Video surveillance systems using out of band key exchange
US-12177293-B2 · Dec 24, 2024 · US
US9787648B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9787648-B2 |
| Application number | US-201514596040-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jan 13, 2015 |
| Priority date | Jun 25, 2014 |
| Publication date | Oct 10, 2017 |
| Grant date | Oct 10, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method includes receiving a challenge from an authentication consumer. The method also includes generating for display a figure associated with an identification, a public certificate, and a private key after receiving the challenge. The figure, the identification, the public certificate, and the private key are stored in a TrustZone (TZ) enriched environment. The method further includes receiving an input identification. The method includes verifying that the input identification matches the identification. The method also includes transmitting the challenge to the authentication consumer in response to verifying that the input identification matches the identification.
Opening claim text (preview).
What is claimed is: 1. A method, comprising: receiving a selection of a figure and an input, storing the figure and input in a TrustZone (TZ) enriched environment, and associating the figure and the input with an authentication consumer server; receiving, by at least one processor operating in the TZ enriched environment, a challenge from an authentication consumer server; generating for display the challenge in a secured manner, wherein the secured manner comprises displaying the challenge in conjunction with the figure; receiving an input associated with the authentication consumer server; generating a signed public key using a secret root key determined by a component manufacturer and stored in a TZ database in the TZ enriched environment; and transmitting, to the authentication consumer server, the challenge, the signed public key, and the input to the authentication consumer server, wherein the transmitted challenge matches the received challenge. 2. The method of claim 1 , wherein the figure comprises a photograph. 3. The method of claim 1 , further comprising associating a certificate with the authentication consumer server. 4. The method of claim 1 , wherein the input comprises at least one of a password, signature, finger print, retinal signature, or biometric signature. 5. The method of claim 1 , wherein the challenge comprises an indication of a transaction identified by the authentication consumer server. 6. The method of claim 5 , wherein generating for display the challenge comprises generating for display an indication of the transaction identified by the authentication consumer server. 7. The method of claim 5 , wherein receiving the input comprises receiving an authorization to complete the transaction identified by the authentication consumer server. 8. The method of claim 5 , wherein transmitting the challenge comprises transmitting the authorization to complete the transaction with the input and the signed public key. 9. An apparatus, comprising: at least one processor operating in a TrustZone (TZ) enriched environment, the TZ enriched environment comprising a TZ database configured to store a figure, an input, and a signed public key, the at least one processor configured to: receive a challenge from an authentication consumer server, generate for display the challenge in a secured manner, wherein the secured manner comprises displaying the challenge in conjunction with the figure, receive an input associated with the authentication consumer server, and generate the signed public key using a secret root key determined by a component manufacturer and stored in the TZ database, and control the apparatus to transmit, to the authentication consumer server, the challenge, the signed public key, the input to the authentication consumer server, wherein the transmitted challenge matches the received challenge. 10. The apparatus of claim 9 , wherein the at least one processor is configured to receive a selection of the figure and the input, store the figure and input in the TZ database, and associate the figure and the input with the authentication consumer server. 11. The apparatus of claim 10 , wherein the figure comprises a photograph. 12. The apparatus of claim 9 , wherein the input comprises at least one of a password, signature, finger print, retinal signature, or biometric signature. 13. The apparatus of claim 9 , wherein the challenge comprises an indication of a transaction. 14. The apparatus of claim 13 , wherein the at least one processor is configured to generate for display an indication of the transaction when generating for display the challenge. 15. The apparatus of claim 13 , wherein the at least one processor is configured to receive an authorization to complete the transaction when receiving the input. 16. The apparatus of claim 13 , wherein the at least one processor is configured to transmit an authorization to complete the transaction, the signed public key, and the input when transmitting the challenge. 17. A system, comprising: an apparatus configured to wirelessly communicate with a server associated with an authentication consumer, the apparatus comprising at least one processor operating in a TrustZone (TZ) enriched environment, the TZ enriched environment comprising a TZ database configured to store a figure, an input, and a signed public key, the at least one processor configured to: receive a challenge from the server, the challenge associated with a transaction, generate for display the challenge in a secured manner, wherein the secured manner comprises displaying the challenge in conjunction with the figure, receive an input associated with the server, generate the signed public key using a secret root key determined by a component manufacturer and stored in the TZ database, control the apparatus to transmit the signed public key, the input to the server to complete the transaction, and the received challenge for comparison with a challenge previously transmitted by the authentication consumer server. 18. The system of claim 17 , wherein the at least one processor is configured to receive a selection of the figure and the input, store the figure and input in the TZ database, and associate the figure and the input with the server. 19. The system of claim 18 , wherein the figure comprises a photograph. 20. The system of claim 17 , wherein the input comprises at least one of a password, signature, finger print, retinal signature, or biometric signature.
wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements (network architectures or network communication protocols for supporting authentication of entities using certificates in a packet data network H04L63/0823) · CPC title
One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.