Authenticated remote PIN unblock
Abstract
This invention provides a simple and secure PIN unblock mechanism for use with a security token. A set of one or more passphrases ire stored on a remote sever during personalization. Likewise, the answers to the passphrases are hashed and stored inside the security token for fixture comparison. A local client program provides the user input and display dialogs and ensures a secure communications channel is provided before passphrases are retrieved from the remote server. Retrieval of passphrases and an administrative unblock secret from the remote server are accomplished using a unique identifier associated with the security token, typically the token's serial number. A PIN unblock applet provides the administrative mechanisms to unblock the security token upon receipt of an administrative unblock shared secret. The remote server releases the administrative unblock shared secret only after a non-forgeable confirmatory message is received from the security token that the user has been properly authenticated. The administrative unblock shared secret is encrypted with the token's public key during transport to maximize security.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A system which facilitates an authenticated user to unblock a temporarily blocked security token comprising:
a security executive associated with said token, an unblock applet associated with said security executive, a first secret associated with at least one unblock inquiry, and a first shared secret associated with said unblock applet; a client functionally connected to said security token including;
at least one client application for initiating an unblock procedure with said security token and a remote server,
said remote server in processing communications with said client including;
said at least one unblock inquiry,
at least one unblock service application, responsive to said at least one client application, and
a second shared secret,
wherein said at least one unblock inquiry and said second shared secret are progressively sent to said unlock applet for unblocking said security token.
2 . The system according to claim 1 wherein said first secret is a one way hash of an answer to said at least one unblock inquiry.
3 . The system according to claim 2 wherein said security token further includes a private asymmetric key.
4 . The system according to claim 3 wherein said server further includes a public asymmetric key counterpart to said private asymmetric key.
5 . The system according to claim 4 wherein said at least one unblock inquiry is encrypted with said public asymmetric key.
6 . The system according to claim 1 wherein said first shared secret is equal to said second shared secret.
7 . The system according to claim 5 wherein said second shared secret is encrypted with said public asymmetric key.
8 . The system according to claim 7 wherein said second shared secret is an administrative PIN.
9 . The system according to claim 8 wherein said second shared secret is a synthetic key.
10 . The system according to claim 7 wherein said second shared secret is decrypted with said private asymmetric key.
11 . The remote server according to claim 1 further including means for providing an audit trail of said unblock procedure.
12 . The system according to claim 1 wherein said second shared secret is sent to said security token upon receipt of a properly encoded message by said at least one unblock service application.
13 . The system according to claim 1 wherein said at least one unblock inquiry includes a passphrase.
14 . The system according to claim 1 wherein said processing communications includes a secure communications protocol.
15 . A method for generating and storing at least one passphrase and answers associated with said at least one passphrase, facilitating an authenticated user to unblock a temporarily blocked security token comprising:
generating said at least one passphrase, associating said at least one passphrase with a unique identifier, storing said at least one passphrase on a server in a manner retrievable using said unique identifier, generating said answers associated with said at least one passphrase, performing a message digest function on said answers associated with said at least one passphrase, storing a result of said message digest function in a security token associated with said authenticated user, and wherein said unique identifier is associated with said security token.
16 . The method according to claim 15 further including the step of encrypting said at least one passphrase with a public asymmetric key associated with said security token.
17 . A method which facilitates an authenticated user to unblock a temporarily blocked security token composing:
a. executing a PIN unblock application on a local client in which said security token operatively is connected, b. passing a set of parameters from said security token via said PIN unblock application to a remote PIN unblock service, c. using at least one of said set of parameters for retrieving and locally displaying at least one passphrase from said PIN unblock service, d. entering an appropriate response to said at least one passphrase, e. performing a mathematical function on said appropriate response, f. comparing said result of said mathematical function to an existing reference, g. sending a confirmatory message to said remote PIN unblock service if said result of said mathematical function matches said existing reference or ending processing if no match is found, h. retrieving an unblocking secret using said at least one of said set of parameters upon receipt of said confirmatory message, i. sending said unblocking secret to said security token, j. unblocking said security token using said unblocking secret.
18 . The method according to claim 17 further including the step of using said at least one of said set of parameters to establish a secure communications channel between said remote PIN unblock service and said PIN unblock application
19 . The method according to claim 18 further including the step of entering a replacement PIN when prompted by said PIN unlock application.
20 . The method according to claim 17 wherein said at least one of said set of parameters includes an authentication challenge, a unique identifier and a digital certificate.
21 . A computer program product embodied in a tangible form which provides computer executable instructions to perform the steps of:
a. generating user display and input dialogs, b. passing a set of parameters from said security token via said PIN unblock application to a remote PIN unblock service, c. using at least one of said set of parameters for retrieving and locally displaying at least one passphrase from said PIN unblock service, d. prompting for entry of an appropriate response to said at least one passphrase, e. performing a mathematical function on said appropriate response, f. comparing said result of said mathematical function to an existing reference, g. sending a confirmatory message to said remote PIN unblock service if said result of said mathematical function matches said existing reference or ending processing if no match is found, h. retrieving an unblocking secret using said at least one of said set of parameters upon receipt of said confirmatory message, i. sending said unblocking secret to said security token, j. unblocking said security token using said unblocking secret.
22 . The computer program product according to claim 21 further including the step of using said at least one of said set of parameters to establish a secure communications channel between said remote PIN unblock service and said PIN unblock application.
23 . The computer program product according to claim 22 further including the step of prompting for the entry of a replacement PIN.
24 . The computer program product according to claim 21 wherein said at least one of said set of parameters includes an authentication challenge, a unique identifier and a digital certificate.Join the waitlist — get patent alerts
Track US2004103325A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.