Nova Patents
EP1775673A2

Token authentication system

Abstract

An apparatus, method and program product for enabling token authentication by generating a secret key using manufacturer controlled information (57) present on a token (34). A computer (30) typically reads the manufacturer controlled information and applies an cryptographic algorithm (41) to determine the secret key (47). The secret key (47) may comprise or be used to generate a one-time password (42) for use in authenticating the token (34). Typical manufacturer controlled information (57) present on the token (34) includes static, non-writeable/erasable information, such as a serial number (56) or manufacturer ID (54). Where desired, the token authentication is accomplished in the absence of memory or processors on the token that are dedicated to the authentication process, itself. This absence reduces token hardware requirements and associated expenses. The dynamic generation of the cryptographic key (47) also reduces risks conventionally associated with duplicating static keys stored within token memory. Where desired, token includes a password (55) and/or a user name (53) in addition to the manufacturer controlled information (57) for realizing multiple factor authentication. As such, the password (55) and user name (53) stored on the token (34) may automatically be transmitted to the access device (14).

EP1775673A2, drawing sheet 1
Sheet 1 of 4

Term

Projected expiry 16 October 2026.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

33 claims: 20 independent, 13 dependent

  1. 1
    A method of controlling user access with a token having fixed manufacturer controlled information, the method comprising determining the manufacturer controlled information from the token, generating a cryptographic key using the manufacturer controlled information of the token, and authenticating the token using the generated cryptographic key.
  2. 9
    The method of any preceding claim, wherein authenticating the token further comprises determining a look ahead value used for comparison of at least one of the cryptographic key and a value determined using the cryptographic key.
  3. 10
    The method of any preceding claim, wherein authenticating the token using the cryptographic key further includes receiving a user name.
  4. 12
    The method of any preceding claim, wherein determining the manufacturer controlled information further comprises determining the manufacturer controlled information from a flash drive.
  5. 13
    The method of any preceding claim, wherein generating the cryptographic key using the manufacturer controlled information further comprises applying a cryptographic algorithm to the manufacturer controlled information.
  6. 14
    The method of any preceding claim, wherein generating the cryptographic key using the manufacturer controlled information further comprises using a serial number.
  7. 15
    The method of any preceding claim, wherein generating the cryptographic key using the manufacturer controlled information further comprises using a manufacturer identifier.
  8. 16
    The method of any preceding claim, wherein generating the cryptographic key using the manufacturer controlled information further comprises using at least one of a product identifier, a date of manufacture and a model number.
  9. 17
    The method of any preceding claim, further comprising determining that at least one of the token and an authenticating computer has been compromised.
  10. 19
    The method of any preceding claim, wherein authenticating the cryptographic token further comprises authenticating at a computer that is remote from a device that receives the token.
  11. 20
    The method of any preceding claim, wherein authenticating the cryptographic token further comprises authenticating at a client computer.
  12. 21
    A method of controlling user access with random data stored within a memory of a token, the method comprising determining the random data from the token, generating a cryptographic key using the random data of the token, and authenticating the token using the generated cryptographic key.
  13. 22
    An apparatus, comprising a token having fixed manufacturer controlled information, and an access control device comprising a program resident in a memory, the program configured to determine the manufacturer controlled information from the token, to generate a cryptographic key using the manufacturer controlled information of the token, and to authenticate the token using the generated cryptographic key.
  14. 26
    The apparatus of any one of claims 22 to 25, further comprising at least one of a counter and a clock.
  15. 28
    The apparatus of any one of claims 22 to 27, wherein the program is further configured to determine a look ahead value used for comparison of at least one of the cryptographic key and a value determined using the cryptographic key.
  16. 29
    The apparatus of any one of claims 22 to 28, wherein the token comprises a flash drive.
  17. 30
    The apparatus of any one of claims 22 to 30, wherein the program is further configured to authenticate the token using multifactor data.
  18. 31
    The apparatus of any one of claims 22 to 30, wherein the manufacturer controlled information further comprises at least one of a serial number, a manufacturer identifier, a model number, and a date of manufacture.
  19. 32
    An access control device, comprising a token comprising a memory having random data, and a program resident in the memory, the program configured to determine the random data from the token, to generate a cryptographic key using the random data of the token, and to authenticate the token using the generated cryptographic key.
  20. 33
    A program product, comprising program code configured to determine fixed manufacturer controlled information from a token, to generate a cryptographic key using the manufacturer controlled information of the token, and to authenticate the token using the generated cryptographic key, and a signal bearing medium bearing the program code.
Independent claims20