US2014189811A1PendingUtilityA1

Security enclave device to extend a virtual secure processing environment to a client device

Individually held — no corporate assignee on recordPriority: Dec 29, 2012Filed: Apr 5, 2013Published: Jul 3, 2014
Est. expiryDec 29, 2032(~6.4 yrs left)· nominal 20-yr term from priority
G06F 21/6236H04L 63/0884H04W 12/068H04W 12/06
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Disclosed are methods and devices to provide a transaction over a network. In one embodiment, a machine-implemented method includes: opening, through an enclave device, an in-band channel or an out-of-band channel over the network; authenticating, through the enclave device, a user of a resource over the in-band channel or the out-of-band channel; facilitating, through the enclave device, an authorization of the user to access the resource over the in-band channel or the out-of-band channel; and accounting for a transaction conducted by the user accessing the resource, through the enclave device, over the in-band channel or the out-of-band channel.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A machine-implemented method, comprising:
 opening, through an enclave device, an in-band channel or an out-of-band channel over a network;   authenticating, through the enclave device, a user of a resource over the in-band channel or the out-of-band channel;   facilitating, through the enclave device, an authorization of the user to access the resource over the in-band channel or the out-of-band channel; and   accounting for a transaction conducted by the user accessing the resource, through the enclave device, over the in-band channel or the out-of-band channel.   
     
     
         2 . The method of  claim 1 , wherein:
 the in-band channel is opened over an in-band network and the out-of-band channel is opened over an out-of-band network;   the in-band network is at least one of a wireless network established over a licensed radio frequency band and a wired network; and   the out-of-band network is a wireless network established over an unlicensed radio frequency band.   
     
     
         3 . The method of  claim 1 , further comprising:
 authenticating the user of the resource through a multi-factor authentication mechanism using at least one of a plurality of readers of the enclave device, wherein the multi-factor authentication mechanism comprises at least two of a near-field communication (NFC) identification mechanism, a biometric reader identification mechanism, a user name and password identification mechanism, a pattern matching identification mechanism, a global positioning system (GPS) identification mechanism, and a radio-frequency identification (RFID) mechanism.   
     
     
         4 . The method of  claim 1 , further comprising:
 facilitating, through the enclave device, the authorization of the user to access the resource by:
 generating a one-time encrypted software token (EST) through a trusted platform module (TPM), 
 sending a hash of the one-time EST through at least one of the in-band channel and the out-of-band channel to a switch managing the network, and 
 authorizing the user to access the resource based on a comparison of the hash of the one-time EST with a one-time EST independently generated by the switch. 
   
     
     
         5 . The method of  claim 1 , wherein the enclave device comprises a battery, a low-power processor, an NFC chip, a plurality of readers, an interface to a client device used by the user to access the resource, and a storage device coupled to the low-power processor. 
     
     
         6 . The method of  claim 5 , wherein the interface to the client device is a physical interface that couples the enclave device to the client device through a physical connection. 
     
     
         7 . The method of  claim 5 , wherein the interface to the client device is a radio interface that couples the enclave device to the client device through a radio frequency connection. 
     
     
         8 . The method of  claim 1 , wherein the enclave device is an integrated circuit chip embedded in a client device used by the user to access the resource. 
     
     
         9 . The method of  claim 1 , wherein the enclave device is a software module running on a client device used by the user to access the resource. 
     
     
         10 . The method of  claim 1 , wherein at least one of the in-band channel and the out-of-band channel is opened at one of a resource level, a resource flow level, and a network level and a virtual network is established over at least one of the in-band channel and the out-of-band channel. 
     
     
         11 . An enclave device to provide a transaction over a network, comprising:
 one or more low-power processors;   one or more storage devices communicatively coupled to the one or more low-power processors;   a plurality of readers communicatively coupled to the one or more low-power processors;   an NFC chip communicatively coupled to the one or more low-power processors;   a battery;   an interface to a client device; and   one or more programs, wherein the one or more programs are stored in the one or more storage devices and executable by the one or more low-power processors, the one or more programs comprising:
 instructions to open an in-band channel or an out-of-band channel from the client device to a switch managing a network, 
 instructions to authenticate a user of a resource over the in-band channel or the out-of-band channel, 
 instructions to facilitate an authorization of the user to access the resource using the client device over the in-band channel or the out-of-band channel, and 
 instructions to account for a transaction conducted by the user through the client device using the resource over the in-band channel or the out-of-band channel. 
   
