US2021084030A1PendingUtilityA1

One-time-password generated on reader device using key read from personal security device

Assignee: ASSA ABLOY ABPriority: Jul 8, 2013Filed: Oct 7, 2020Published: Mar 18, 2021
Est. expiryJul 8, 2033(~6.9 yrs left)· nominal 20-yr term from priority
G06F 21/34H04L 63/06H04L 9/0863G06F 21/35H04L 9/3234H04L 63/10H04L 63/0838
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An authentication system is provided using one-time passwords (OTPs) for user authentication. An OTP key may be stored on a different device than the device on which the OTP is generated. In an embodiment, the system described herein enables a combined authentication system, including the two separate devices communicating over a non-contact interface, to provide advantageous security features compared to the use of a single device, such as a hardware OTP token. One device may be a personal security device and the other device may be a reader device coupled to a host device via which access is being controlled.

Claims

exact text as granted — not AI-modified
1 . A method for access control using a personal security device (PSD) of a user, comprising:
 providing the PSD with a one-time-password (OTP) key;   interfacing a reader device, coupled to a host device, with the PSD;   authenticating the reader device to the PSD, wherein the OTP key is only readable from the PSD by the reader device when the reader device is authenticated and a secure channel is established between the PSD and a reader device;   transferring the OTP key from the PSD to the reader device over the secure channel;   generating an OTP at the reader device using the OTP key transferred to the reader device from the PSD; and   passing the OTP from the reader device to the host device or a validation system connected to the host device for validation.   
     
     
         2 . The method according to  claim 1 , further comprising:
 validating the OTP and granting access to the user.   
     
     
         3 . The method according to  claim 1 , further comprising:
 clearing the OTP key from the reader device.   
     
     
         4 . The method according to  claim 1 , further comprising at least one of:
 (i) sending counter data from the PSD to the reader device;   (ii) sending counter data or incremented counter data from the reader device to the PSD after an access decision; or   (iii) storing counter data on the reader device before or after an access decision.   
     
     
         5 . The method according to  claim 1 , wherein the PSD is at least one of: a smart card, a token or a mobile phone. 
     
     
         6 . The method according to  claim 1 , wherein the PSD is a secure memory storage card that has authentication capabilities and no exposed crypto functions beyond memory access authentication. 
     
     
         7 . The method according to  claim 1 , wherein the OTP is generated at the reader device in a secure environment of the reader device. 
     
     
         8 . The method according to  claim 1 , wherein the PSD is provided with the OTP key at least one of: at a time of manufacture of the PSD or during a field revision of the PSD. 
     
     
         9 . The method according to  claim 1 , wherein the interfacing of the reader device and the PSD is via a non-contact interface. 
     
     
         10 . A non-transitory computer readable medium storing software for access control using a personal security device (PSD) of a user, the software comprising:
 executable code that stores a one-time-password (OTP) key on the PSD;   executable code that controls interfacing of a reader device, coupled to a host device, with the PSD;   executable code that authenticates the reader device to the PSD, wherein the OTP key is only readable from the PSD by the reader device when the reader device is authenticated and a secure channel is established between the PSD and a reader device;   executable code that transfers the OTP key from the PSD to the reader device over the secure channel;   executable code that generates an OTP at the reader device using the OTP key transferred to the reader device from the PSD; and   executable code that passes the OTP from the reader device to the host device or a validation system connected to the host device for validation.   
     
     
         11 . The non-transitory computer readable medium according to  claim 10 , wherein the software further comprises:
 executable code that validates the OTP and grants access to the user.   
     
     
         12 . The note-transitory computer readable medium according to  claim 10 , further comprising:
 executable code that clears the OTP key from the reader device.   
     
     
         13 . The non-transitory computer readable medium according to  claim 10 , further comprising at least one of:
 (i) executable code that sends counter data from the PSD to the reader device;   (ii) executable code that sends counter data or incremented counter data from the reader device to the PSD after an access decision; or   (iii) executable code that stores counter data on the reader device before or after an access decision.   
     
     
         14 . The non-transitory computer readable medium according to  claim 10 , wherein the PSD is at least one of a smart card, a token or a mobile phone. 
     
     
         15 . The non-transitory computer readable medium according to  claim 10 , wherein the PSD is a secure memory storage card that has authentication capabilities and no exposed crypto functions beyond memory access authentication. 
     
     
         16 . The non-transitory computer readable medium according to  claim 10 , wherein the OTP is generated at the reader device in a secure environment of the reader device. 
     
     
         17 . The non-transitory computer readable medium according to  claim 10 , wherein the PSD is provided with the OTP key at least one of: at a time of manufacture of the PSD or during a field revision of the PSD. 
     
     
         18 . The non-transitory computer readable medium according to  claim 10 , wherein the interfacing of the reader device and the PSD is via a non-contact interface. 
     
     
         19 . A system for access control using a personal security device (PSD) of a user, comprising:
 the PSD;   a non-contact field reader device coupled to a host device; and at least one processor that reads software stored on at least one computer readable medium, the software comprising:
 executable code that stores a one-time-password (OTP) key on the PSD; 
 executable code that controls interfacing of a reader device, coupled to the host device, with the PSD; 
 executable code that authenticates the reader device to the PSD, wherein the OTP key is only readable from the PSD by the reader device when the reader device is authenticated and a secure channel is established between the PSD and a reader device; 
 executable code that transfers the OTP key from the PSD to the reader device over the secure channel; 
 executable code that generates an OTP at the reader device using the OTP key transferred to the reader device from the PSD; and 
 executable code that passes the OTP from the reader device to the host device or a validation system connected to the host device for validation. 
   
     
     
         20 . The system according to  claim 19 , wherein the software further comprises at least one of:
 (i) executable code that validates the OTP and grants access to the user;   (ii) executable code that clears the OTP key from the reader device;   (iii) executable code that sends counter data from the PSD to the reader device;   (iv) executable code that sends counter data or incremented counter data from the reader device to the PSD after an access decision; or   (v) executable code that stores counter data on the reader device before or after an access decision.

Join the waitlist — get patent alerts

Track US2021084030A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.