Detecting soft token copies
US8752156B1 · kind B1 · utility
Assignee
Inventors
Key dates
| Filing date | Mar 30, 2012 |
| Grant date | Jun 10, 2014 |
| Priority date | — |
| Expiry date | Jul 31, 2032 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04W12/122
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A technique for detecting unauthorized copies of a soft token that runs on a mobile device includes generating a set of random bits on the mobile device and providing samples of the set of random bits, as well as token codes from the soft token, for delivery to a server during authentication requests. The server acquires the set of random bits of the mobile device, or learns the set of random bits over the course of multiple login attempts. Thereafter, the server predicts values of the samples of the set of random bits and tests actual samples arriving in connection with subsequent authentication requests. Mismatches between predicted samples and received samples indicate discrepancies between the random bits of the device providing the samples and the random bits of the mobile device, and thus indicate unauthorized soft token copies.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.