     
     
         12 . The enclave device of  claim 11 , wherein:
 the in-band channel is opened over an in-band network and the out-of-band channel is opened over an out-of-band network;   the in-band network is at least one of a wireless network established over a licensed radio frequency band and a wired network;   the out-of-band network is a wireless network established over an unlicensed radio frequency band;   at least one of the in-band channel and the out-of-band channel is opened at one of a resource level, a resource flow level, and a network level; and   a virtual network is established over at least one of the in-band channel and the out-of-band channel.   
     
     
         13 . The enclave device of  claim 11 , further comprising:
 instructions to authenticate the user through a multi-factor authentication mechanism using at least one of the plurality of readers of the enclave device, wherein the multi-factor authentication mechanism comprises at least two of a near-field communication (NFC) identification mechanism, a biometric reader identification mechanism, a user name and password identification mechanism, a pattern matching identification mechanism, a global positioning system (GPS) identification mechanism, and a radio-frequency identification (RFID) mechanism.   
     
     
         14 . The enclave device of  claim 11 , further comprising:
 instructions to facilitate the authorization of the user to access the resource using the client device with further instructions to:
 generate a one-time encrypted software token (EST) through a trusted platform module (TPM), 
 send a hash of the one-time EST through at least one of the in-band channel and the out-of-band channel to the switch, and 
 authorize the user to access the resource based on a comparison of the hash of the one-time EST with a one-time EST independently generated by the switch. 
   
     
     
         15 . The enclave device of  claim 11 , wherein the interface to the client device is a physical interface that couples the enclave device to the client device through a physical connection. 
     
     
         16 . The enclave device of  claim 11 , wherein the interface to the client device is a radio interface that couples the enclave device to the client device through a radio frequency connection. 
     
     
         17 . A storage medium, readable through a processor, and including instructions embodied therein and configured to be executable through the processor, comprising:
 instructions to open an in-band channel or an out-of-band channel from a client device to a switch managing a network;   instructions to authenticate, through a reader communicatively coupled to the processor, a user of a resource over the in-band channel or the out-of-band channel;   instructions to facilitate an authorization of the user to access the resource over the in-band channel or the out-of-band channel; and   instructions to account for a transaction conducted by the user using the resource over the in-band channel or the out-of-band channel.   
     
     
         18 . The storage medium of  claim 17 , wherein:
 the in-band channel is opened over an in-band network and the out-of-band channel is opened over an out-of-band network;   the in-band network is at least one of a wireless network established over a licensed radio frequency band and a wired network;   the out-of-band network is a wireless network established over an unlicensed radio frequency band;   at least one of the in-band channel and the out-of-band channel is opened at one of a resource level, a resource flow level, and a network level; and   a virtual network is established over at least one of the in-band channel and the out-of-band channel.   
     
     
         19 . The storage medium of  claim 17 , further comprising:
 instructions to authenticate the user of the resource through a multi-factor authentication mechanism using the reader, wherein the multi-factor authentication mechanism comprises at least two of a near-field communication (NFC) identification mechanism, a biometric reader identification mechanism, a user name and password identification mechanism, a pattern matching identification mechanism, a global positioning system (GPS) identification mechanism, and a radio-frequency identification (RFID) mechanism.   
     
     
         20 . The storage medium of  claim 17 , further comprising:
 instructions to facilitate the authorization of the user to access the resource with further instructions to:
 generate a one-time encrypted software token (EST) through a trusted platform module (TPM), 
 send a hash of the one-time EST through at least one of the in-band channel and the out-of-band channel to the switch, and 
 authorize the user to access the resource based on a comparison of the hash of the one-time EST with a one-time EST independently generated by the switch.

Join the waitlist — get patent alerts

Track US2014189811A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.