Invention Grant
- Patent Title: Secure credential unlock using trusted execution environments
-
Application No.: US14672143Application Date: 2015-03-28
-
Publication No.: US09256750B2Publication Date: 2016-02-09
- Inventor: Stefan Thom , Robert K. Spiger , Magnus NystrÖm , Himanshu Soni , Marc R. Barbour , Nick Voicu , Xintong Zhou , Kirk Shoop
- Applicant: MICROSOFT TECHNOLOGY LICENSING, LLC
- Applicant Address: US WA Redmond
- Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee Address: US WA Redmond
- Agent Judy Yee; Timothy Churna; Micky Minhas
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/60 ; G06F21/31 ; G06F21/57 ; G06F21/30 ; H04L9/08 ; H04L9/32

Abstract:
Computing devices utilizing trusted execution environments as virtual smart cards are designed to support expected credential recovery operations when a user credential, e.g., personal identification number (PIN), password, etc. has been forgotten or is unknown. A computing device generates a cryptographic key that is protected with a PIN unlock key (PUK) provided by an administrative entity. If the user PIN cannot be input to the computing device the PUK can be input to unlock the locked cryptographic key and thereby provide access to protected data. A computing device can also, or alternatively, generate a group of challenges and formulate responses thereto. The formulated responses are each used to secure a computing device cryptographic key. If the user PIN cannot be input to the computing device an entity may request a challenge. The computing device issues a challenge from the set of generated challenges. Upon receiving a valid response back, the computing device can unlock the secured computing device cryptographic key associated with the issued challenge and subsequently provide access to protected data.
Public/Granted literature
- US20150213278A1 SECURE CREDENTIAL UNLOCK USING TRUSTED EXECUTION ENVIRONMENTS Public/Granted day:2015-07-30
Information query