IP Library Granted Patent US 11,134,075
Granted Patent B2
US 11,134,075 · App. 16/227,632 · Granted Sep 28, 2021

Method and system for authenticated login using static or dynamic codes

Inventors: Armin Ebrahimi (Los Gatos, CA); Gaurav Khot (Cupertino, CA); Vladimir Reshetnikov (San Jose, CA); Robert Gadbois (Los Gatos, CA)
Assignee: Ping Identity Corporation
H04L63/083G06F21/31G06F21/645H04L9/3236H04L9/3247H04L9/3271H04L9/3297H04L29/06H04L63/0435H04L63/0442H04L63/061H04L63/08H04L63/0861H04L63/0876H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,134,075
App. No.
16/227,632
Granted
Sep 28, 2021
Kind
B2
Abstract

Method of authentication including sending a login web page to a first device of a user including a scannable code having an envelope ID and a login challenge. The envelope ID generated by an identity manager is associated with a first envelope of data including a session ID. A confirmation login request is received from a second device associated with the user, and includes a second envelope of data comprising the session ID, a user ID, and a seal of the user ID registering the user ID with the identity manager. The confirmation login request to the login challenge is verified using the session ID, and the user is verified using the user ID and seal. User login is authorized upon successful verification of the login challenge and user, and a communication session having the session ID is established between the web server and the first device.

Claims (97)

1. A method of authentication by a verification device, comprising:

scanning a first code obtained from a device of a user, wherein the first code includes trip credentials;

sending data from the trip credentials to an identity server configured to access certified user data using the data from the trip credentials, wherein the certified user data includes information obtained from a public storage facility configured for authenticating the user, the certified user data having been certified by a certifier using a certification process including:

receiving the user data based on a second code provided from a registering device of a user;

receiving an image identifier based on the second code;

accessing a seal of the user data from a blockchain;

verifying the user data using the seal of the user data to generate the certified user data;

generating a secure envelope by encrypting the certified user data using a travel secret key; and

sending a certification identifier that is associated with the secure envelope and the travel secret key to the registering device of the user;

receiving from the identity server the certified user data;

accessing biometric data of the user using the certified user data; and

performing a recognition process of the user to verify the user based on the accessed biometric data.

2. The method of claim 1 , wherein the first code includes a QR code, or a bar code, or PDF417-code, or text, or an image.

3. The method of claim 1 , wherein the performing the recognition process includes:

capturing a live image of the user; and

performing a facial recognition process to verify the user by comparing the live image to a digital image of the user, wherein the accessed biometric data includes the digital image of the user.

4. The method of claim 3 , wherein:

the trip credentials include the image identifier and an image secret key,

the method further includes:

sending the image identifier to the identity server,

receiving from the identity server an encrypted digital image of the user; and

decrypting the encrypted digital image of the user using the image secret key to obtain the digital image of the user.

5. The method of claim 4 , wherein a registration process to register the digital image of the user includes:

capturing the digital image of the user using the registering device of the user;

generating at the registering device the image secret key;

encrypting at the registering device the digital image of the user using the image secret key;

sending from the registering device the encrypted digital image of the user to the identity server for storing; and

receiving at the registering device the image identifier from the identity server, wherein the image identifier provides access to the encrypted digital image of the user.

6. The method of claim 1 , wherein:

the trip credentials include a travel identifier, the travel secret key, and an image secret key,

the sending the data from the trip credentials to the identity server includes sending the travel identifier to the identity server to access the secure envelope;

the receiving from the identity server the certified user data includes:

receiving the secure envelope from the identity server; and

decrypting the secure envelope using the travel secret key to obtain the certified user data.

7. The method of claim 1 , wherein the certified user data includes at least one of:

a token; or

a token expiration; or

a user seal identifier; or

the image identifier; or

a certifier identifier.

8. A non-transitory computer-readable medium storing a computer program for performing authentication, the computer-readable medium comprising:

program instructions for scanning a code obtained from a device of a user, wherein the code includes trip credentials;

program instructions for sending data from the trip credentials to an identity server configured to access certified user data using the data from the trip credentials, wherein the certified user data includes information obtained from a public storage facility configured for authenticating the user and including an image identifier and an image secret key;

program instructions for receiving from the identity server the certified user data;

program instructions for accessing biometric data of the user using the certified user data, the program instructions for accessing the biometric data of the user including program instructions for receiving, based on the image identifier and from the identity server, an encrypted digital image of the user;

program instructions for decrypting the encrypted digital image of the user using the image secret key to obtain a digital image of the user; and

program instructions for performing a recognition process of the user to verify the user based on the accessed biometric data, the program instructions for performing the recognition process including program instructions for:

capturing a live image of the user; and

performing a facial recognition process to verify the user by comparing the live image to the digital image of the user.

9. The non-transitory computer-readable medium of claim 8 , wherein the code includes a QR code, or a bar code, or PDF417-code, or text, or an image.

