Nova Patents
EP1846830B1

Access keys

Abstract

This record has no abstract on file.

EP1846830B1, drawing sheet 1
Sheet 1 of 10

Term

Term ended

Expired 20 December 2025, 0.8 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

14 claims: 3 independent, 11 dependent

  1. 1
    A machine-implemented method, implemented at a secure module (102, 402, 600, 700), the secure module (102) being part of a self-contained device that is plugged into a host computer (126, 404) and is for acquiring user data and the secure module including a secure area (106), the secure area (106) comprising access key circuitry having a memory (110), the memory (110) including access keys (122) and instructions (112) for generating a passcode, the method comprising:receiving user data from a user and authenticating the user data;sending (1002) to the host computer a request to perform a task, whereby performing the task requires an access key, receiving a passcode (306) from the host computer;authenticating (1006) the host computer by comparing the passcode (306) received to a passcode generated by instructions (112) for generating the passcode;if the host computer is authenticated, then retrieving the access key from the memory (110) and sending the access key to the host computer (126), and, optionally, generating a new passcode and sending the new passcode to the host computer (126);wherein, if the method does not comprise generating and sending a new passcode to the host computer (126), the host computer (126) is adapted to generate a new passcode from the access key;and wherein the new passcode is not stored on the secure module (102, 402, 600, 700) after the sending of the new passcode (306) to the host computer (126).
  2. 9
    A machine-implemented method, implemented by a host computer (128), the host computer (126) being connected to a plugged-in secure module (102), the memory (206) including a passcode (306) and instructions (304) for performing a task that requires an access key (122), the method comprising:receiving from the secure module (102), a request to perform the task (128, 304) at a host computer (126);in response to the request, sending the passcode (306) to the secure module (102);receiving from the secure module (102) an access key (122) and optionally a new passcode;if no new passcode is received, generating a new passcode based on the received access key (122), and storing the new passcode;wherein the secure module (102) is adapted to send the request in response to a user entering user data and the user data being authenticated, and wherein, if the secure module (102) is adapted to generate and send the new passcode, it is adapted to not store the new passcode after sending the new passcode to the host computer (126) and the secure module (102) is adapted to verify the received passcode by comparing the received passcode to a passcode generated by instructions for generating a passcode.
  3. 14
    The secure module of one of claims 11 to 13 further comprising:an acquisition mechanism (104, 502, 604, 706) for acquiring user data;and an interface for sending the encryption keys (122) to and receiving passcodes (306) from another system (126);the circuitry (106) also including a memory (110) storing instructions for acquiring the user data, storing user information (120) that is based on the user data, acquired during set up, and comparing the user information (120) with user data acquired while requesting access.