US2020396212A1PendingUtilityA1

Distributed authentication

Assignee: HEWLETT PACKARD DEVELOPMENT COPriority: Mar 24, 2017Filed: Aug 28, 2020Published: Dec 17, 2020
Est. expiryMar 24, 2037(~10.7 yrs left)· nominal 20-yr term from priority
H04L 9/085H04L 9/3255H04L 9/3271H04L 9/0861H04L 63/062H04L 63/104H04L 63/0853G06F 2221/2103H04L 9/0891
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Examples associated with distributed authentication are described. One example includes generating a paired public key and private key associated with a user. The private key is split into a set of shares, which are distributed to a set of devices associated with the user. A challenge is generated to authenticate the user to grant the user access to a resource upon receiving an authenticating response to the challenge. The challenge is distributed to members of the set of devices. Partial responses are received from members of the set of devices and combined into a group signature. The group signature serves as an authenticating response to the challenge when generated from partial responses received from a threshold number of members of the set of devices.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A user device, comprising:
 a processor;   a non-transitory machine-readable storage device that stores instructions that are executable by the processor to:
 receive, from a dealer module, multiple shares of a distributed private key, the distributed private key being paired with a public key that is usable by an authentication module to authenticate a user; 
 receive, from a challenge module, a challenge to authenticate the user; 
 generate a partial response to the challenge based on the challenge and on the multiple shares of the distributed private key; and 
 provide the partial response to a combiner module, wherein:
 the combiner module generates a group signature from partial responses received from a set of user devices to the authentication module, and the group signature serves as an authenticating response to the challenge when generated from partial responses received from members of the set of devices. 
 
   
     
     
         2 . The user device of  claim 1 , wherein one of the dealer module, the challenge module, and the combiner module are implemented by the user device. 
     
     
         3 . The user device of  claim 1 , wherein the group signature is a message that would be produced by signing the challenge with the distributed private key. 
     
     
         4 . The user device of  claim 1 , wherein the dealer module provides multiple verification values to the user device, each verification value corresponding to one of the multiple shares of the distributed private key, and wherein the combiner module uses the multiple verification values to verify validity of the partial response received from the user device before generating the group signature. 
     
     
         5 . The user device of  claim 4 , wherein one of the verification values received by the user device corresponding to one of the multiple shares of the distributed private key has been indicated as deprovisioned by the dealer module, and wherein the combiner module does not use the partial response provided by the user device, or a portion thereof, that corresponds to the deprovisioned verification value to generate the complete response. 
     
     
         6 . The user device of  claim 5 , wherein the deprovisioned verification value was deprovisioned based on a new user device being added to the set of user devices. 
     
     
         7 . A method, comprising:
 receiving, by a user device, multiple shares of a distributed private key, where the distributed private key is paired with a public key used by an authentication module to authenticate a user;   receiving, from the authentication module, a challenge to authenticate the user;   generating a partial response to the challenge based on the challenge and on the multiple shares;   receiving a partial response from a second device of the set of user devices, the received partial response based on a different share of the distributed private key; and   based on the received partial response satisfying a criterion:
 generating a group signature, and 
 transmitting the group signature to the authentication module. 
   
     
     
         8 . The method of  claim 7 , wherein the set of user devices includes a mobile device of the user, a laptop of the user, a wearable smart device of the user, a device belonging to another user, or an environmental device. 
     
     
         9 . The method of  claim 7 , wherein generating the group signature comprises generating the group signature using the generated partial response and a subset of multiple partial responses received from other user devices of the set of user devices. 
     
     
         10 . The method of  claim 9 , wherein the criterion includes the subset of the multiple partial responses being received from different devices of the set of user devices than other partial responses of the subset of multiple partial responses. 
     
     
         11 . The method of  claim 9 , wherein the criterion includes the subset of the received partial responses being received from a subset of the other user devices of the set of user devices that each belong to a different user than each of the other user devices of the subset of the other user devices. 
     
     
         12 . The method of  claim 9 , wherein the criterion includes the subset of the partial responses being received from a threshold number of other user devices of the set of user devices that are detected as being present in an environment associated with a resource accessible by the user once the user is authenticated by the authentication module. 
     
     
         13 . A tangible, non-transitory computer-readable medium storing computer-readable instructions executable to cause a processor to:
 receive, by a user device, multiple shares of a distributed private key;   receive a challenge seeking to authenticate a group of users;   generate partial responses to the challenge based on the multiple shares;   receive partial responses from other devices associated with other users of the group, each generated based on a different share of the distributed private key;   select a subset of all of the partial responses;   generate a group signature based on the selected subset; and   transmit the group signature to an authentication module to cause the authentication module to authenticate the group of users using a public key paired to the distributed private key.   
     
     
         14 . The non-transitory computer-readable medium of  claim 13 , wherein the group signature is generated further based on the generated partial responses, and wherein the group signature authenticates multiple members of the group of users whose associated devices generated partial responses used in generating the authenticating group signature. 
     
     
         15 . The non-transitory computer-readable medium of  claim 13 , wherein less than all existing shares of the distributed private key may be used to authenticate the group of users. 
     
     
         16 . The non-transitory computer-readable medium of  claim 13 , wherein the user device comprises a mobile device, a laptop, a wearable smart device, or an environmental device. 
     
     
         17 . The non-transitory computer-readable medium of  claim 13 , wherein the selected partial responses of the subset each correspond to a different member of the group. 
     
     
         18 . The non-transitory computer-readable medium of  claim 13 , wherein the selected partial responses of the subset each correspond to one of the other devices that is detected as being collocated with a particular user of the group. 
     
     
         19 . The non-transitory computer-readable medium of  claim 13 , wherein each of the other devices associated with the other users of the group receives the challenge seeking to authenticate the group of users from the user device prior to transmitting their respective partial responses to the user device. 
     
     
         20 . The non-transitory computer-readable medium of  claim 13 , wherein the partial responses of the subset are selected based on the selected partial responses indicating participation of a quorum of members of the group.

Join the waitlist — get patent alerts

Track US2020396212A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.