US2015195276A1PendingUtilityA1
System and Method For Securely Provisioning and Generating One-Time-Passwords In A Remote Device
Est. expirySep 21, 2025(expired)· nominal 20-yr term from priority
G06F 21/31H04L 63/0428H04L 63/0838H04L 63/083H04L 63/0853
51
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A secure processor such as a TPM generates one-time-passwords used to authenticate a communication device to a service provider. In some embodiments the TPM maintains one-time-password data and performs the one-time-password algorithm within a secure boundary associated with the TPM. In some embodiments the TPM generates one-time-password data structures and associated parent keys and manages the parent keys in the same manner it manages standard TPM keys.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An apparatus comprising:
a data memory; a secure processor configured to:
maintain a security boundary, and
execute a one-time password algorithm within the security boundary to generate a first one-time password using a shared secret,
wherein the shared secret is received from a binary large object (blob) structure in the data memory; and
a memory manager, external to the secure processor, configured to manage the data memory.
2 . The apparatus of claim 1 , wherein the secure processor is further configured to send the first one-time password to a verification server to access a service or data.
3 . The apparatus of claim 1 , wherein the secure processor is further configured to receive a second one-time password from a device and perform a comparison operation to determine whether the second one-time password from the device matches the first one-time password.
4 . The apparatus of claim 3 , wherein the secure processor is further configured to permit the device to access a service or data based on the comparison operation determining that the second one-time password from the device matches the first one-time password.
5 . The apparatus of claim 3 , wherein the device is a wireless phone.
6 . The apparatus of claim 1 , wherein the secure processor comprises a plurality of cryptographic processors.
7 . The apparatus of claim 1 , wherein the security boundary is protected by tamperproof or tamper evident hardware.
8 . The apparatus of claim 1 , wherein the shared secret comprises a key.
9 . The apparatus of claim 1 , wherein the shared secret comprises a credential.
10 . The apparatus of claim 1 , wherein the shared secret comprises a seed value, a time variant value, or a count.
11 . The apparatus of claim 1 , wherein the one-time password algorithm comprises a hashing algorithm.
12 . The apparatus of claim 1 , wherein the one-time password algorithm comprises a time-based algorithm.
13 . The apparatus of claim 1 , wherein the secure processor is further configured to encrypt the first one-time password using a private key of the secure processor.
14 . The apparatus of claim 1 , wherein the secure processor is further configured to encrypt the shared secret to maintain the shared secret within the security boundary of the secure processor.
15 . The apparatus of claim 1 , wherein the first one-time password is combined with a user credential or the shared secret.
16 . The apparatus of claim 1 , wherein the blob structure comprises a one-time password identifier, a public key, or a definition for the one-time password algorithm.
17 . An apparatus comprising:
a data memory; a secure processor configured to:
maintain a security boundary,
decrypt a binary large object (blob) structure stored in the data memory to retrieve a shared secret, and
execute a one-time password algorithm within the security boundary to generate a first one-time password using the shared secret; and
a memory manager, external to the secure processor, configured to manage the data memory.
18 . The apparatus of claim 17 , wherein the secure processor is further configured to send the first one-time password to a verification server to access a service or data.
19 . An apparatus comprising:
a data memory; a secure processor configured to:
maintain a security boundary,
decrypt a binary large object (blob) structure stored in the data memory to retrieve a shared secret,
execute a one-time password algorithm within the security boundary to generate a first one-time password using the shared secret,
receive a second one-time password from a device, and
perform a comparison operation to determine whether the second one-time password from the device matches the first one-time password; and
a memory manager, external to the secure processor, configured to manage the data memory.
20 . The apparatus of claim 19 , wherein the secure processor is further configured to permit the device to access a service or data based on the comparison operation determining that the second one-time password from the device matches the first one-time password.Join the waitlist — get patent alerts
Track US2015195276A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.