Security and authentication systems and methods for personalized portable devices and associated systems
Abstract
Systems and methods for client authentication and verification in a distributed client-server system are described. An authentication and verification system may include a plurality of client devices containing private keys, a first server configured to interface with the plurality of client devices, and a second, secure server configured to interface with the first server and store public keys associated with the private keys on the client devices. A method is further described for verifying client devices in conjunction with the first and second servers. The first server may contain secure tokens that can be decrypted in conjunction with the authentication and verification method.
Claims
exact text as granted — not AI-modified1 . An authentication system comprising:
a first server, said first server including a first processor readable storage medium on which is stored:
a plurality of public keys, wherein ones of the public keys are matched with ones of a corresponding plurality of private keys stored individually on a plurality of client devices, the client devices each including a user presence input mechanism for performing an authentication transaction; and
a first server private key, said private key matched to a public key stored on the plurality of client devices; and
a second server configured to store client device information associated with one or more of the plurality of client devices and to electronically communicate with the first server and the plurality of client devices, the electronic communication being performed at least in part in response to an indication from the user presence input mechanism; wherein the second server includes a second processor readable storage medium on which is stored the client device information, the client device information including a first putative ID (PID) associated with a first of the plurality of client devices, the PID providing an identifier of the first of the plurality of client devices, and the PID being associated with an authentication status of the first of the plurality of client devices.
2 . (canceled)
3 . The authentication system of claim 1 , wherein said client device information further includes:
a first owner key (OK) indexed to the first PID; and a first security token indexed to the first PID, wherein the first security token is associated with the first OK.
4 . The authentication system of claim 3 , wherein the first security token is encrypted with the first OK.
5 . The authentication system of claim 1 , wherein a hash table is stored on the first storage medium, said hash table indexed on ones of a plurality of PIDs associated with the plurality of client devices.
6 . The authentication system of claim 1 , wherein the first server is configured to communicate with the plurality of client devices through a network connection to the second server.
7 . The authentication system of claim 1 , wherein the first server may be accessed solely through a dedicated electronic connection with the second server.
8 . The authentication system of claim 7 , wherein the first server and second server are configured to communicate using a proprietary interface.
9 . The authentication system of claim 1 , further comprising a third server, said third server including a third processor readable storage medium on which is stored a master private key, said master private key matched to a master public key stored on one or more of the client devices.
10 . The authentication system of claim 9 , wherein the third server is isolated from all network connectivity.
11 . The authentication system of claim 10 , wherein the master private key is further stored on the second server.
12 . A client device for use in an authentication system, comprising:
a hardware processor; a user presence input mechanism; and a processor readable storage medium on which is stored client device information, said client device information including:
a putative ID (PID) associated with the client device, the PID providing an identifier of the client device that is associated with an authentication status of the client device, wherein the authentication status is modified at least in part in response to activation of the user presence input mechanism;
a private key matched to a corresponding public key, the corresponding public key also being stored on a first server;
a server public key matched to a corresponding server private key stored on the first server; and
an owner key (OK), said OK associated with a security token (ST), the ST being stored on a second server.
13 . (canceled)
14 . The client device of claim 12 , wherein the first processor comprises a cryptographic processor, the cryptographic processor coupled to a processor readable read-only storage medium, the read-only storage medium including the private key.
15 . The client device of claim 14 , wherein said processor is electronically coupled to said crypto processor.
16 . The client device of claim 15 , wherein said core processor is electronically coupled to said crypto processor through a serial bus.
17 . The client device of claim 12 , wherein the processor readable storage medium further contains a master public key, said master public key matched to a master private key stored on a third server, the third server being physically isolated from the first server and the second server.
18 . The client device of claim 12 , wherein the device is configured to delete the OK in response to a user actuated input.
19 . (canceled)
20 . (canceled)
21 . (canceled)
22 . The method of claim 37 , wherein said owner key is encrypted using a public key stored on the client device, said public key corresponding to a private key stored on the server.
23 . (canceled)
24 . (canceled)
25 . (canceled)
26 . The method of claim 37 , wherein the authentication request includes a hash of the PID.
27 . (canceled)
28 . (canceled)
29 . (canceled)
30 . (canceled)
31 . (canceled)
32 . (canceled)
33 . (canceled)
34 . (canceled)
35 . (canceled)
36 . (canceled)
37 . A method of authenticating a client device comprising operations performed using a hardware processor and memory of the client device, the operations including:
generating an authentication request at the client device, said authentication request including a putative ID (PID), the PID providing an identifier of the client device that is associated with an authentication status of the client device; sending the authentication request to a server; receiving, from the server, a reply request, said reply request including a first random number (Rn); testing, at the client device, for a user presence input; generating a reply message, in response to a detected occurrence of the user presence input, said reply message including an encrypted owner key (OK), unsigned information, and signed information, said signed information signed using a private key stored on the client device, wherein said private key matches a public key stored on the server; and sending the reply message to the server, wherein said server is configured to verify the reply message.
38 . The method of claim 37 , wherein said signed information includes:
the encrypted OK; a first random number (Rn) provided in the reply request; a second random number (Rm) generated at the client device; and version information associated with the client device.
39 . (canceled)
40 . The method of claim 37 , further comprising verifying the reply request using a master public key stored on the client device, said master public key matched to a master private key stored on the server.
41 . The authentication system of claim 1 , wherein the indication from the user presence input mechanism is provided from actuation of a button located on the respective client devices.
42 . The client device of claim 12 , wherein said user presence input mechanism includes a physical switch on a surface of the client device, said physical switch operably coupled to said processor.
43 . The client device of claim 14 , wherein said user presence input mechanism includes a physical switch on a surface of the client device, said physical switch operably coupled to said crypto processor.
44 . The client device of claim 14 , wherein said crypto processor will only perform. an authentication including said PID and said OK in response to an actuation of the physical switch.
45 . The method of claim 37 , further comprising:
generating a second random number (Rm) at the client device; wherein said unsigned information includes:
the encrypted OK;
the Rm; and
version information associated with the client device.
46 . The method of claim 37 , wherein said owner key is encrypted using a public key stored on the client device, said public key corresponding private key stored on the server.
47 . The method of claim 37 , wherein the authentication request includes a hash of the PID.
48 . A non-transitory computer-readable storage media comprising instructions that when executed by a processor of a device causes the device to:
generate an authentication request at the client device, said authentication request including a putative ID (PID), the PID providing an identifier of the device that is associated with an authentication status of the device; send the authentication request to a server; receive, from the server, a reply request, said reply request including a first random number (Rn); test, at the client device, for a user presence input; generating a reply message, in response to a detection of the user presence input, said reply message including: an encrypted owner key (OK), unsigned information, and signed information, said signed information signed using a private key stored on the client device, wherein said private key matches a public key stored on the server; and sending the reply message to the server, wherein said server is configured to verify the reply message.
49 . The computer-readable storage media of claim 48 , wherein said signed information includes:
the encrypted OK; a first random number (Rn) provided in the reply request; a second random number (Rm) generated at the client device; and version information associated with the client device
50 . The computer-readable storage media of claim 48 , comprising instructions that when executed by a processor cause the processor to:
verify the reply request using a master public key stored on the client device, said master public key matched to a master private key stored on the server.
51 . The computer-readable storage media of claim 48 , comprising instructions that when executed by a processor cause the processor to:
generate a second random number (Rm) at the client device; wherein said unsigned information includes:
the encrypted OK;
the Rm; and
version information associated with the client device.Join the waitlist — get patent alerts
Track US2014136847A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.