IP Library Granted Patent US 9,756,035
Granted Patent B2
US 9,756,035 · App. 14/621,845 · Granted Sep 5, 2017

Device fingerprint registration for single sign on authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,756,035
App. No.
14/621,845
Granted
Sep 5, 2017
Kind
B2
Abstract

A device fingerprinting system provides an additional factor of authentication. A user device may be redirected, along with user ID parameters, to authentication system. The user device may be sent instructions to execute that collect and send back device characteristic information to the authentication system. The authentication can create a unique fingerprint of the device, and determine if the fingerprint has been seen before. If seen before, the authentication system may send back an authentication token indicating the additional factor of authentication was a success. If the fingerprint has not been seen previously, the authentication system may conduct a one-time password authentication as the additional factor. If successful, the fingerprint may be stored in association with the user device for future authentication as an additional factor.

Claims (86)

1. A computerized fingerprint-based authentication system comprising:

one or more hardware processors configured to cause the authentication system to:

receive, over a network, a request for authentication of a user computing device associated with a user, the request resulting from a redirection operation sent to the user computing device;

communicate a one-time password to the user for an initial authentication;

receive, over the network, the one-time password from the user computing device;

send, over the network, to the user computing device capture instructions, the capture instructions configured to cause the user computing device to collect a plurality of characteristic values of the user computing device, the plurality of the characteristic values representing at least two attributes of the user computing device;

receive, over the network, the plurality of characteristic values of the user computing device;

create a device fingerprint value associated with the user computing device based on the plurality of characteristics of the user computing device;

store the device fingerprint value and the plurality of characteristics in data storage; and

transmit an authentication token to the user computing device, the authentication token indicating that the user computing device has been authenticated by a fingerprinting mechanism.

2. The computerized fingerprint-based authentication system of claim 1 , wherein the at least two attributes of the user computing device comprise one or more of:

a browser type value,

a plurality of browser plugin values,

a plurality of browser flash fonts,

at least one display resolution size value,

at least one value associated with HTML5 local storage,

at least one HTTP header value,

at least one networking address value,

a time zone value,

a language value,

a plurality of browser-accepted language values,

a plurality of browser encoding values,

an IP address value, and

at least one value associated with browser cookie data.

3. The computerized fingerprint-based authentication system of claim 1 , wherein the one-time password is communicated by at least one of: SMS, telephony, push notification, or email.

4. The computerized fingerprint-based authentication system of claim 1 , wherein generation of the device fingerprint value comprises the application of a hash algorithm to at least a portion of the plurality of characteristic values.

5. The computerized fingerprint-based authentication system of claim 1 , wherein the fingerprint-based authentication system is configured to store the device fingerprint value in an active directory.

6. The computerized fingerprint-based authentication system of claim 1 , wherein the fingerprint-based authentication system is configured to store the device fingerprint value over the network in remote data storage.

7. The computerized fingerprint-based authentication system of claim 1 , wherein the fingerprint-based authentication system is configured to store the device fingerprint value in local data storage.

8. The computerized fingerprint-based authentication system of claim 1 , wherein the authentication token is configured to allow a plurality of distinct network services to accept the authentication token in lieu of authenticating an additional factor with the fingerprint-based authentication system.

9. The computerized fingerprint-based authentication system of claim 1 , wherein the request for device fingerprint registration comprises profile information, the profile information comprising a user identifier value, and at least one of: a user email address value, a telephone number value, or an SMS number value.

10. The computerized fingerprint-based authentication system of claim 1 , wherein the request for authentication indicates an additional certificate-based factor of authentication is required by a network service to authenticate the user.

11. A computerized method for registering a device fingerprint for a user computing device, the method comprising:

by one or more hardware computer processors:

receiving, over a network, a request for authentication for a user computing device associated with a user, the request resulting from a redirection operation sent to the user computing device;

communicate a one-time password to the user for an initial authentication;

receiving, over the network, the one-time password from the user computing device;

sending, over the network, to the user computing device capture instructions, the capture instructions configured to cause the user computing device to collect a plurality of characteristic values of the user computing device, the plurality of the characteristic values representing at least two attributes of the user computing device;

receiving, over the network, the plurality of characteristic values of the user computing device;

generating a device fingerprint value associated with the user computing device based on the plurality of characteristics of the user computing device;

storing the device fingerprint value and the plurality of characteristics in data storage; and

transmitting an authentication token to the user computing device, the authentication token indicating that the user computing device was authenticated by a fingerprinting mechanism.

