IP Library Granted Patent US 10,587,609
Granted Patent B2
US 10,587,609 · App. 15/449,902 · Granted Mar 10, 2020

Method and system for authenticated login using static or dynamic codes

Inventors: Armin Ebrahimi (Los Gatos, CA); Gaurav Khot (Cupertino, CA); Vladimir Reshetnikov (San Jose, CA); Robert Gadbois (Los Gatos, CA)
Assignee: ShoCard, Inc.
H04L63/083G06F21/31G06F21/645H04L9/3236H04L9/3247H04L9/3271H04L9/3297H04L63/0435H04L63/0442H04L63/061H04L63/08H04L63/0861H04L63/0876H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,587,609
App. No.
15/449,902
Granted
Mar 10, 2020
Kind
B2
Abstract

Method of authentication including sending a login web page to a first device of a user including a scannable code having an envelope ID and a login challenge. The envelope ID generated by an identity manager is associated with a first envelope of data including a session ID. A confirmation login request is received from a second device associated with the user, and includes a second envelope of data comprising the session ID, a user ID, and a seal of the user ID registering the user ID with the identity manager. The confirmation login request to the login challenge is verified using the session ID, and the user is verified using the user ID and seal. User login is authorized upon successful verification of the login challenge and user, and a communication session having the session ID is established between the web server and the first device.

Claims (52)

1. A method of authentication, comprising:

at a web server, sending a login web page to a first device associated with a user, wherein the login web page includes a scannable code comprising an envelope ID and a login challenge, wherein the envelope ID is associated with a first envelope of data comprising a session ID, wherein the envelope ID is generated by an identity manager at a request of the web server;

receiving a confirmation login request responding to the login challenge from a second device associated with the user, wherein the confirmation login request includes a second envelope of data comprising the session ID, a user ID, and a seal of the user ID registering the user ID;

verifying the confirmation login request to the login challenge using the session ID from the confirmation login request;

verifying the user ID based on the seal of the user ID, including:

extracting a transaction number from the seal of the user ID;

accessing transaction data from a blockchain using the transaction number, wherein the transaction data comprises a public key of the user and a first signature of a first hash of the user ID, wherein the first signature is generated using a private key of the user;

generating a second hash of the user ID by hashing the user ID from the second envelope of data;

signing the second hash using the public key of the user to generate a second signature; and

confirming the user when the first signature matches the second signature;

authorizing user login upon successful verification of the login challenge and user ID; and

establishing a communication session having the session ID between the web server and the first device.

2. The method of claim 1 , further comprising:

receiving a request for the login web page from the first device at the web server;

generating the session ID in response to the request for the login web page;

generating the first envelope of data;

sending the first envelope of data to the identity manager over a network, wherein the identity manager generates the envelope ID corresponding to the first envelope of data;

receiving the envelope ID from the identity manager;

generating the scannable code including the envelope ID and the login challenge; and

generating the login web page including the scannable code.

3. The method of claim 1 , wherein the scannable code is scanned by a second device of the user to obtain the envelope ID, wherein the second device retrieves the first envelope from the identity manager using the envelope ID, wherein the second device accesses the Session ID from the first envelope.

4. The method of claim 1 , further comprising:

generating a digital signature by signing the data to be included within the first envelope with a private key of the web server; and

including the digital signature of the data and a public key of the web server within the first envelope of data so that the first envelope of data can be trusted.

5. The method of claim 1 , wherein the receiving a response comprises:

decrypting the second envelope of data using a private key of the web server, wherein the second envelope of data is encrypted using a public key of the web server.

6. The method of claim 1 , wherein the verifying the confirmation login request further comprises:

verifying the session ID in the confirmation login request is valid; and

confirming that the session ID has not timed-out.

7. The method of claim 6 , wherein the verifying the session ID further comprises:

determining that the session ID in the confirmation login request is valid when it matches the session ID in the first envelope of data.

8. The method of claim 1 , wherein the verifying the user ID further comprises:

certifying the user using the user ID and a certification seal included in the second envelope of data.

