Single-certificate multi-factor authentication

US11856113B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11856113-B2
Application numberUS-202117548326-A
CountryUS
Kind codeB2
Filing dateDec 10, 2021
Priority dateDec 10, 2020
Publication dateDec 26, 2023
Grant dateDec 26, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method of multi-factor authentication includes receiving, by a first electronic device, a partial digital certificate including partial certificate information omitting at least one authentication factor from complete certificate information, and a signature encrypting a first hash of the complete certificate information with a certificate authority private key. The method also includes obtaining the first hash by decrypting, by the first electronic device, the signature with a certificate authority public key corresponding to the certificate authority private key; generating, by the first electronic device, a second hash based on the partial certificate information in the partial digital certificate and the at least one authentication factor; and comparing, by the first electronic device, the second hash to the first hash.

First claim

Opening claim text (preview).

What is claimed is: 1. A method of multi-factor authentication, the method comprising: receiving, by a first electronic device, a partial digital certificate comprising: only partial certificate information among complete certificate information, the partial certificate omitting at least one authentication factor from the complete certificate information, and a digital signature encrypting a first hash of the complete certificate information with a certificate authority private key, obtaining the first hash by decrypting, by the first electronic device, the digital signature with a certificate authority public key corresponding to the certificate authority private key; supplying, by the first electronic device, the at least one authentication factor; generating, by the first electronic device, a second hash based on a combination of the partial certificate information in the partial digital certificate with the at least one authentication factor; and comparing, by the first electronic device, the second hash to the first hash, wherein the first electronic device is an implanted medical device, and wherein the at least one authentication factor comprises a time stamp from an internal clock of the implanted medical device, GPS coordinates of the implanted medical device, and/or a unique identification number of the implanted medical device. 2. The method of claim 1 , further comprising: transmitting, from a second electronic device to the first electronic device, the partial digital certificate; and authenticating the second electronic device in response to the second hash matching the first hash. 3. The method of claim 1 , wherein the at least one authentication factor comprises a plurality of authentication factors. 4. The method of claim 3 , wherein the digital signature comprises a plurality of digital signatures, each digital signature of the plurality of digital signatures corresponding to the partial certificate information and one of the plurality of authentication factors. 5. The method of claim 3 , wherein the digital signature corresponds to the partial certificate information and each of the plurality of authentication factors. 6. The method of claim 3 , wherein the digital signature comprises a plurality of digital signatures, a first digital signature of the plurality of digital signatures corresponding to the partial certificate information and one of the plurality of authentication factors having a first value, and a second digital signature of the plurality of digital signatures corresponding to the partial certificate information and the one of the plurality of authentication factors having a second value different than the first value. 7. The method of claim 1 , wherein the at least one authentication factor comprises a knowledge factor selected from the group consisting of a password, a pin code, a unique identifier of the second electronic device, and an answer to a secret question. 8. The method of claim 1 , wherein the at least one authentication factor comprises an inherence factor selected from the group consisting of a fingerprint, an iris scan, a vocal sample, and a speech pattern. 9. The method of claim 1 , wherein the at least one authentication factor comprises plain-text information. 10. The method of claim 1 , wherein a memory of the first electronic device stores the certificate authority public key. 11. The method of claim 1 , wherein the digital signature was formed utilizing a signing algorithm selected from the group consisting of a standard Digital Signature Algorithm (DSA), an elliptic curve digital signature algorithm (ECDSA), a Rivest-Shamir-Adleman (RSA) algorithm, and an elliptic curve RSA algorithm (ECRSA). 12. A method of multi-factor authentication, the method comprising: transmitting, by a second electronic device, an authentication request to a first electronic device, the authentication request comprising a partial digital certificate comprising: only partial certificate information among complete certificate information, the partial certificate information omitting at least one authentication factor from the complete certificate information, and a digital signature encrypting a first hash of the complete certificate information with a certificate authority private key; receiving, by the first electronic device, the partial digital certificate; obtaining the first hash by decrypting, by the first electronic device, the digital signature with a certificate authority public key corresponding to the certificate authority private key; supplying, by the first electronic device, the at least one authentication factor; generating, by the first electronic device, a second hash based on a combination of the partial certificate information in the partial digital certificate with the at least one authentication factor; and comparing, by the first electronic device, the second hash to the first hash, wherein the first electronic device is an implanted medical device, and wherein the at least one authentication factor comprises a time stamp from an internal clock of the implanted medical device, GPS coordinates of the implanted medical device, and/or a unique identification number of the implanted medical device. 13. The method of claim 12 , further comprising authenticating the second electronic device in response to the second hash matching the first hash. 14. The method of claim 12 , wherein the at least one authentication factor comprises a plurality of authentication factors. 15. The method of claim 14 , wherein the digital signature comprises a plurality of digital signatures, each digital signature of the plurality of digital signatures corresponding to the partial certificate information and one of the plurality of authentication factors. 16. The method of claim 14 , wherein the digital signature corresponds to the partial certificate information and each of the plurality of authentication factors. 17. The method of claim 14 , wherein the digital signature comprises a plurality of digital signatures, a first digital signature of the plurality of digital signatures corresponding to the partial certificate information and one of the plurality of authentication factors having a first value, and a second digital signature of the plurality of digital signatures corresponding to the partial certificate information and the one of the plurality of authentication factors having a second value different than the first value. 18. The method of claim 12 , wherein the at least one authentication factor comprises a knowledge factor selected from the group consisting of a password, a pin code, a unique identifier of the second electronic device, and an answer to a secret question. 19. The method of claim 12 , wherein the at least one authentication factor comprises an inherence factor selected from the group consisting of a fingerprint, an iris scan, a vocal sample, and a speech pattern. 20. The method of claim 12 , further comprising receiving, by the first electronic device, the at least one authentication factor from the second electronic device. 21. The method of claim 12 , further comprising supplying, by the first electronic device, the at least one authentication factor. 22. The method of claim 12 , wherein the at least one authentication factor comprises plain-text information. 23. The method of claim 12 , wherein the digital signature was formed utilizing a signing algorithm selected from the group co

Assignees

Inventors

Classifications

  • H04L9/3268Primary

    using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL] · CPC title

  • using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates · CPC title

  • Biological data, e.g. fingerprint, voice or retina (network architectures or network communication protocols for supporting authentication of entities using biometrical features in a packet data network H04L63/0861) · CPC title

  • involving keyed hash functions, e.g. message authentication codes [MACs], CBC-MAC or HMAC · CPC title

  • involving digital signatures · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11856113B2 cover?
A method of multi-factor authentication includes receiving, by a first electronic device, a partial digital certificate including partial certificate information omitting at least one authentication factor from complete certificate information, and a signature encrypting a first hash of the complete certificate information with a certificate authority private key. The method also includes obtai…
Who is the assignee on this patent?
The Alfred E Mann Foundation For Scient Research
What technology area does this patent fall under?
Primary CPC classification H04L9/3268. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 26 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 11 related publications on this page (citations in our corpus or others sharing the same primary CPC).