Authentication token
First Claim
1. A system for generating secure passwords for use by at least one authentication server in authenticating a user of an authentication token and an authentication token interface device, in response to the user seeking access to protected computer resources of at least one server, comprising:
- said authentication token interface device operable to interact with said authentication token to generate said secure passwords in response to input of a unique consumer code by the user into said authentication token interface device and upon authenticating of said unique consumer code by said authentication token;
said authentication token interface device having;
a processor, firmware, a user interface, an I/O interface compatible with said authentication token, and a dynamic variable generator;
said authentication token having;
a processor, firmware, an operating system, a data store, an I/O interface compatible with said authentication token interface device, a key generation algorithm, and a password application;
said authentication token storing at least;
(i) a secret key, (ii) a changing register value, (iii) a seed value and (iv) said unique consumer code;
said password application generating said secure passwords by;
(i) combining said changing register value with a dynamic variable generated by said dynamic variable generator to produce a payload, (ii) encrypting said payload with said secret key to produce an encrypted payload and, (iii) combining least significant bits of said encrypted payload with least significant bits of said dynamic variable to produce a new secure password; and
said key generation algorithm;
(i) generating a new secret key and a new seed value following the generation of a first of said secure passwords and of said new secure password, said new secret key being derived from said secret key, said changing register value, and said seed value, and said new seed value being derived from said secret key, said changing register value, and said seed value, (ii) replacing said secret key and said seed value with said new secret key and said new seed value in storage of said authentication token, and (iii) changing said changing register value by a change value to result in a new changing register value after generation of said new secret key and said new seed value;
wherein, after generation of said first of said secure passwords and of said new secure password, said dynamic variable is changed to a new dynamic variable by said dynamic variable generator.
3 Assignments
0 Petitions
Accused Products
Abstract
An authentication token using a smart card that an organisation would issue to its customer, the smart card having a processor for executing a software application that is responsive to a user input to generate a one-time password as an output. The smart card co-operates with an interface device for inputting the user input and displaying the one-time password. The authentication token may be used in combination with a remote authentication server for validation of the password and hence authentication of the user.
69 Citations
23 Claims
-
1. A system for generating secure passwords for use by at least one authentication server in authenticating a user of an authentication token and an authentication token interface device, in response to the user seeking access to protected computer resources of at least one server, comprising:
-
said authentication token interface device operable to interact with said authentication token to generate said secure passwords in response to input of a unique consumer code by the user into said authentication token interface device and upon authenticating of said unique consumer code by said authentication token; said authentication token interface device having;
a processor, firmware, a user interface, an I/O interface compatible with said authentication token, and a dynamic variable generator;said authentication token having;
a processor, firmware, an operating system, a data store, an I/O interface compatible with said authentication token interface device, a key generation algorithm, and a password application;said authentication token storing at least;
(i) a secret key, (ii) a changing register value, (iii) a seed value and (iv) said unique consumer code;said password application generating said secure passwords by;
(i) combining said changing register value with a dynamic variable generated by said dynamic variable generator to produce a payload, (ii) encrypting said payload with said secret key to produce an encrypted payload and, (iii) combining least significant bits of said encrypted payload with least significant bits of said dynamic variable to produce a new secure password; andsaid key generation algorithm;
(i) generating a new secret key and a new seed value following the generation of a first of said secure passwords and of said new secure password, said new secret key being derived from said secret key, said changing register value, and said seed value, and said new seed value being derived from said secret key, said changing register value, and said seed value, (ii) replacing said secret key and said seed value with said new secret key and said new seed value in storage of said authentication token, and (iii) changing said changing register value by a change value to result in a new changing register value after generation of said new secret key and said new seed value;wherein, after generation of said first of said secure passwords and of said new secure password, said dynamic variable is changed to a new dynamic variable by said dynamic variable generator. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A method of generating secure passwords for use by at least one authentication server in authenticating a user of an authentication token and an authentication token interface device, in response to the user seeking access to protected computer resources of at least one server, the method comprising:
-
storing, by the authentication token;
(i) a unique consumer code (ii) a changing register value (iii) a secret key and, (iv) a seed value;generating, by the authentication token interface device, a dynamic variable; forwarding, by the authentication token interface device, the unique consumer code to the authentication token; authenticating, by the authentication token, the unique consumer code forwarded by the authentication token interface device; forwarding, by the authentication token interface device, the dynamic variable to the authentication token, in response to the authenticating; combining, by the authentication token, the dynamic variable with the changing register value to produce a payload; encrypting, by the authentication token, the payload using the secret key to produce an encrypted payload; combining, by the authentication token, least significant bits of the encrypted payload with least significant bits of the dynamic variable to produce a new secure password; executing, by the authentication token, a key generating algorithm to;
(i) produce a new secret key derived from the changing register value, the secret key, and the seed value, and produce a new seed value derived from the changing register value, the secret key, and the seed value, (ii) replace the secret key and the seed value with the new secret key and the new seed value stored in the authentication token, and (iii) change the changing register value by a change value to result in a new changing register value after generation of the new secret key and the new seed value; andchanging, after producing the new secure password, the dynamic variable to a new dynamic variable. - View Dependent Claims (13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23)
-
Specification