IP Library Granted Patent US 11,025,619
Granted Patent B2
US 11,025,619 · App. 16/135,835 · Granted Jun 1, 2021

Biometric identity registration and authentication

Inventor: Yuanbo Sun (Hangzhou, CN)
Assignee: Advanced New Technologies Co., Ltd.
H04L63/0861G06F21/32H04L9/006H04L9/0825H04L9/32H04L9/3213H04L9/3231H04L9/3234H04L9/3247H04L9/3263H04L29/06H04L63/0876H04L63/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,025,619
App. No.
16/135,835
Granted
Jun 1, 2021
Kind
B2
Abstract

An authentication information request packet of user equipment is received at an authentication server. The authentication information request packet includes a device identity of the user equipment. A virtual account identity corresponding to the device identity is obtained. The authentication information response packet is signed using a server private key. An authentication request packet of the user equipment is received. The authentication request packet includes the device identifier, the virtual account identity, and a biometric feature token. A registered service public key and a registered biometric feature token corresponding to the device identifier, the virtual account identity, and a biometric authentication type are obtained. A signature verification is performed by the authentication server on the authentication request packet using the registered service public key. An identity authentication is performed based on the biometric feature token in the authentication request packet and the registered biometric feature token.

Claims (67)

1. A computer-implemented method, comprising:

receiving, at an authentication server and from a service server, a first authentication information request packet of a user equipment, wherein the first authentication information request packet includes a device identity of the user equipment;

obtaining, by the authentication server, a registered virtual account identity corresponding to the device identity;

encapsulating, by the authentication server, the registered virtual account identity into an authentication information response packet;

signing, by the authentication server, the authentication information response packet using an authentication server private key;

forwarding, by the authentication server through the service server, the authentication information response packet to the user equipment;

performing, by the user equipment, a first signature verification on the authentication information response packet using a registered authentication server public key, wherein the registered authentication server public key corresponds to the authentication server private key;

in response to a successful first signature verification, receiving, by the authentication server, from the user equipment through the service server, a second authentication request packet signed by the user equipment using a user equipment private key, wherein the second authentication request packet includes the device identity of the user equipment, the registered virtual account identity, and a biometric feature token, and wherein the second authentication request packet originates at the user equipment and provided to the authentication server through the service server;

verifying, by the authentication server, the second authentication request packet based on an authentication verification code and a time interval between the forwarding of the authentication information response packet and receiving the second authentication request packet;

obtaining, by the authentication server, a registered user equipment public key that corresponds to the user equipment private key and a registered biometric feature token corresponding to the device identity, the registered virtual account identity, and a biometric authentication type;

performing, by the authentication server, a second signature verification on the second authentication request packet using the registered user equipment public key; and

performing, by the authentication server, an identity authentication based on the biometric feature token in the second authentication request packet and the registered biometric feature token.

2. The computer-implemented method of claim 1 , wherein performing the identity authentication comprises performing a comparison of the biometric feature token included in the second authentication request packet and the registered biometric feature token.

3. The computer-implemented method of claim 1 , wherein a biometric identity of a user of the user equipment is authenticated if the second signature verification succeeds, and if the biometric feature token and the registered biometric feature token are determined to be identical.

4. The computer-implemented method of claim 1 , further comprising:

in response to an unsuccessful first signature verification, determining, by the user equipment, that the authentication server is not reliable.

5. The computer-implemented method of claim 1 , further comprising:

in response to an unsuccessful second signature verification, or in response to determining that the biometric feature token and the registered biometric feature token are different, determining, by the authentication server, the user equipment is not authenticated; and

sending, from the authentication server to the user equipment through the service server, an authentication failure result.

6. The computer-implemented method of claim 1 , further comprising:

determining, by the authentication server, that a biometric identity of a user of the user equipment is authenticated; and

sending, from the authentication server to the service server, a third authentication response packet, wherein the third authentication response packet comprises an identity authentication success result.

7. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

receiving, at an authentication server and from a service server, a first authentication information request packet of a user equipment, wherein the first authentication information request packet includes a device identity of the user equipment;

obtaining, by the authentication server, a registered virtual account identity corresponding to the device identity;

encapsulating, by the authentication server, the registered virtual account identity into an authentication information response packet;

signing, by the authentication server, the authentication information response packet using an authentication server private key;

forwarding, by the authentication server through the service server, the authentication information response packet to the user equipment;

performing, by the user equipment, a first signature verification on the authentication information response packet using a registered authentication server public key, wherein the registered authentication server public key corresponds to the authentication server private key;