10. The non-transitory computer-readable medium of claim 8 ,

wherein-program instructions for performing a registration process to register the digital image of the user include:

program instructions for capturing the digital image of the user using a registering device of the user;

program instructions for generating at the registering device the image secret key;

program instructions for encrypting at the registering device the digital image of the user using the image secret key;

program instructions for sending from the registering device the encrypted digital image of the user to the identity server for storing; and

program instructions for receiving at the registering device the image identifier from the identity server, wherein the image identifier provides access to the encrypted digital image of the user.

11. The non-transitory computer-readable medium of claim 8 ,

wherein the trip credentials include a travel identifier and a travel secret key,

the non-transitory computer-readable medium further comprising:

program instructions for sending the travel identifier to the identity server to access a secure envelope packaging the certified user data using the travel secret key;

program instructions for receiving the secure envelope from the identity server; and

program instructions for decrypting the secure envelope using the travel secret key to obtain the certified user data.

12. The non-transitory computer-readable medium of claim 8 , wherein the certified user data includes at least one of:

a token; or

a token expiration; or

a user seal identifier; or

the image identifier; or

a certifier identifier.

13. A computer system, comprising:

a processor; and

a memory coupled to the processor and having stored therein instructions that, if executed by the computer system, cause the computer system to execute a method for performing authentication comprising:

scanning a code obtained from a device of a user, wherein the code includes trip credentials including a travel identifier and a travel secret key;

sending data from the trip credentials to an identity server configured to access certified user data using the data from the trip credentials, wherein the certified user data includes information obtained from a public storage facility configured for authenticating the user, the sending the data to the identity server includes sending the travel identifier to the identity server to access a secure envelope including the certified user data and encrypted using the travel secret key;

receiving from the identity server the secure envelope including the certified user data;

decrypting the secure envelope using the travel secret key to obtain the certified user data;

accessing biometric data of the user using the certified user data; and

performing a recognition process of the user to verify the user based on the accessed biometric data.

14. The computer system of claim 13 , wherein in the method the code includes a QR code, or a bar code, or PDF417-code, or text, or an image.

15. The computer system of claim 13 , wherein the performing the recognition process includes:

sending an image identifier to the identity server;

receiving from the identity server an encrypted digital image of the user;

decrypting the encrypted digital image of the user using an image secret key to obtain the digital image of the user,

capturing a live image of the user;

performing a facial recognition process to verify the user by comparing the live image to the digital image of the user;

wherein the certified user data includes at least one of:

a token; or

a token expiration; or

a user seal identifier; or

the image identifier; or

a certifier identifier.

16. The computer system of claim 15 , wherein performing a registration process to register the digital image of the user includes:

capturing the digital image of the user using a registering device of the user;

generating at the registering device the image secret key;

encrypting at the registering device the digital image of the user using the image secret key;

sending from the registering device the encrypted digital image of the user to the identity server for storing; and

receiving at the registering device the image identifier from the identity server, wherein the image identifier provides access to the encrypted digital image of the user.

Assignments (10)
RELEASE OF SECURITY INTEREST AT R/F 61703/0988 Recorded Nov 14, 2025
From: BLUE OWL CAPITAL CORPORATION
To: PING IDENTITY CORPORATION
Reel/Frame 073570/0777 →
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
RELEASE OF SECURITY INTEREST Recorded Oct 19, 2022
From: BANK OF AMERICA, N.A.
To: PING IDENTITY CORPORATION
Reel/Frame 061709/0527 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Oct 18, 2022
From: PING IDENTITY CORPORATION
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 061703/0988 →
SECURITY INTEREST Recorded Nov 23, 2021
From: PING IDENTITY CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 058944/0687 →
RELEASE OF SECURITY INTEREST Recorded Nov 23, 2021
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: SHOCARD, LLC
Reel/Frame 058195/0683 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2020
From: EBRAHIMI, ARMIN; KHOT, GAURAV; RESHETNIKOV, VLADIMIR; GADBOIS, ROBERT
To: SHOCARD, INC.
Reel/Frame 053010/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2020
From: SHOCARD, LLC
To: PING IDENTITY CORPORATION
Reel/Frame 052889/0793 →
CHANGE OF NAME Recorded Apr 17, 2020
From: SHOCARD, INC.
To: SHOCARD, LLC
Reel/Frame 052435/0009 →
PATENT SECURITY AGREEMENT Recorded Apr 1, 2020
From: SHOCARD, LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 052291/0082 →
Continuity (5)
Continuation 15449902 · Mar 3, 2017
Provisional Application 62304144 · Mar 4, 2016
Provisional Application 62304934 · Mar 7, 2016
Provisional Application 62455199 · Feb 6, 2017
Related Publication 20190149537A1 · May 16, 2019
Cited By (3)
US 12,198,133 US 12,259,988 US 12,518,278