9. The method of claim 1 , wherein the scannable code comprises one of a QR code, bar code, and PDF417 code.

10. The method of claim 1 , wherein the user ID comprises a public key of the user.

11. A method for authentication, comprising:

on a second device associated with a user, scanning a first scannable code on a login web page of a web server displayed on a first device associated with the user, wherein the first scannable code comprises an envelope ID and a login challenge, wherein the envelope ID is associated with a first envelope of data generated by the web server and comprising a session ID, wherein the envelope ID is generated by an identity manager at the request of the web server, wherein the envelope ID is used to request the first envelope of data from the identity manager;

generating a challenge envelope of data comprising a shared-string generated by the second device, a first digital signature of a hash of the shared-string using a private key of the user, and a user ID;

sending the challenge envelope of data to the web server over a network;

on the second device, scanning a second scannable code on an updated login web page displayed on the first device, wherein the second scannable code comprises a challenge response including the shared-string and a second digital signature of the hash of the shared-string using a private key of the web server;

verifying the second digital signature using a public key of the web server;

at the second device, generating a confirmation login request responding to the login challenge, wherein the confirmation login request includes a second envelope of data comprising the shared-string, the session ID, the user ID, and a seal of the user ID registering the user ID with the identity manager; and

sending the confirmation login request to the web server via the identity manager for authentication and login of the user with the web server.

12. The method of claim 11 , further comprising:

encrypting the challenge envelope of data using the public key of the web server.

13. The method of claim 11 , wherein the web server verifies the confirmation login request using the session ID from the confirmation login request, wherein the web server verifies the user using the user ID and seal, wherein the web server authorizes user login upon successful verification of the login challenge and user, and wherein a communication session having the session ID is established between the web server and the first device.

14. The method of claim 11 , further comprising:

sending a request to the identity manager for the first envelope of data, wherein the request includes the envelope ID; and

receiving the first envelope of data from the identity manager.

15. The method of claim 11 , further comprising:

decrypting the challenge response including the shared-string and a second digital signature using a private key of the user, wherein the challenge response is encrypted using the public key of the user by the web server.

16. The method of claim 11 , wherein the first scannable code comprises one of a QR code, bar code, and pdf 417 code.

Assignments (10)
RELEASE OF SECURITY INTEREST AT R/F 61703/0988 Recorded Nov 14, 2025
From: BLUE OWL CAPITAL CORPORATION
To: PING IDENTITY CORPORATION
Reel/Frame 073570/0777 →
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
RELEASE OF SECURITY INTEREST Recorded Oct 19, 2022
From: BANK OF AMERICA, N.A.
To: PING IDENTITY CORPORATION
Reel/Frame 061709/0527 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Oct 18, 2022
From: PING IDENTITY CORPORATION
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 061703/0988 →
SECURITY INTEREST Recorded Nov 23, 2021
From: PING IDENTITY CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 058944/0687 →
RELEASE OF SECURITY INTEREST Recorded Nov 23, 2021
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: SHOCARD, LLC
Reel/Frame 058195/0683 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2020
From: SHOCARD, LLC
To: PING IDENTITY CORPORATION
Reel/Frame 052889/0793 →
CHANGE OF NAME Recorded Apr 17, 2020
From: SHOCARD, INC.
To: SHOCARD, LLC
Reel/Frame 052435/0009 →
PATENT SECURITY AGREEMENT Recorded Apr 1, 2020
From: SHOCARD, LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 052291/0082 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2017
From: EBRAHIMI, ARMIN; KHOT, GAURAV; RESHETNIKOV, VLADIMIR; GADBOIS, ROBERT
To: SHOCARD, INC.
Reel/Frame 041586/0491 →
Continuity (4)
Provisional Application 62304144 · Mar 4, 2016
Provisional Application 62304934 · Mar 7, 2016
Provisional Application 62455199 · Feb 6, 2017
Related Publication 20170257358A1 · Sep 7, 2017
Cited By (89)
US 12,206,696 US 12,244,621 US 12,267,345 US 12,309,185 US 12,314,351 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,279 US 12,457,231 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,513,221 US 12,518,278 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,932 US 12,706,933 US 12,712,897 US 12,719,671 US 12,719,896