US2015195276A1PendingUtilityA1

System and Method For Securely Provisioning and Generating One-Time-Passwords In A Remote Device

Assignee: BROADCOM CORPPriority: Sep 21, 2005Filed: Mar 24, 2015Published: Jul 9, 2015
Est. expirySep 21, 2025(expired)· nominal 20-yr term from priority
G06F 21/31H04L 63/0428H04L 63/0838H04L 63/083H04L 63/0853
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A secure processor such as a TPM generates one-time-passwords used to authenticate a communication device to a service provider. In some embodiments the TPM maintains one-time-password data and performs the one-time-password algorithm within a secure boundary associated with the TPM. In some embodiments the TPM generates one-time-password data structures and associated parent keys and manages the parent keys in the same manner it manages standard TPM keys.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An apparatus comprising:
 a data memory;   a secure processor configured to:
 maintain a security boundary, and 
 execute a one-time password algorithm within the security boundary to generate a first one-time password using a shared secret, 
 wherein the shared secret is received from a binary large object (blob) structure in the data memory; and 
   a memory manager, external to the secure processor, configured to manage the data memory.   
     
     
         2 . The apparatus of  claim 1 , wherein the secure processor is further configured to send the first one-time password to a verification server to access a service or data. 
     
     
         3 . The apparatus of  claim 1 , wherein the secure processor is further configured to receive a second one-time password from a device and perform a comparison operation to determine whether the second one-time password from the device matches the first one-time password. 
     
     
         4 . The apparatus of  claim 3 , wherein the secure processor is further configured to permit the device to access a service or data based on the comparison operation determining that the second one-time password from the device matches the first one-time password. 
     
     
         5 . The apparatus of  claim 3 , wherein the device is a wireless phone. 
     
     
         6 . The apparatus of  claim 1 , wherein the secure processor comprises a plurality of cryptographic processors. 
     
     
         7 . The apparatus of  claim 1 , wherein the security boundary is protected by tamperproof or tamper evident hardware. 
     
     
         8 . The apparatus of  claim 1 , wherein the shared secret comprises a key. 
     
     
         9 . The apparatus of  claim 1 , wherein the shared secret comprises a credential. 
     
     
         10 . The apparatus of  claim 1 , wherein the shared secret comprises a seed value, a time variant value, or a count. 
     
     
         11 . The apparatus of  claim 1 , wherein the one-time password algorithm comprises a hashing algorithm. 
     
     
         12 . The apparatus of  claim 1 , wherein the one-time password algorithm comprises a time-based algorithm. 
     
     
         13 . The apparatus of  claim 1 , wherein the secure processor is further configured to encrypt the first one-time password using a private key of the secure processor. 
     
     
         14 . The apparatus of  claim 1 , wherein the secure processor is further configured to encrypt the shared secret to maintain the shared secret within the security boundary of the secure processor. 
     
     
         15 . The apparatus of  claim 1 , wherein the first one-time password is combined with a user credential or the shared secret. 
     
     
         16 . The apparatus of  claim 1 , wherein the blob structure comprises a one-time password identifier, a public key, or a definition for the one-time password algorithm. 
     
     
         17 . An apparatus comprising:
 a data memory;   a secure processor configured to:
 maintain a security boundary, 
 decrypt a binary large object (blob) structure stored in the data memory to retrieve a shared secret, and 
 execute a one-time password algorithm within the security boundary to generate a first one-time password using the shared secret; and 
   a memory manager, external to the secure processor, configured to manage the data memory.   
     
     
         18 . The apparatus of  claim 17 , wherein the secure processor is further configured to send the first one-time password to a verification server to access a service or data. 
     
     
         19 . An apparatus comprising:
 a data memory;   a secure processor configured to:
 maintain a security boundary, 
 decrypt a binary large object (blob) structure stored in the data memory to retrieve a shared secret, 
 execute a one-time password algorithm within the security boundary to generate a first one-time password using the shared secret, 
 receive a second one-time password from a device, and 
 perform a comparison operation to determine whether the second one-time password from the device matches the first one-time password; and 
   a memory manager, external to the secure processor, configured to manage the data memory.   
     
     
         20 . The apparatus of  claim 19 , wherein the secure processor is further configured to permit the device to access a service or data based on the comparison operation determining that the second one-time password from the device matches the first one-time password.

Join the waitlist — get patent alerts

Track US2015195276A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.