US2015058620A1PendingUtilityA1

Proximity Authentication System

Assignee: BROADCOM CORPPriority: Sep 30, 2003Filed: Jul 30, 2014Published: Feb 26, 2015
Est. expirySep 30, 2023(expired)· nominal 20-yr term from priority
G07C 9/20H04W 4/80H04L 2209/805H04L 9/32H04L 63/0853H04W 4/021H04L 63/0861G06F 21/35H04L 63/0823H04L 63/0492H04L 63/0807G06Q 20/327H04W 4/008
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An authorized user may be provided access to a service only when a wireless token assigned to the user is in the proximity of a computing device. A user's credential may be stored on an RFID token and an RFID reader may be implemented within a security boundary on the computing device. Thus, the credential may be passed to the security boundary without passing through the computing device via software messages or applications. The security boundary may be provided, in part, by incorporating the RFID reader onto the same chip as a cryptographic processing component. Once the information is received by the RFID reader it may be encrypted within the chip. As a result, the information may never be presented in the clear outside of the chip. The cryptographic processing component may cryptographically encrypt/sign the credential received from the token.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . An apparatus, comprising:
 a proximity reader within a security boundary, the proximity reader configured to wirelessly receive a signal from a proximate device;   a secure processor within the security boundary, the secure processor configured to cryptographically sign or encrypt a credential for transmission to a service provider system in response to the proximity reader receiving the signal from the proximate device; and   an interface configured to send the cryptographically signed or encrypted credential to the service provider system to gain access to a secure service provided by the service provider system,   wherein the security boundary comprises a physical boundary and a cryptographic boundary and is configured to prevent software that is executing external to the physical boundary and the cryptographic boundary from accessing the credential.   
     
     
         3 . The apparatus of  claim 2 , further comprising a keyboard configured to receive a password. 
     
     
         4 . The apparatus of  claim 3 , wherein the interface is further configured to send the password to the service provider system to gain access to the secured service. 
     
     
         5 . The apparatus of  claim 2 , further comprising a biometric reader configured to read a biometric identifying characteristic. 
     
     
         6 . The apparatus of  claim 5 , wherein the interface is further configured to send the biometric identifying characteristic to the service provider system to gain access to the secured service. 
     
     
         7 . The apparatus of  claim 1 , further comprising a database configured to store a default service provider associated with the proximate device. 
     
     
         8 . The apparatus of  claim 1 , wherein the secure processor is configured to determine the service provider system by looking up in a database the default service provider system associated with the proximate device. 
     
     
         9 . The apparatus of  claim 1 , wherein the secured service is for performing a sales transaction. 
     
     
         10 . The apparatus of  claim 1 , wherein the credential includes credit card information. 
     
     
         11 . An apparatus, comprising:
 a proximity reader within a security boundary, the proximity reader configured to wirelessly receive a signal from a proximate device that includes identity information of the proximate device;   a processor within the security boundary, the processor configured to determine a service provider system based on the identity information of the proximate device and cryptographically sign or encrypt a credential for transmission to the service provider system; and   an interface configured to send the cryptographically signed or encrypted credential to the service provider system to gain access to a secure service provided by the service provider system,   wherein the security boundary comprises a physical boundary and a cryptographic boundary and is configured to prevent software that is executing external to the physical boundary and the cryptographic boundary from accessing the credential.   
     
     
         12 . The apparatus of  claim 11 , further comprising a keyboard configured to receive a password. 
     
     
         13 . The apparatus of  claim 12 , wherein the interface is further configured to send the password to the service provider system to gain access to the secured service. 
     
     
         14 . The apparatus of  claim 11 , further comprising a biometric reader configured to read a biometric identifying characteristic. 
     
     
         15 . The apparatus of  claim 14 , wherein the interface is further configured to send the biometric identifying characteristic to the service provider system to gain access to the secured service. 
     
     
         16 . The apparatus of  claim 11 , wherein the secured service is for performing a sales transaction. 
     
     
         17 . The apparatus of  claim 11 , wherein the credential includes credit card information. 
     
     
         18 . A method, comprising:
 wirelessly receiving, using a proximity reader within a security boundary, a signal from a proximate device;   cryptographically signing or encrypting a credential, using a secure processor within the security boundary, for transmission to a service provider system in response to receiving the signal from the proximate device; and   sending the cryptographically signed or encrypted credential to the service provider system to gain access to a secure service provided by the service provider system,   wherein the security boundary comprises a physical boundary and a cryptographic boundary and is configured to prevent software that is executing external to the physical boundary and the cryptographic boundary from accessing the credential.   
     
     
         19 . The method of  claim 18 , further comprising:
 determining the service provider system by looking up in a database the default service provider system associated with the proximate device.   
     
     
         20 . The method of  claim 18 , wherein the secured service is for performing a sales transaction. 
     
     
         21 . The method of  claim 18 , wherein the credential includes credit card information.

Join the waitlist — get patent alerts

Track US2015058620A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.