3. The method of claim 1 , wherein computing the unique value comprises applying a key derivation function to an input representing a combination of the first PIN and a device identifier associated with the computing device.

4. The method of claim 1 , wherein determining that the first PIN is associated with the first cryptographic key comprises querying a lookup table stored in the memory to identify a cryptographic key that is stored in association with the first PIN.

5. The method of claim 1 , wherein the first cryptographic key comprises a randomly-generated key.

6. The method of claim 1 , further comprising:

receiving a plurality of authorized PINs associated with the computing device;

for each of the plurality of authorized PINs:

generating a random key; and

storing the random key in association with the authorized PIN in the memory.

7. The method of claim 6 , further comprising, for each of the stored random keys:

encrypting the first credential using the random key to obtain an encrypted first credential; and

storing, in the memory, the encrypted first credential in association with the random key.

8. The method of claim 6 , further comprising, for each of the plurality of authorized PINs:

computing a hash value based on the authorized PIN;

encrypting the random key that is stored in association with the authorized PIN using the computed hash value; and

storing, in the memory, the encrypted random key.

9. The method of claim 1 , further comprising:

receiving a request to update a first authorized PIN associated with the computing device;

in response to receiving the request:

identifying one or more keys that are stored in the memory in association with the first authorized PIN;

deleting the identified keys from the memory; and

generating new keys associated with the first authorized PIN.

10. A computing device, comprising:

a processor; and

a memory coupled to the processor, the memory storing instructions that, when executed by the processor, are to cause the processor to:

receive, in a locked state of the computing device, input of a first PIN;

determine that the first PIN is associated with a first cryptographic key that is stored in a memory, wherein the determining includes:

computing a unique value based on the first PIN; and

iterating through a plurality of stored cryptographic keys corresponding to authorized PINs for the computing device to determine if any of the cryptographic keys is protected using the unique value, the determining including, for each cryptographic key:

obtaining a ciphertext based on encrypting the cryptographic key using the unique value; and

comparing the ciphertext and a stored encrypted form of the cryptographic key in order to identify a match;

responsive to determining that the first PIN is associated with the first cryptographic key, retrieve, from the memory, an encrypted form of a first credential that is associated with the first cryptographic key;

recover the first credential from the encrypted form using the first cryptographic key; and

cause the computing device to be unlocked using the recovered first credential.

11. The computing device of claim 10 , wherein recovering the first credential comprises decrypting the encrypted form using the first cryptographic key.

12. The computing device of claim 10 , wherein computing the unique value comprises applying a key derivation function to an input representing a combination of the first PIN and a device identifier associated with the computing device.

13. The computing device of claim 10 , wherein determining that the first PIN is associated with the first cryptographic key comprises querying a lookup table stored in the memory to identify a cryptographic key that is stored in association with the first PIN.

14. The computing device of claim 10 , wherein the first cryptographic key comprises a randomly-generated key.

15. The computing device of claim 10 , wherein the instructions, when executed, are to further cause the processor to:

receive a plurality of authorized PINs associated with the computing device;

for each of the plurality of authorized PINs:

generate a random key; and

store the random key in association with the authorized PIN in the memory.

16. The computing device of claim 15 , wherein the instructions, when executed, are to further cause the processor to, for each of the stored random keys:

encrypt the first credential using the random key to obtain an encrypted first credential; and

store, in the memory, the encrypted first credential in association with the random key.

17. The computing device of claim 15 , wherein the instructions, when executed, are to further cause the processor to, for each of the plurality of authorized PINs:

compute a hash value based on the authorized PIN;

encrypt the random key that is stored in association with the authorized PIN using the computed hash value; and

store, in the memory, the encrypted random key.

18. The computing device of claim 10 , wherein the instructions, when executed, are to further cause the processor to:

receive a request to update a first authorized PIN associated with the computing device;

in response to receiving the request:

identify one or more keys that are stored in the memory in association with the first authorized PIN;

delete the identified keys from the memory; and

generating new keys associated with the first authorized PIN.

19. A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by a processor, are to cause the processor to:

receive, via a computing device in a locked state, input of a first PIN;

determine that the first PIN is associated with a first cryptographic key that is stored in a memory, wherein the determining includes:

computing a unique value based on the first PIN;

iterating through a plurality of stored cryptographic keys corresponding to authorized PINs for the computing device to determine if any of the cryptographic keys is protected using the unique value, the determining including, for each cryptographic key:

obtaining a ciphertext based on encrypting the cryptographic key using the unique value; and

comparing the ciphertext and a stored encrypted form of the cryptographic key in order to identify a match;

responsive to determining that the first PIN is associated with the first cryptographic key, retrieve, from the memory, an encrypted form of a first credential that is associated with the first cryptographic key;

recover the first credential from the encrypted form using the first cryptographic key; and

cause the computing device to be unlocked using the recovered first credential.

20. The computer-readable medium of claim 19 , wherein recovering the first credential comprises decrypting the encrypted form using the first cryptographic key.

21. The computer-readable medium of claim 19 , wherein computing the unique value comprises applying a key derivation function to an input representing a combination of the first PIN and a device identifier associated with the computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2021
From: HUGHES, MICHAEL; CAVEDON, FRANCISCO AFONSO; ALI, MIR MUSTAFA; CHAWLA, TARIKA; KALIAZINE, ALEXANDRE
To: SHOPIFY INC.
Reel/Frame 058467/0425 →
Continuity (1)
Related Publication 20230185892A1 · Jun 15, 2023