Secure access to secure access module-enabled machine using personal security device

US2016014116A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016014116-A1
Application numberUS-201414769865-A
CountryUS
Kind codeA1
Filing dateFeb 24, 2014
Priority dateFeb 25, 2013
Publication dateJan 14, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system and method are provided to access a secure host device using a personal security device (PSD). A user's PSD may hold a credential of a requesting component of the secure host device. The credential may only be readable from the PSD when a secure channel is established therewith. The establishment of a secure channel with the PSD may require access to keys. The secure host device may contain a SAM capable of securely storing and operating keys. The SMA may contain the relevant keys to support establishment of a secure channel with the personal security device and release a credential to its requesting component. These criteria may achieve the secure release of the credential from the PSD to the requesting component of the secure host device to achieve access by the user when the PSD is presented in the non-contract field of a card reader monitored by the secure host device.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for accessing a secure host device using a personal security device (PSD) of a user, comprising: providing the PSD with a credential for accessing the secure host device, wherein the credential is only readable from or operable with the PSD when a secure channel is established between the PSD and the secure host device after presenting the PSD in a non-contact field of a reader monitored by the secure host device; establishing the secure channel with the PSD using keys stored and operated on the secure host device; and securely releasing the credential of the PSD to a requesting component of the secure host device to achieve access by the user to the secure host device when the PSD is presented in the non-contact field. 2 . The method according to claim 1 , wherein the requesting component is an operating system (OS) of the secure host device, and wherein the credential is an OS credential. 3 . The method according to claim 1 , wherein the requesting component is an application running on the secure host device. 4 . The method according to claim 1 , wherein the credential is a one-time password. 5 . The method according to claim 1 , wherein the PSD is at least one of: a smart card, a tag, a wearable, or a mobile terminal. 6 . The method according to claim 1 , wherein the secure host device includes a secure access module (SAM). 7 . The method according to claim 6 , wherein the SAM runs on at least one of: dedicated secure hardware of the secure host device or a main processor of the secure host device. 8 . The method according to claim 1 , wherein the establishing of the secure channel is performed in at least one of: a tethered mode of operation or a roaming mode of operation, wherein, for the tethered mode of operation, the PSD releases the credential to the secure host device only when the PSD is cryptographically bound to the secure host device, and, wherein, for the roaming mode of operation, the PSD releases the OS credential to any secure host device activated for a specific group of PSDs. 9 . The method according to claim 1 , further comprising: binding the PSD to the user to provide two factor authentication. 10 . A non-transitory computer readable medium storing software for accessing a secure host device using a personal security device (PSD) of a user, the software comprising: executable code that stores on the PSD a credential for accessing the secure host device, wherein the credential is only readable from or operable with the PSD when a secure channel is established between the PSD and the secure host device after presenting the PSD in a non-contact field of a reader monitored by the secure host device; executable code that establishes the secure channel with the PSD using keys stored and operated on the secure host device; executable code that securely releases the credential of the PSD to a requesting component of the secure host device to achieve access by the user to the secure host device when the PSD is presented in the non-contact field. 11 . The non-transitory computer readable medium according to claim 10 , wherein the requesting component is an operating system (OS) of the secure host device, and wherein the credential is an OS credential. 12 . The non-transitory computer readable medium according to claim 10 , wherein the requesting component is an application running on the secure host device. 13 . The non-transitory computer readable medium according to claim 10 , wherein the credential is a one-time password. 14 . The non-transitory computer readable medium according to claim 10 , wherein the PSD is at least one of: a smart card, a tag, a wearable, or a mobile terminal. 15 . The non-transitory computer readable medium according to claim 10 , wherein the secure host device includes a secure access module (SAM). 16 . The non-transitory computer readable medium according to claim 15 , wherein the SAM runs on at least one of: dedicated secure hardware of the secure host device or a main processor of the secure host device 17 . The non-transitory computer readable medium according to claim 10 , wherein the executable code that establishes the secure channel includes at least one of: executable code that provides a tethered mode of operation or executable code that provides a roaming mode of operation, wherein, for the tethered mode of operation, the PSD releases the credential to the secure host device only when the PSD is cryptographically bound to the secure host device, and, wherein, for the roaming mode of operation, the PSD releases the OS credential to any secure host device activated for a specific group of PSDs. 18 . The non-transitory computer readable medium according to claim 10 , further comprising: executable code that binds the PSD to the user to provide two factor authentication. 19 . A mechanism for accessing a secure host device using a personal security device (PSD) of a user, the mechanism comprising: a non-contact field reader monitored by the secure host device; and at least one processor that reads software stored on at least one computer readable medium, the software comprising: executable code that stores on the PSD a credential for accessing the secure host device, wherein the credential is only readable from or operable with the PSD when a secure channel is established between the PSD and the secure host device after presenting the PSD in the non-contact field of the reader monitored by the secure host device; executable code that establishes the secure channel with the PSD using keys stored and operated on the secure host device; executable code that securely releases the credential of the PSD to a requesting component of the secure host device to achieve access by the user to the secure host device when the PSD is presented in the non-contact field. 20 . The mechanism according to claim 19 , wherein the PSD is at least one of: a smart card, a tag, a wearable, or a mobile terminal, and wherein the secure host device includes a secure access module.

Assignees

Inventors

Classifications

  • using one-time-passwords · CPC title

  • communicating wirelessly · CPC title

  • G06F21/41Primary

    where a single sign-on provides access to a plurality of computers · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016014116A1 cover?
A system and method are provided to access a secure host device using a personal security device (PSD). A user's PSD may hold a credential of a requesting component of the secure host device. The credential may only be readable from the PSD when a secure channel is established therewith. The establishment of a secure channel with the PSD may require access to keys. The secure host device may co…
Who is the assignee on this patent?
Assa Abloy Ab
What technology area does this patent fall under?
Primary CPC classification H04L63/0838. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jan 14 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).