EP1881663A1

Management of multiple connections to a security token access device

Abstract

A security token access device, a user device such as a computing device or communications device, and a method for managing multiple connections between multiple user devices and the access device. The access device maintains connection information, including security information, for each user device securely paired with the access device. Each time a new user device is paired with the access device, the access device transmits a notification to the user devices already paired to the user device. A user may provide instructions to the access device to terminate a pairing with one of the user devices by overwriting at least a portion of the connection information associated with the designated user device. A user device may further request a listing of all user devices currently paired with the access device.

EP1881663A1, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Projected expiry passed 17 July 2026, 0.2 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

23 claims: 13 independent, 10 dependent

  1. 1
    A user device adapted to communicate with a security token access device over a wireless link, the access device being adapted to communicate with a plurality of user devices and to be paired with at least one of the plurality of user devices, and further being adapted to maintain connection information relating to each of the plurality of user devices paired with the access device, the user device comprising:means adapted to receive a signal from the access device comprising a notification that another user device has been paired with the access device, the access device comprising a store comprising connection information, a portion of the connection information comprising security information associated with the user device;means adapted to receive an instruction from a user to terminate the pairing between the another user device and the access device;means adapted to transmit a signal to the access device to instruct the access device to terminate the pairing with the another user device, such that the access device terminates the pairing by overwriting at least the portion of the connection information relating to the another user device.
  2. 4
    The user device of any one of the preceding claims, wherein the wireless link over which the user device is adapted to communicate with the access device comprises a wireless link secured with a secure pairing key associated with the user device, and wherein the access device is adapted to be paired with at least one of the plurality of user devices using a secure pairing key associated with the at least one of the plurality of user devices, such that the portion of connection information comprises any secure pairing key associated with at least one of the plurality of user devices.
  3. 5
    The user device of any one of claims 1 to 4, wherein the user device is a mobile communication device.
  4. 6
    A security token access device adapted to wirelessly communicate with a plurality of user devices, comprising:means adapted to enter into a pairing with each of a plurality of user devices;means adapted to store and maintain connection information relating to each of the plurality of user devices thus paired;means adapted to receive, from one of the plurality of user devices thus paired, an instruction to terminate a pairing with another one of the plurality of user devices;means adapted to terminate a pairing with the another one of the plurality of user devices upon receipt of an instruction to terminate the pairing, the means adapted to terminate the pairing further being adapted to overwrite at least a portion of the connection information relating to the another one of the plurality of user devices for which the pairing is to be terminated.
  5. 9
    The access device of any one of claims 6 to 8, wherein the pairing with each of a plurality of user devices is a secure pairing associated with security information, and the portion of connection information comprises the security information.
  6. 12
    The access device of any one of claims 9 to 11, wherein the connection information further comprises a connection pairing key and an address associated with each of the plurality of user devices thus paired.
  7. 15
    The access device of any one of claims 6 to 14, wherein the access device comprises a computing device.
  8. 16
    A method for managing a plurality of user devices adapted to communicate over a wireless link with a security token reading device, the method being implemented by the reading device and comprising the steps of:receiving a request for a connection from a first user device, the request comprising a first identifier for the first user device;generating and transmitting a first secure pairing value to the first user device for establishing a secure pairing with the first user device;storing connection information comprising the first identifier and a first key derived from the first secure pairing value;receiving a request for a connection from a second user device, the request comprising a second identifier for the second user device;generating and transmitting a second secure pairing value to the second user device for establishing a secure pairing with the second user device;storing connection information comprising the second identifier and a second key derived from the second secure pairing value;transmitting a notification to the first user device that the second user device has been paired with the access device;receiving an instruction from a user device paired with the access device to terminate a pairing between the access device and a designated user device;and in response to an instruction to terminate a pairing between the access device and the designated user device, overwriting the key associated with the designated user device.
  9. 19
    The method of any one of claims 16 to 18, further comprising the steps of:after the step of generating and transmitting a first secure pairing value, establishing at the access device first master connection key data for generating a first master connection key;generating a first master connection key from the first master connection key data, wherein the first user device is configured to generate the first master connection key from the first master connection key data, the first master connection key being used to secure data transmitted between the access device and the first user device, and wherein data transmitted to the first user device by the access device comprises the first identifier;after the step of generating and transmitting a second secure pairing value, establishing at the access device second master connection key data for generating a second master connection key;generating a second master connection key from the second master connection key data, wherein the second user device is configured to generate the second master connection key from the second master connection key data, the second master connection key being used to secure data transmitted between the access device and the second user device, and wherein data transmitted to the second user device by the access device comprises the second identifier;and wherein the connection information further comprises the master connection key associated with the user device, and further comprising the step in response to an instruction to terminate a pairing between the access device and the designated user device, overwriting the master connection key associated with the designated user device.
  10. 20
    The method of any one of claims 16 to 19, further comprising the steps of:receiving a request from a requesting user device for a listing of all user devices currently paired with the access device;and transmitting to the requesting user device in response to the request a listing of all user devices currently paired with the access device.
  11. 21
    A computer-readable medium comprising code executable by a computing device for causing said computing device to carry out the method of any one of claims 16 to 20.
  12. 22
    A mobile communication device comprising the access device of any one of claims 6 through 15.
  13. 23
    A smart card access device adapted to communicate with a plurality of user devices and to be securely paired with at least one of the plurality of user devices for implementing the method recited in any one of claims 16 through 20.