US2004177258A1PendingUtilityA1

Secure object for convenient identification

Priority: Mar 3, 2003Filed: Apr 21, 2003Published: Sep 9, 2004
Est. expiryMar 3, 2023(expired)· nominal 20-yr term from priority
Inventors:Peng Ong
H04L 63/0823H04L 63/0853H04L 63/0428G06F 21/41H04L 63/083G06F 21/34
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and apparatus for automatic user authentication are described. The method includes receiving information at a device, the device including a credential container; storing the information at the credential container and performing cryptographic calculations on the received information and providing the encrypted information upon request.

Claims

exact text as granted — not AI-modified
What is claimed is:  
     
         1 . A method comprising: 
 receiving information at a device, the device including a credential container;    storing the information at the credential container; and    performing cryptographic calculations on the received information and providing the encrypted information upon request.    
     
     
         2 . The method of  claim 1  wherein the information is authentication information.  
     
     
         3 . The method of  claim 1  wherein the cryptographic calculations are public key algorithms.  
     
     
         4 . The method of  claim 1  wherein the device is a hardware device communicating with a client computer.  
     
     
         5 . The method of  claim 4  wherein the device is communicating with the client computer via a USB controller.  
     
     
         6 . The method of  claim 4  wherein the device is communicating with the client computer via a Bluetooth controller.  
     
     
         7 . The method of  claim 4  wherein the device is communicating with the client computer via an RFID controller.  
     
     
         8 . The method of  claim 4  wherein the device is communicating with the client computer via a PCMCIA controller.  
     
     
         9 . The method of  claim 4  wherein the device is communicating with the client computer via an 802.11b controller.  
     
     
         10 . The method of  claim 1  wherein the credential container includes user passwords.  
     
     
         11 . The method of  claim 1  wherein the credential container includes cryptographic keys.  
     
     
         12 . The method of  claim 1  wherein the credential container includes digital certificates.  
     
     
         13 . A method comprising: 
 encrypting a symmetric key of a first device with a public key of the second device;    transferring the encrypted symmetric key to the second device; and    transferring contents of first device to the second device.    
     
     
         14 . The method of  claim 13  wherein the contents of the first device are authentication data.  
     
     
         15 . The method of  claim 13  wherein the second device is a hardware device.  
     
     
         16 . The method of  claim 13  further comprising uploading the contents of the first device to a server.  
     
     
         17 . The method of  claim 16  further comprising downloading the contents of the first device from the server to the second device.  
     
     
         18 . The method of  claim 17  further comprising decrypting the contents downloaded to the second device utilizing the symmetric key.  
     
     
         19 . A method comprising: 
 receiving a request for information to be provided to a host; and    determining whether the host is included in a list of trusted hosts prior to performing cryptographic calculations on the requested information.    
     
     
         20 . The method of  claim 19  wherein the information is authentication information.  
     
     
         21 . The method of  claim 19  wherein the list of trusted hosts is located on a hardware device.  
     
     
         22 . The method of  claim 19  wherein the cryptographic calculations include public key algorithms.  
     
     
         23 . A method comprising: 
 detecting a change of a PIN by the software hosting a first device of a plurality of devices;    encrypting the PIN with a public key of at least one other device from the plurality of devices;    distributing the encrypted PIN to the at least one other device from the plurality of devices.    
     
     
         24 . The method of  claim 23  wherein the device is a hardware device including authentication information.  
     
     
         25 . The method of  claim 23  wherein the change of the PIN is performed by a user at a user computer.  
     
     
         26 . The method of  claim 23  wherein the distributing the encrypted PIN is performed via a server.  
     
     
         27 . The method of  claim 23  further comprising decrypting the PIN with a private key of the at least one other device from the plurality of devices and replacing an old PIN with the decrypted PIN.  
     
     
         28 . A method comprising: 
 receiving a challenge phrase on a client computer;    inputting the challenge phrase into a security device;    receiving a response phrase from the security device; and    inputting the response phrase into the client computer.    
     
     
         29 . The method of  claim 28  wherein the security device is a hardware device including authentication information.  
     
     
         30 . The method of  claim 28  wherein the security device includes a display and a keyboard.  
     
     
         31 . The method of  claim 30  wherein the inputting the challenge phrase into the security device is performed by a user utilizing the keyboard.  
     
     
         32 . The method of  claim 30  wherein the receiving the response phrase from the security device comprises displaying the response phrase on the display.  
     
     
         33 . The method of  claim 28  wherein the challenge phrase is a request for authentication data.  
     
     
         34 . The method of  claim 28  wherein the response phrase includes authentication data.  
     
     
         35 . A method comprising: 
 receiving data to be digitally signed into at hardware device;    digitally signing the data in the hardware device.    
     
     
         36 . The method of  claim 35  wherein the hardware device configured to be connected to a user computer.  
     
     
         37 . The method of  claim 35  further comprising a user entering the data utilizing the hardware device keyboard and display.  
     
     
         38 . The method of  claim 35  further comprising a user authorizing the digital signing by utilizing physical features of the hardware device.  
     
     
         39 . The method of  claim 38  wherein the physical features of the hardware device include an authorization button.  
     
     
         40 . The method of  claim 38  wherein the physical features of the hardware device include a display.  
     
     
         41 . The method of  claim 40  wherein the display displays contents to be digitally signed.  
     
     
         42 . The method of  claim 38  wherein the user authorizing the digital signing by pressing an authorization button.  
     
     
         43 . An apparatus comprising: 
 a communication controller to receive information and to transmit encrypted information;    a processor to perform cryptographic calculations on received information;    a credential container to store the received information;    a keyboard to allow a user to control the device and a display to display user requested information,    wherein the apparatus configured to be connected to a client computer.    
     
     
         44 . The apparatus of  claim 43  wherein the apparatus is a hardware device.  
     
     
         45 . The apparatus of  claim 43  further comprising a smart card chip to perform the cryptographic calculations.  
     
     
         46 . The apparatus of  claim 43  wherein the credential container includes a trusted hosts list comprising hosts to which the apparatus configured to authenticate a user.  
     
     
         47 . The apparatus of  claim 43  wherein the credential container includes manufacturing data, wherein the manufacturing data is digitally signed and stored in a certificate.  
     
     
         48 . The apparatus of  claim 47  wherein the manufacturing data includes at least one piece of information from a plurality of information including a serial number of the apparatus, a color of the apparatus, a physical form of the apparatus, an identification of a manufacturer of the apparatus, a date of manufacturing of the apparatus.

Join the waitlist — get patent alerts

Track US2004177258A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.