Invention Grant
- Patent Title: Authenticated remote pin unblock
- Patent Title (中): 认证远程销解除阻塞
-
Application No.: US13922582Application Date: 2013-06-20
-
Publication No.: US09118668B1Publication Date: 2015-08-25
- Inventor: Mark Herbert Priebatsch
- Applicant: Assa Abloy AB
- Applicant Address: SE Stockholm
- Assignee: Assa Abloy AB
- Current Assignee: Assa Abloy AB
- Current Assignee Address: SE Stockholm
- Agency: Muirhead and Saturnelli, LLC
- Main IPC: H04L9/32
- IPC: H04L9/32 ; H04L29/06 ; G06F21/31

Abstract:
This invention provides a simple and secure PIN unblock mechanism for use with a security token. A set of one or more passphrases are stored on a remote server during personalization. Likewise, the answers to the passphrases are hashed and stored inside the security token for future comparison. A local client program provides the user input and display dialogs and ensures a secure communications channel is provided before passphrases are retrieved from the remote server. Retrieval of passphrases and an administrative unblock secret from the remote server are accomplished using a unique identifier associated with the security token, typically the token's serial number. A PIN unblock applet provides the administrative mechanism to unblock the security token upon receipt of an administrative unblock shared secret. The remote server releases the administrative unblock shared secret only after a non-forgeable confirmatory message is received from the security token that the user has been properly authenticated. The administrative unblock shared secret is encrypted with the token's public key during transport to maximize security.
Information query