×

Method to manage a one time password key

  • US 10,164,954 B2
  • Filed: 03/25/2015
  • Issued: 12/25/2018
  • Est. Priority Date: 03/25/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method to manage a One Time Password key, referenced OTP key, used in an OTP algorithm in a user device having access to an unsafe storage including the preliminary steps of:

  • retrieving a Personal Identification Number, named PIN, of a user of the user device,deriving a symmetric key from the PIN,encrypting the OTP key using the derived symmetric key,storing the encrypted OTP key in the unsafe storagethe method further comprising the following steps, when the calculation of an OTP is required;

    retrieving a PIN of a user of the user device,decrypting the stored OTP key using the derived symmetric key, andusing said decrypted OTP key and an incremental parameter to generate a next OTP,wherein the incremental parameter has values within an interval in which the number of possible values for the incremental parameter is limited and the algorithm is such that a counter is not wrapped, and the start value of the incremental parameter of the OTP generation is a generated random value chosen in a limited interval of possible values for the incremental parameter,and wherein, in the case the counter is incremented, the limited interval is one including lowest bits.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×