12. The computerized method of claim 11 , wherein the at least two attributes of the user computing device comprise one or more of:

a browser type value,

a plurality of browser plugin values,

a plurality of browser flash fonts,

at least one display resolution size value,

at least one value associated with HTML5 local storage,

at least one HTTP header value,

at least one networking address value,

a time zone value,

a language value,

a plurality of browser-accepted language values,

a plurality of browser encoding values,

an IP address value, and

at least one value associated with browser cookie data.

13. The computerized method of claim 11 , wherein the one-time password is communicated by at least one of: SMS, telephony, push notification, or email.

14. The computerized method of claim 11 , wherein generation of the device fingerprint value comprises the application of a hash algorithm to at least a portion of the plurality of characteristic values.

15. The computerized method of claim 11 , wherein the device fingerprint value is stored in one or more of an active directory, a remote data storage, or a local data storage.

16. The computerized method of claim 11 , further comprising allowing a plurality of distinct network services to accept the authentication token in lieu of authenticating an additional factor.

17. The computerized method of claim 11 , wherein the request for device fingerprint registration comprises profile information, the profile information comprising a user identifier value, and at least one of: a user email address value, a telephone number value, or an SMS number value.

18. A non-transitory computer storage medium which stores a program comprising executable code that directs a computing device to perform a process that registers a fingerprint for a user computing device, comprising:

receiving, over a network, a request to authenticate a user computing device associated with a user, the request resulting from a redirection operation sent to the user computing device;

communicate a one-time password to the user for an initial authentication;

receiving, over the network, the one-time password from the user computing device;

sending, over the network, to the user computing device capture instructions, the capture instructions configured to cause the user computing device to collect a plurality of characteristic values of the user computing device, the plurality of the characteristic values representing at least two attributes of the user computing device;

receiving, over the network, the plurality of characteristic values of the user computing device;

generating a device fingerprint value associated with the user computing device based on the plurality of characteristics of the user computing device; and

storing the device fingerprint value and the plurality of characteristics in data storage.

19. The non-transitory computer storage medium of claim 18 , wherein the at least two attributes of the user computing device comprise one or more of:

a browser type value,

a plurality of browser plugin values,

a plurality of browser flash fonts,

at least one display resolution size value,

at least one value associated with HTML5 local storage,

at least one HTTP header value,

at least one networking address value,

a time zone value,

a language value,

a plurality of browser-accepted language values,

a plurality of browser encoding values,

an IP address value, and

at least one value associated with browser cookie data.

20. The non-transitory computer storage medium of claim 18 , wherein generation of the device fingerprint value comprises the application of a hash algorithm to at least a portion of the plurality of characteristic values.

21. The non-transitory computer storage medium of claim 18 , wherein the device fingerprint value in stored in one or more of an active directory, a remote data storage, or a local data storage.

22. The non-transitory computer storage medium of claim 18 , wherein the request for authentication indicates an additional certificate based factor of authentication is required by a network service to authenticate the user.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 070086/0011 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 070086/0158 →
RELEASE OF SECURITY INTEREST Recorded Aug 14, 2024
From: MIDTOWN MADISON MANAGEMENT LLC (AS SUCCESSOR TO ELM PARK CAPITAL MANAGEMENT, LLC)
To: SECUREAUTH CORPORATION
Reel/Frame 068288/0856 →
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2024
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 068251/0496 →
SECURITY INTEREST Recorded Oct 27, 2021
From: SECUREAUTH CORPORATION
To: ELM PARK CAPITAL MANAGEMENT, LLC
Reel/Frame 057937/0732 →
SECURITY INTEREST Recorded Jan 3, 2018
From: SECUREAUTH CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 044522/0031 →
RELEASE OF SECURITY INTEREST Recorded Dec 18, 2017
From: WESTERN ALLIANCE BANK
To: SECUREAUTH CORPORATION
Reel/Frame 044899/0635 →
SECURITY INTEREST Recorded Aug 8, 2016
From: SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 039368/0463 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2015
From: GRAJEK, GARRET FLORIAN; LIU, CHIHWEI; QUACH, ALLEN YU; LO, JEFFREY CHIWAI
To: SECUREAUTH CORPORATION
Reel/Frame 035279/0763 →