IN8235DEN2014A

One time passcodes with asymmetric keys

Abstract

Protecting the security of an entity by using passcodes is disclosed. A user s passcode device generates a passcode. In an embodiment the passcode is generated in response to receipt of user information. The passcode is received by another system which authenticates the passcode by at least generating a passcode from a passcode generator and comparing the generated passcode with the received passcode. The passcode is temporary. At a later use a different passcode is generated from a different passcode generator. In these embodiments there are asymmetric secrets stored on the passcode device and by the administrator. This adds more security so that if the backend servers are breached the adversary cannot generate valid passcodes. In some embodiments the passcode depends on the rounded time.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

36 claims: 10 independent, 26 dependent

  1. 1
    CLAIMS 1. A method comprising enrolling a user based on at least one of the following:his or her biometric prints, his or her selection of visual images or his or her selection of a PIN;and at the completion of this enrollment generating asymmetric secrets based on a semiconductor that detects the arrival of photons.
  2. 8
    A method comprising:generating, via a machine, a code that is valid temporarily, WO 2013/134306 PCT/US2013/029187 wherein the code is based on information associated with a user;and determining whether an attempted access is permitted, based on the code that is generated only after a valid authentication from a user selecting visual images displayed by this machine to the user.
  3. 12
    A method comprising:generating, via a machine, a code that is valid temporarily, wherein the code is based on the time;and determining whether an attempted access is permitted, based on encrypting the code with a user key.
  4. 19
    A system comprising at least one machine-readable medium storing instructions that cause one or more processors to perform a method including at least determining whether a submitted passcode is valid, by at least generating a generated passcode from a passcode generator and a key;comparing the submitted passcode to the generated passcode;if the submitted passcode matches the generated passcode granting access to a secure entity.
  5. 25
    A system comprising at least one machine-readable medium storing instructions that cause one or more processors to perform a method including at least determining whether a submitted encrypted passcode is valid, by at least generating a generated passcode from the time and a key;decrypting the submitted passcode, and comparing the decrypted, submitted passcode to the generated passcode;if the decrypted, submitted passcode matches the generated passcode, then granting access to a secure entity.
  6. 27
    A method comprising:generating a registration code using a Diffie-Hellman exchange wherein a user and an administrator that grants access to a secure entity both derive the same passcode generator from the registration code.
  7. 29
    The claim of method 28 wherein said photodetector is made from a semiconductor.
  8. 30
    A method comprising:acquiring identifying information or unpredictable information;generating at least one registration code and at least one key by at least applying a first method to the identifying or unpredictable information or both, wherein the first method is of a type such that computing the identifying or unpredictable information from the registration code is computationally intractable;submitting the registration code to a system that is distinct from where the acquiring occurred;generating a passcode generator from the registration code, at a device where the acquiring occurred, by at least applying a second method to the registration code, wherein the second method is of a type such that computing the registration code from the passcode generator is computationally intractable;and storing the passcode generator and key at the device.
  9. 31
    A system comprising a machine-readable medium storing thereon instructions for an Application Program Interface (API) having an argument for a passcode generator, an administrator key and a user ID;wherein the passcode generator and administrator key arc value derived from user information or random information;and wherein the passcode generator and administrator keys are values from which deriving the user information is expected to be intractable. WO 2013/134306 PCT/US2013/029187
  10. 36
    A system comprising a machine-readable medium storing thereon instructions for an Application Program Interface (API) having an argument for an administrator key and the time and a user ID;wherein the administrator key is a value derived from user WO 2013/134306 PCT/ (JS2013/029'187 information or random information or both;and wherein the administrator keys arc values from which deriving the user information is expected to be intractable.