Method and system for using location information acquired from gps for secure authentication
Abstract
Secure functions may be accessed via an authentication process utilizing a password that may be generated within a chip integrated on a device. The password may be unique per chip location, per challenge and/or per chip. The location of the chip may be determined based on GPS information and securely stored and securely communicated to an external entity. Two or more of the chip location, a generated random number sample and a key from a table of keys may be passed to a hash function that may generate a password. An external entity attempting access may be challenged to respond with a password that matches the password generated by the hash function. The response may be compared with the password generated by the hash function and access to one or more secure functions may be granted based on the comparison.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for processing data in a communication system involving a challenge, comprising:
receiving, by a first device, a first password from a second device in response to said challenge; determining, by said first device, whether said first password matches a second password that is unique per a location of a chip and per said challenge, said chip being integrated within said first device; and granting, by said first device, access to said second device to a secure function controlled by said first device when said first password matches said second password.
2 . The method according to claim 1 , wherein in said determining comprises:
passing two or more of: said chip location, a random number sample and a key from a table of keys to a hash function; and generating said second password by operating upon said two or more of: said chip location, said random number sample and said key from said table of keys in accordance with said hash function.
3 . The method according to claim 1 , further comprising:
challenging, by said first device, said second device to provide said first password.
4 . The method according to claim 1 , further comprising:
generating said second password based on a random number sample from a random number generator (RNG).
5 . The method according to claim 1 , further comprising:
determining said location of said chip based on global positioning system (GPS) information.
6 . The method according to claim 1 , further comprising:
authenticating, by said first device, said second device when said first password matches said second password.
7 . A system for processing data in a communication system, comprising:
a chip integrated in a first device; and an authentication subsystem, integrated in said first device, configured to:
receive a first password from a second device in response to a challenge,
determine whether said first password matches a second password that is unique per a location of said chip and per said challenge, and
grant access to said second device to a secure function controlled by said first device when said first password matches said second password.
8 . The system according to claim 7 , wherein said authentication subsystem is configured to pass two or more of: said chip location, a random number sample and a key from a table of keys to a hash function and to operate upon said two or more of: said chip location, said random number sample and said key from said table of keys in accordance with said hash function to generate said second password.
9 . The system according to claim 7 , wherein said authentication subsystem is further configured to challenge said second device to provide said first password.
10 . The system according to claim 7 , further comprising:
a random number generator (RNG) configured to generate a random number sample, wherein said chip is configured to generating said second password based on said random number sample.
11 . The system according to claim 7 , further comprising:
a global positioning system (GPS) receiver configured to determine said location of said chip based on GPS information; and a secure storage unit configured to securely store said location of said chip in a region that is inaccessible by said second device.
12 . The system according to claim 7 , wherein said authentication subsystem is further configured to authenticate said second device when said first password matches said second password.
13 . The system according to claim 7 , wherein said first device is implemented as part of a set-top box (STB),
wherein said second device is implemented as part of a service provider network, wherein the service provider network being configured to transmit audio data or video data to the STB.
14 . A system for processing data in a communication system, comprising:
a chip integrated in a first device; and an authentication subsystem, integrated in said first device, configured to:
challenge a second device to provide a first password in response to a challenge,
determine whether said first password matches a second password that is unique per a location of said chip and per said challenge, and
authenticate said second device when said first password matches said second password.
15 . The system according to claim 14 , wherein said authentication subsystem is configured to pass two or more of said chip location, a random number sample and a key from a table of keys to a hash function and to operate upon said two or more of: said chip location, said random number sample and said key from said table of keys in accordance with said hash function to generate said second password.
16 . The system according to claim 14 , wherein said authentication subsystem is further configured to receive said first password from said second device in response to said challenge.
17 . The system according to claim 14 , further comprising:
a random number generator (RNG) configured to generate a random number sample, wherein said chip is configured to generating said second password based on said random number sample.
18 . The system according to claim 14 , wherein said authentication subsystem is further configured to grant access to said server to a secure function controlled by said terminal device when said first password matches said second password.
19 . The system according to claim 14 , further comprising:
a global positioning system (GPS) receiver configured to determine said location of said chip based on GPS information; and a secure storage unit configured to securely store said location of said chip in a region that is inaccessible by said second device.
20 . The system according to claim 14 , wherein said first device is implemented as part of a set-top box (STB),
wherein said second device is implemented as part of a service provider network, wherein the service provider network being configured to transmit audio data or video data to the STB.Join the waitlist — get patent alerts
Track US2015012936A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.