US2016314294A1PendingUtilityA1
Secure unattended network authentication
Est. expiryApr 24, 2035(~8.7 yrs left)· nominal 20-yr term from priority
G06F 21/44H04L 63/18H04L 63/0853G06F 21/42
45
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A system for secure network access by unattended devices is described. The system describes how unattended devices that have encrypted data at rest and/or require secure authentication to an open network may procure the access credentials for authentication and/or decryption. With these access credentials, then the unattended devices may exchange information with and/or receive updates from servers on the network.
Claims
exact text as granted — not AI-modified1 . A system, comprising:
an unattended first device comprising:
a first communication interface;
a first control system communicatively coupled to the first communication interface and comprising at least one first hardware processor and a first memory storing program codes operable to:
send a request to the second device for access credentials;
receive the access credentials;
send the access credentials to the fourth device; and
if the access credentials is validated,
exchange information with the fourth device.
a second device comprising:
a second communication interface;
a second secured storage element;
a second control system communicatively coupled to the second communication interface and comprising at least one second hardware processor and a second memory storing program codes operable to:
receive a request for the access credentials from the first device;
send a request for the access credentials to the third device;
exchange pairing credentials with the third device to authenticate with the third device;
if authenticated with the third device, receive the access credentials; and
send the access credentials to the first device;
a third device comprising:
a third communication interface;
a third control system communicatively coupled to the third communication interface and comprising at least one third hardware processor and a third memory storing program codes operable to:
receive a request for the access credentials from the second device;
exchange pairing credentials with the second device to authenticate with the second device;
if authenticated with the second device, send the access credentials to the second device; and
a fourth device comprising:
a fourth communication interface;
a fourth control system communicatively coupled to the fourth communication interface and comprising at least one fourth hardware processor and a fourth memory storing program codes operable to:
receive access credentials from the first device;
validate the access credentials; and
if validated, exchange information with the first device.
2 . The system of claim 1 , wherein the second device is internal to the first device.
3 . The system of claim 1 , further comprising the first device using the access credentials to decrypt an encrypted file system.
4 . The system of claim 1 , wherein the information exchanged between the fourth device and the first device comprises one of the group consisting of: information to update software on the first device, information to update firmware on the first device, information to update applications on the first device, information to update program codes on the first device, information to make configuration setting changes on the first device, information to update the operating system on the first device, and information pertaining to customer data.
5 . The system of claim 1 , wherein the pairing credentials stored in the second device are stored in a tamper resistant manner.
6 . The system of claim 5 , wherein the tamper resistant manner comprises use of potted material which would destroy one or more components of the second device upon removal.
7 . The system of claim 1 , wherein the pairing credentials stored in the second device are stored in a manner to provide for tamper detection.
8 . The system of claim 7 , wherein the manner to provide for tamper detection comprises one of the group consisting of: detection of ultraviolet fluorescent chemicals, detection of varying temperature, detection of varying clocking information, detection of varying voltage, and detection of varying electrical signals.
9 . The system of claim 7 , wherein the second device, upon tamper detection, is further operable to:
report the detected tampering; and disable one or more components of the second device.
10 . The system of claim 1 , wherein the pairing credentials are stored according to National Institute of Standards and Technology (NIST) standards.
11 . The system of claim 1 , wherein the pairing credentials exchanged between the second and third device are exchanged by out-of-band means.
12 . The system of claim 11 , wherein the out-of-band means comprises one of the group consisting of: direct user input at the second and third devices, use of a thumb drive at the second and third devices, use of a universal serial bus (USB) cable between the second and third device, or use of wired Ethernet cable between the second and third device.
13 . The system of claim 1 , wherein the pairing credentials exchanged between the second and third device are exchanged by use of a wireless communication channel.
14 . The system of claim 13 , wherein the wireless communication channel comprises one of the group consisting of: Bluetooth and a near field communication (NFC).
15 . The system of claim 14 , wherein the wireless communication channel is secured with an encryption algorithm.
16 . The system of claim 1 , wherein the second device is a dock for the first device with at least one mechanism for providing user level authentication, wherein the mechanism for providing user level authentication is selected from the group consisting of: a common access card (CAC) reader, a touchscreen, a keypad, and a display for password entry.
17 . The system of claim 1 , wherein the access credentials comprise one of a group consisting of: a one-time password, a symmetric key, a public key along with its private key, and a public key cryptography standard (PKCS) certificate.
18 . The system of claim 1 , wherein the second device is further operable to:
send a pairing request with initial credentials to the third device; receive an acceptance of the pairing request form the third device; and exchange pairing credentials with the third device.
19 . The system of claim 1 , wherein the third device is further operable to:
receive a pairing request with initial credentials from the second device; send an acceptance of the pairing request to the second device; and exchange pairing credentials with the second device.
20 . The system of claim 1 , wherein the second device is further operable to:
store the access credentials.Join the waitlist — get patent alerts
Track US2016314294A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.