The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 10, 2014

Filed:

Mar. 30, 2012
Applicants:

Marten Van Dijk, Somerville, MA (US);

Kevin D. Bowers, Melrose, MA (US);

Samuel Curry, Andover, MA (US);

Sean P. Doyle, Edmonds, WA (US);

Nikolaos Triandopoulos, Arlington, MA (US);

Riaz Zolfonoon, Marlborough, MA (US);

Inventors:

Marten van Dijk, Somerville, MA (US);

Kevin D. Bowers, Melrose, MA (US);

Samuel Curry, Andover, MA (US);

Sean P. Doyle, Edmonds, WA (US);

Nikolaos Triandopoulos, Arlington, MA (US);

Riaz Zolfonoon, Marlborough, MA (US);

Assignee:

EMC Corporation, Hopkinton, MA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
Abstract

A technique for detecting unauthorized copies of a soft token that runs on a mobile device includes generating a set of random bits on the mobile device and providing samples of the set of random bits, as well as token codes from the soft token, for delivery to a server during authentication requests. The server acquires the set of random bits of the mobile device, or learns the set of random bits over the course of multiple login attempts. Thereafter, the server predicts values of the samples of the set of random bits and tests actual samples arriving in connection with subsequent authentication requests. Mismatches between predicted samples and received samples indicate discrepancies between the random bits of the device providing the samples and the random bits of the mobile device, and thus indicate unauthorized soft token copies.


Find Patent Forward Citations

Loading…