Security enclave device to extend a virtual secure processing environment to a client device
Abstract
Disclosed are methods and devices to provide a transaction over a network. In one embodiment, a machine-implemented method includes: opening, through an enclave device, an in-band channel or an out-of-band channel over the network; authenticating, through the enclave device, a user of a resource over the in-band channel or the out-of-band channel; facilitating, through the enclave device, an authorization of the user to access the resource over the in-band channel or the out-of-band channel; and accounting for a transaction conducted by the user accessing the resource, through the enclave device, over the in-band channel or the out-of-band channel.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A machine-implemented method, comprising:
opening, through an enclave device, an in-band channel or an out-of-band channel over a network; authenticating, through the enclave device, a user of a resource over the in-band channel or the out-of-band channel; facilitating, through the enclave device, an authorization of the user to access the resource over the in-band channel or the out-of-band channel; and accounting for a transaction conducted by the user accessing the resource, through the enclave device, over the in-band channel or the out-of-band channel.
2 . The method of claim 1 , wherein:
the in-band channel is opened over an in-band network and the out-of-band channel is opened over an out-of-band network; the in-band network is at least one of a wireless network established over a licensed radio frequency band and a wired network; and the out-of-band network is a wireless network established over an unlicensed radio frequency band.
3 . The method of claim 1 , further comprising:
authenticating the user of the resource through a multi-factor authentication mechanism using at least one of a plurality of readers of the enclave device, wherein the multi-factor authentication mechanism comprises at least two of a near-field communication (NFC) identification mechanism, a biometric reader identification mechanism, a user name and password identification mechanism, a pattern matching identification mechanism, a global positioning system (GPS) identification mechanism, and a radio-frequency identification (RFID) mechanism.
4 . The method of claim 1 , further comprising:
facilitating, through the enclave device, the authorization of the user to access the resource by:
generating a one-time encrypted software token (EST) through a trusted platform module (TPM),
sending a hash of the one-time EST through at least one of the in-band channel and the out-of-band channel to a switch managing the network, and
authorizing the user to access the resource based on a comparison of the hash of the one-time EST with a one-time EST independently generated by the switch.
5 . The method of claim 1 , wherein the enclave device comprises a battery, a low-power processor, an NFC chip, a plurality of readers, an interface to a client device used by the user to access the resource, and a storage device coupled to the low-power processor.
6 . The method of claim 5 , wherein the interface to the client device is a physical interface that couples the enclave device to the client device through a physical connection.
7 . The method of claim 5 , wherein the interface to the client device is a radio interface that couples the enclave device to the client device through a radio frequency connection.
8 . The method of claim 1 , wherein the enclave device is an integrated circuit chip embedded in a client device used by the user to access the resource.
9 . The method of claim 1 , wherein the enclave device is a software module running on a client device used by the user to access the resource.
10 . The method of claim 1 , wherein at least one of the in-band channel and the out-of-band channel is opened at one of a resource level, a resource flow level, and a network level and a virtual network is established over at least one of the in-band channel and the out-of-band channel.
11 . An enclave device to provide a transaction over a network, comprising:
one or more low-power processors; one or more storage devices communicatively coupled to the one or more low-power processors; a plurality of readers communicatively coupled to the one or more low-power processors; an NFC chip communicatively coupled to the one or more low-power processors; a battery; an interface to a client device; and one or more programs, wherein the one or more programs are stored in the one or more storage devices and executable by the one or more low-power processors, the one or more programs comprising:
instructions to open an in-band channel or an out-of-band channel from the client device to a switch managing a network,
instructions to authenticate a user of a resource over the in-band channel or the out-of-band channel,
instructions to facilitate an authorization of the user to access the resource using the client device over the in-band channel or the out-of-band channel, and
instructions to account for a transaction conducted by the user through the client device using the resource over the in-band channel or the out-of-band channel.
12 . The enclave device of claim 11 , wherein:
the in-band channel is opened over an in-band network and the out-of-band channel is opened over an out-of-band network; the in-band network is at least one of a wireless network established over a licensed radio frequency band and a wired network; the out-of-band network is a wireless network established over an unlicensed radio frequency band; at least one of the in-band channel and the out-of-band channel is opened at one of a resource level, a resource flow level, and a network level; and a virtual network is established over at least one of the in-band channel and the out-of-band channel.
13 . The enclave device of claim 11 , further comprising:
instructions to authenticate the user through a multi-factor authentication mechanism using at least one of the plurality of readers of the enclave device, wherein the multi-factor authentication mechanism comprises at least two of a near-field communication (NFC) identification mechanism, a biometric reader identification mechanism, a user name and password identification mechanism, a pattern matching identification mechanism, a global positioning system (GPS) identification mechanism, and a radio-frequency identification (RFID) mechanism.
14 . The enclave device of claim 11 , further comprising:
instructions to facilitate the authorization of the user to access the resource using the client device with further instructions to:
generate a one-time encrypted software token (EST) through a trusted platform module (TPM),
send a hash of the one-time EST through at least one of the in-band channel and the out-of-band channel to the switch, and
authorize the user to access the resource based on a comparison of the hash of the one-time EST with a one-time EST independently generated by the switch.
15 . The enclave device of claim 11 , wherein the interface to the client device is a physical interface that couples the enclave device to the client device through a physical connection.
16 . The enclave device of claim 11 , wherein the interface to the client device is a radio interface that couples the enclave device to the client device through a radio frequency connection.
17 . A storage medium, readable through a processor, and including instructions embodied therein and configured to be executable through the processor, comprising:
instructions to open an in-band channel or an out-of-band channel from a client device to a switch managing a network; instructions to authenticate, through a reader communicatively coupled to the processor, a user of a resource over the in-band channel or the out-of-band channel; instructions to facilitate an authorization of the user to access the resource over the in-band channel or the out-of-band channel; and instructions to account for a transaction conducted by the user using the resource over the in-band channel or the out-of-band channel.
18 . The storage medium of claim 17 , wherein:
the in-band channel is opened over an in-band network and the out-of-band channel is opened over an out-of-band network; the in-band network is at least one of a wireless network established over a licensed radio frequency band and a wired network; the out-of-band network is a wireless network established over an unlicensed radio frequency band; at least one of the in-band channel and the out-of-band channel is opened at one of a resource level, a resource flow level, and a network level; and a virtual network is established over at least one of the in-band channel and the out-of-band channel.
19 . The storage medium of claim 17 , further comprising:
instructions to authenticate the user of the resource through a multi-factor authentication mechanism using the reader, wherein the multi-factor authentication mechanism comprises at least two of a near-field communication (NFC) identification mechanism, a biometric reader identification mechanism, a user name and password identification mechanism, a pattern matching identification mechanism, a global positioning system (GPS) identification mechanism, and a radio-frequency identification (RFID) mechanism.
20 . The storage medium of claim 17 , further comprising:
instructions to facilitate the authorization of the user to access the resource with further instructions to:
generate a one-time encrypted software token (EST) through a trusted platform module (TPM),
send a hash of the one-time EST through at least one of the in-band channel and the out-of-band channel to the switch, and
authorize the user to access the resource based on a comparison of the hash of the one-time EST with a one-time EST independently generated by the switch.Join the waitlist — get patent alerts
Track US2014189811A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.