in response to a successful first signature verification, receiving, by the authentication server, from the user equipment through the service server, a second authentication request packet signed by the user equipment using a user equipment private key, wherein the second authentication request packet includes the device identity of the user equipment, the registered virtual account identity, and a biometric feature token, and wherein the second authentication request packet originates at the user equipment and provided to the authentication server through the service server;

verifying, by the authentication server, the second authentication request packet based on an authentication verification code and a time interval between the forwarding of the authentication information response packet and receiving the second authentication request packet;

obtaining, by the authentication server, a registered user equipment public key that corresponds to the user equipment private key and a registered biometric feature token corresponding to the device identity, the registered virtual account identity, and a biometric authentication type;

performing, by the authentication server, a second signature verification on the second authentication request packet using the registered user equipment public key; and

performing, by the authentication server, an identity authentication based on the biometric feature token in the second authentication request packet and the registered biometric feature token.

8. The non-transitory, computer-readable medium of claim 7 , wherein performing the identity authentication comprises performing a comparison of the biometric feature token included in the second authentication request packet and the registered biometric feature token.

9. The non-transitory, computer-readable medium of claim 7 , wherein a biometric identity of a user of the user equipment is authenticated if the second signature verification succeeds, and if the biometric feature token and the registered biometric feature token are determined to be identical.

10. The non-transitory, computer-readable medium of claim 7 , the operations further comprises:

in response to an unsuccessful first signature verification, determining, by the user equipment, that the authentication server is not reliable.

11. The non-transitory, computer-readable medium of claim 7 , the operations further comprises:

in response to an unsuccessful second signature verification, or in response to determining that the biometric feature token and the registered biometric feature token are different, determining, by the authentication server, the user equipment is not authenticated; and

sending, from the authentication server to the user equipment through the service server, an authentication failure result.

12. The non-transitory, computer-readable medium of claim 7 , the operations further comprises:

determining, by the authentication server, that a biometric identity of a user of the user equipment is authenticated; and

sending, from the authentication server to the service server, a third authentication response packet, wherein the third authentication response packet comprises an identity authentication success result.

13. A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:

receiving, at an authentication server and from a service server, a first authentication information request packet of a user equipment, wherein the first authentication information request packet includes a device identity of the user equipment;

obtaining, by the authentication server, a registered virtual account identity corresponding to the device identity;

encapsulating, by the authentication server, the registered virtual account identity into an authentication information response packet;

signing, by the authentication server, the authentication information response packet using an authentication server private key;

forwarding, by the authentication server through the service server, the authentication information response packet to the user equipment;

performing, by the user equipment, a first signature verification on the authentication information response packet using a registered authentication server public key, wherein the registered authentication server public key corresponds to the authentication server private key;

in response to a successful first signature verification, receiving, by the authentication server, from the user equipment through the service server, a second authentication request packet signed by the user equipment using a user equipment private key, wherein the second authentication request packet includes the device identity of the user equipment, the registered virtual account identity, and a biometric feature token, and wherein the second authentication request packet originates at the user equipment and provided to the authentication server through the service server;

verifying, by the authentication server, the second authentication request packet based on an authentication verification code and a time interval between the forwarding of the authentication information response packet and receiving the second authentication request packet;

obtaining, by the authentication server, a registered user equipment public key that corresponds to the user equipment private key and a registered biometric feature token corresponding to the device identity, the registered virtual account identity, and a biometric authentication type;

performing, by the authentication server, a second signature verification on the second authentication request packet using the registered user equipment public key; and

performing, by the authentication server, an identity authentication based on the biometric feature token in the second authentication request packet and the registered biometric feature token.

14. The computer-implemented system of claim 13 , wherein performing the identity authentication comprises performing a comparison of the biometric feature token included in the second authentication request packet and the registered biometric feature token.

15. The computer-implemented system of claim 13 , the operations further comprises:

in response to an unsuccessful first signature verification, determining, by the user equipment, that the authentication server is not reliable.

16. The computer-implemented system of claim 13 , the operations further comprises:

in response to an unsuccessful second signature verification, or in response to determining that the biometric feature token and the registered biometric feature token are different, determining, by the authentication server, the user equipment is not authenticated; and

sending, from the authentication server to the user equipment through the service server, an authentication failure result.

17. The computer-implemented system of claim 13 , the operations further comprises:

determining, by the authentication server, that a biometric identity of a user of the user equipment is authenticated; and

sending, from the authentication server to the service server, a third authentication response packet, wherein the third authentication response packet comprises an identity authentication success result.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2020
From: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053754/0625 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2020
From: ALIBABA GROUP HOLDING LIMITED
To: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053743/0464 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2018
From: SUN, YUANBO
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 047601/0913 →
Cited By (2)
US 12,342,214 US 12,603,939