Invention Grant
- Patent Title: Method and system for issuing and using derived credentials
-
Application No.: US15230044Application Date: 2016-08-05
-
Publication No.: US10320774B2Publication Date: 2019-06-11
- Inventor: Yamian Quintero Cantero , Jerry S. Iwanski
- Applicant: Route1 Inc.
- Applicant Address: CA Toronto
- Assignee: ROUTE1 INC.
- Current Assignee: ROUTE1 INC.
- Current Assignee Address: CA Toronto
- Agency: Muncy, Geissler, Olds & Lowe, P.C.
- Agent Daniel Podhajny
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/06 ; H04W12/04 ; H04W12/06 ; G06F21/31

Abstract:
At a mobile device, a password is used to create a proof of knowledge (POK). The POK is stored in a controller accessible via a communication network. The POK ensures that the controller can detect an incorrect password from the mobile device, and that the mobile device cannot be subject to a brute force attack to determine the DC stored in the mobile device. After a predetermined number of unsuccessful attempts to enter the password, the controller blocks further attempts, thereby restoring protection against a brute force attack that was lost going from a standalone smart card to mobile-device-based derived credentials. A portion of Derived Credentials, needed to authenticate the user of a mobile device, is stored in the controller, further increasing the difficulty of unauthorized use.
Public/Granted literature
- US20180041494A1 Method and system for issuing and using derived credentials Public/Granted day:2018-02-08
Information query