IP Library Granted Patent US 8,621,189
Granted Patent B2
US 8,621,189 · App. 12/974,051 · Granted Dec 31, 2013

System and method for hardware strengthened passwords

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,621,189
App. No.
12/974,051
Granted
Dec 31, 2013
Kind
B2
Abstract

A cryptographic module and a computing device implemented method for securing data using a cryptographic module is provided. The cryptographic module may include an input component for receiving a password, an output component for outputting data to the computing device, a random number generator for generating a random number and a module processor operative to generate at least one cryptographic key using the generated random number, and to record an association between the received password linking the received password with the at least one cryptographic key in a data store accessible to the cryptographic module.

Claims (58)

1. A computing device implemented method for using a cryptographic module located within the computing device, the method comprising:

a processor of the cryptographic module:

receiving a password together with a cryptographic state identifier, the cryptographic state identifier specifying either an encryption mode or a decryption mode for the cryptographic module;

checking a data store for a cryptographic key previously recorded in association with the received password;

when the data store contains a cryptographic key previously recorded in association with the received password,

retrieving said cryptographic key; and

entering the encryption mode or the decryption mode as specified by the received cryptographic state identifier, and while in said mode, receiving data to be processed from a component of the computing device, processing said received data in accordance with said mode using said retrieved cryptographic key, and outputting the processed data; and

when the data store does not contain a cryptographic key previously recorded in association with the password,

generating a random number using a random number generator;

generating at least one cryptographic key using the generated random number; and,

recording an association of the received password and the at least one cryptographic key in the data store.

2. The method of claim 1 wherein the generating at least one cryptographic key further comprises the processor combining the generated random number with the received password as inputs to a cryptographic key generation operation to form the at least one cryptographic key.

3. The method of claim 1 wherein after generating the at least one cryptographic key, the method further comprises the processor outputting the at least one cryptographic key to a component of the computing device.

4. The method of claim 1 , further comprising, after the cryptographic module generates the at least one cryptographic key:

the processor:

entering the encryption mode or the decryption mode as specified by the received cryptographic state identifier, and while in said mode, receiving data to be processed from the component of the computing device, processing said received data in accordance with said mode using said generated at least one cryptographic key, and outputting the processed data.

5. The method of claim 1 wherein the cryptographic module is further operative to receive a kill command from the computing device and, in response to the kill command, the method further comprises the processor deleting the recorded association from the data store.

6. The method of claim 1 , further comprising, prior to checking the data store:

determining whether the received password is correct; and

when the received password is not correct, the cryptographic module deleting at least one previously recorded association from the data store.

7. The method of claim 2 wherein the at least one cryptographic key is generated by combining the generated random number with the received password using an XOR operation.

8. The method of claim 2 wherein the at least one cryptographic key is generated by the processor:

deriving an elliptic curve value from the received password;

performing an elliptic curve scalar multiplication using the elliptic curve value and the generated random number; and,

applying a deterministic key-derivation function to the product of the elliptic curve scalar multiplication.

9. The method of claim 8 further comprising the processor combining the result of the deterministic key-derivation function with the generated random number using an XOR operation.

10. A cryptographic module for a computing device, the cryptographic module comprising:

an input for receiving a password together with a cryptographic state identifier, the cryptographic state identifier specifying either an encryption mode or a decryption mode for the cryptographic module;

an output for outputting data to the computing device;

a random number generator for generating a random number;

a module processor operative to:

receive the password together with the cryptographic state identifier;

check a data store for a cryptographic key previously recorded in association with the received password;

when the data store contains a cryptographic key previously recorded in association with the received password,

retrieve said cryptographic key; and

enter the encryption mode or the decryption mode as specified by the received cryptographic state identifier, and while in said mode, receive data to be processed from a component of the computing device, process said received data in accordance with said mode using said retrieved cryptographic key, and output the processed data; and

when the data store does not contain a cryptographic key recorded in association with the password,

generate a random number using the random number generator;

generate at least one cryptographic key using the generated random number; and

record an association between the received password and the at least one cryptographic key in the data store.

11. The cryptographic module of claim 10 wherein the cryptographic module is further operative to generate the at least one cryptographic key by combining the generated random number with the received password as inputs to a cryptographic key generation operation to form the at least one cryptographic key.

12. The cryptographic module of claim 10 wherein the cryptographic module is further operative to output the at least one cryptographic key to the computing device.

13. The cryptographic module of claim 10 wherein the cryptographic module is further operative to:

enter the encryption mode or decryption mode as specified by the received cryptographic state identifier, and while in said mode,

receive data to be processed from the component of the computing device;

process the received data in accordance with said mode using said generated at least one cryptographic key; and,

output the processed data.

14. The cryptographic module of claim 10 wherein the cryptographic module is further operative to receive a kill command from the computing device and, in response to the kill command, delete the recorded association from the data store.

15. The cryptographic module of claim 13 wherein the cryptographic module is further operative to:

determine whether the received password is correct; and

when the received password is not correct, delete at least one previously recorded association from the data store.

16. The cryptographic module of claim 11 wherein the cryptographic module is operative to generate the at least one cryptographic key by combining the generated random number with the received password using an XOR operation.

17. The cryptographic module of claim 11 wherein the cryptographic module is operative to generate the at least one cryptographic key by the cryptographic module:

deriving an elliptic curve value from the received password;

performing an elliptic curve scalar multiplication using the elliptic curve value and the generated random number; and,

applying a deterministic key-derivation function to the product of the elliptic curve scalar multiplication.

18. The cryptographic module of claim 17 wherein the cryptographic module is operative to generate the at least one cryptographic key by combining the result of the deterministic key-derivation function with the generated random number using an XOR operation.

19. A non-transitory computer readable storage media bearing computer readable instructions which when implemented in a processor of a cryptographic module cause the module to implement the steps of the method of claim 1 .

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
CHANGE OF NAME Recorded Oct 28, 2013
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 031506/0403 →