IP Library Granted Patent US 8,375,212
Granted Patent B2
US 8,375,212 · App. 12/978,754 · Granted Feb 12, 2013

Method for personalizing an authentication token

Inventors: Peter Buck (London, GB); Peter Newport (London, GB)
Assignee: Prism Technologies LLC
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,375,212
App. No.
12/978,754
Granted
Feb 12, 2013
Kind
B2
Abstract

An authentication token using a smart card that an organization would issue to its customer, the smart card having a processor for executing a software application that is responsive to a user input to generate a one-time password as an output. The smart card co-operates with an interface device for inputting the user input and displaying the one-time password. The authentication token may be used in combination with a remote authentication server for validation of the password and hence authentication of the user.

Claims (11)

1. A method for personalizing an authentication token comprising:

entering by the authentication token into personalization mode;

requesting from the authentication token, by a personalization device in communication with the authentication token, a serial number of the authentication token;

encrypting by the personalization device the serial number using a personalization key, and forwarding the encrypted serial number to the authentication token from the personalization device;

decrypting by the authentication token of the encrypted serial number, and validating by the authentication token that the personalization key is correct;

establishing an encrypted session between the authentication token and the personalization device using a transport key;

sending to the authentication token, by the personalization device, an initial seed value and an initial secret key using the transport key to encrypt the initial seed value and the initial secret key, the initial seed value and the initial secret key for facilitating an initial interaction between the authentication token and an interface device; and

storing by the authentication token the initial seed value and the initial secret key after decryption thereof by the authentication token using the transport key, wherein, once the authentication token is personalized with the initial seed value and the initial secret key, the authentication token can no longer enter the personalization mode.

2. The method of claim 1 , wherein after the authentication token is provided the initial seed value and the initial secret key, the initial seed value stored in a memory in the authentication token can be used to generate a key for use in generating a secure password used in interacting with the interface device.

3. The method of claim 2 , wherein data exchanged between the authentication token and the personalization device for use in generating the secure password is stored by the personalization device for subsequent transfer to a third party.

4. The method of claim 2 , further comprising entering by the authentication token into normal mode after said storing the initial seed value and the initial secret key.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 24, 2021
From: PRISM TECHNOLOGIES, LLC
To: AUTH TOKEN LLC
Reel/Frame 058475/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2011
From: QUIZID TECHNOLOGIES LIMITED
To: PRISM TECHNOLOGIES LLC
Reel/Frame 025803/0425 →
CHANGE OF NAME Recorded Feb 2, 2011
From: ASSENDON LIMITED
To: QUIZID TECHNOLOGIES LIMITED
Reel/Frame 025734/0970 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2011
From: BUCK, PETER; NEWPORT, PETER
To: ASSENDON LIMITED
Reel/Frame 025690/0895 →
Priority Claims (1)
GB 0210692.0 · May 10, 2002 · national
Continuity (2)
Division 10176974 · Jun 20, 2002
Related Publication 20110093708A1 · Apr 21, 2011