Method and apparatus for pervasive authentication domains
First Claim
1. A method comprising:
- registering, at a device configured as a personal authentication gateway, at least one pervasive device for membership in a pervasive authentication domain, the pervasive authentication domain including devices authorized to share access credentials;
ascertaining the device configured as a personal authentication gateway from the at least one pervasive device included in a pervasive authentication domain;
sending at least one token request from the at least one pervasive device to the device configured as a personal authentication gateway; and
receiving a token response including the access credentials from the device configured as a personal authentication gateway;
wherein the access credentials allow the at least one pervasive device to authenticate to one or more services on behalf of a user as configured in the device configured as a personal authentication gateway; and
wherein said registering step comprises;
entering a same random password on the at least one pervasive device and the device configured as a personal authentication gateway;
generating on the device configured as a personal authentication gateway a protected encryption key by having Slave_ID_Secret encrypted by the same random password;
transferring the protected key to the at least one pervasive device and computing a fingerprint of the protected key on the device configured as a personal authentication gateway; and
comparing the fingerprint of the received and decrypted protected encryption key on the at least one pervasive device.
0 Assignments
0 Petitions
Accused Products
Abstract
Methods and apparatus for enabling a Pervasive Authentication Domain. A Pervasive Authentication Domain allows many registered Pervasive Devices to obtain authentication credentials from a single Personal Authentication Gateway and to use these credentials on behalf of users to enable additional capabilities for the devices. It provides an arrangement for a user to store credentials in one device (the Personal Authentication Gateway), and then make use of those credentials from many authorized Pervasive Devices without re-entering the credentials. It provides a convenient way for a user to share credentials among many devices, particularly when it is not convenient to enter credentials as in a smart wristwatch environment. It further provides an arrangement for disabling access to credentials to devices that appear to be far from the Personal Authentication Gateway as measured by metrics such as communications signal strengths.
-
Citations
17 Claims
-
1. A method comprising:
-
registering, at a device configured as a personal authentication gateway, at least one pervasive device for membership in a pervasive authentication domain, the pervasive authentication domain including devices authorized to share access credentials; ascertaining the device configured as a personal authentication gateway from the at least one pervasive device included in a pervasive authentication domain; sending at least one token request from the at least one pervasive device to the device configured as a personal authentication gateway; and receiving a token response including the access credentials from the device configured as a personal authentication gateway; wherein the access credentials allow the at least one pervasive device to authenticate to one or more services on behalf of a user as configured in the device configured as a personal authentication gateway; and wherein said registering step comprises; entering a same random password on the at least one pervasive device and the device configured as a personal authentication gateway; generating on the device configured as a personal authentication gateway a protected encryption key by having Slave_ID_Secret encrypted by the same random password; transferring the protected key to the at least one pervasive device and computing a fingerprint of the protected key on the device configured as a personal authentication gateway; and comparing the fingerprint of the received and decrypted protected encryption key on the at least one pervasive device. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A method comprising:
-
registering, at a device configured as a personal authentication gateway, at least one pervasive device for membership in a pervasive authentication domain, the pervasive authentication domain including devices authorized to share access credentials; receiving at least one token request for access credentials from the at least one pervasive device; determining whether the at least one pervasive device is a member of the pervasive authentication domain based on a pervasive device identification; and sending at least one token response including the access credentials to the at least one pervasive device from the device configured as a personal authentication gateway; wherein the access credentials allow the at least one pervasive device to authenticate to one or more services on behalf of a user as configured in the device configured as a personal authentication gateway; and wherein said registering step comprises; entering a same random password on the at least one pervasive device and the device configured as a personal authentication gateway; generating on the device configured as a personal authentication gateway a protected encryption key by having Slave_ID_Secret encrypted by the same random password; transferring the protected key to the at least one pervasive device and computing a fingerprint of the protected key on the device configured as a personal authentication gateway; and comparing the fingerprint of the received and decrypted protected encryption key on the at least one pervasive device. - View Dependent Claims (8, 9, 10, 11, 12, 13, 14, 15, 16)
-
-
17. A method comprising:
-
configuring a pervasive device as a personal authentication gateway; registering, at the pervasive device, at least one other pervasive device for membership in a pervasive authentication domain, the pervasive authentication domain including devices authorized to share access credentials; receiving at least one token request for access credentials from the at least one other pervasive device; determining whether the at least one other pervasive device is a member of the pervasive authentication domain; and sending at least one token response including the access credentials to the at least one other pervasive device from the pervasive device; wherein the access credentials allow the at least one other pervasive device to authenticate to one or more services on behalf of a user as configured in the pervasive device; and wherein said registering step comprises; entering a same random password on the at least one pervasive device and the device configured as a personal authentication gateway; generating on the device configured as a personal authentication gateway a protected encryption key by having Slave_ID_Secret encrypted by the same random password; transferring the protected key to the at least one pervasive device and computing a fingerprint of the protected key on the device configured as a personal authentication gateway; and comparing the fingerprint of the received and decrypted protected encryption key on the at least one pervasive device.
-
Specification