US20180167208A1

Confidential authentication and provisioning

Claim Score by NHIP

Read claim 26, the broadest

Abstract

Some embodiments provide systems and methods for confidentially and securely provisioning data to an authenticated user device. A user device may register an authentication public key with an authentication server. The authentication public key may be signed by an attestation private key maintained by the user device. Once the user device is registered, a provisioning server may send an authentication request message including a challenge to the user device. The user device may sign the challenge using an authentication private key corresponding to the registered authentication public key, and may return the signed challenge to the provisioning server. In response, the provisioning server may provide provisioning data to the user device. The registration, authentication, and provisioning process may use public key cryptography while maintaining confidentiality of the user device, the provisioning server, and then authentication server.

US20180167208A1, drawing sheet 1
Sheet 1 of 8

Term

10.8 yearsto projected expiry

Projected expiry 26 July 2037, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

26 claims: 5 independent, 21 dependent

  1. 1
    A computer-implemented method comprising:encrypting, by an authentication server, an authentication challenge to obtain an encrypted authentication challenge;sending, by the authentication server, the encrypted authentication challenge to a user device;receiving, by the authentication server, an encrypted authentication response from the user device;generating, by an authentication server, a first shared secret using an authentication server private key and a user device authentication public key;decrypting, by the authentication server, the encrypted authentication response using the first shared secret to obtain an authentication response including the authentication challenge;and authenticating, by the authentication server, the user device based on the authentication response.
  2. 9
    A computer-implemented method comprising:receiving, by a user device, an encrypted authentication challenge from the authentication server;decrypting, by the user device, the encrypted authentication challenge to obtain an authentication challenge;generating, by the user device, a first shared secret using a user device authentication private key corresponding to a user device authentication public key and an authentication server public key;encrypting, by the user device, an authentication response including the authentication challenge using the first shared secret to obtain an encrypted authentication response;and sending, by the user device, the encrypted authentication response to the authentication server, wherein the authentication server authenticates the user device based on the authentication response.
  3. 26
    Broadest claimClaim Score 65, broad(NHIP)A computer system, comprising:a processor;and a non-transitory computer-readable storage medium coupled to the processor and storing code executable by the processor for performing a method comprising: encrypting an authentication challenge to obtain an encrypted authentication challenge;sending the encrypted authentication challenge to a user device;receiving an encrypted authentication response from the user device;generating a first shared secret using an authentication server private key and a user device authentication public key;decrypting the encrypted authentication response using the first shared secret to obtain an authentication response including the authentication challenge;and authenticating the user device based on the authentication response.
  4. 28
    A computer system, comprising:a processor;and a non-transitory computer-readable storage medium coupled to the processor and storing code executable by the processor for performing a method comprising: receiving an encrypted authentication challenge from the authentication server;decrypting the encrypted authentication challenge to obtain an authentication challenge;generating a first shared secret using a user device authentication private key corresponding to a user device authentication public key and an authentication server public key;encrypting an authentication response including the authentication challenge using the first shared secret to obtain an encrypted authentication response;and sending the encrypted authentication response to the authentication server, wherein the authentication server authenticates the user device based on the authentication response.