IP Library › Granted Patent US 10,862,689
Granted Patent B1
US 10,862,689 · App. 16/520,247 · Granted Dec 8, 2020

Verification of client identities based on non-distributed data

Inventors: Evgeni Aizikovich (Petach-Tikva, IL); Boris Spivak (Petach-Tikva, IL); Michael Yavnilovich (Petach-Tikva, IL); Tal Kandel (Pardes Hana-Karkur, IL); Hadas Elkabir (Hod Hasharon, IL)
Assignee: CYBERARK SOFTWARE LTD.
H04L9/3242H04L9/0825H04L9/0866H04L9/0894H04L9/3234
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,862,689
App. No.
16/520,247
Granted
Dec 8, 2020
Kind
B1
Abstract

Disclosed embodiments relate to verifying identities based on identity-inherent data that is inaccessible to the system. Techniques include receiving, from a client, an encrypted token, the encrypted token having been encrypted at the client using a cryptographic key created at the client based on identity-inherent data of an identity of the client; wherein the identity-inherent data of the identity is not itself received by the system, and wherein the cryptographic key is accessible only to the client; and storing the encrypted token in association with a hash of a decrypted version of the encrypted token to allow for comparing the stored hash with a created hash and determining whether to verify the identity based on a result of the comparing.

Claims (38)

1. A system for verifying identities based on identity-inherent data that is inaccessible to the system, the system comprising:

a memory storing software instructions; and

a hardware-based processor configured to execute the software instructions to perform operations comprising:

receiving, from a client, an encrypted token, the encrypted token having been encrypted at the client using a cryptographic key created at the client based on identity-inherent data of an identity of the client;

wherein the identity-inherent data of the identity is not itself received by the system, and wherein the cryptographic key is accessible only to the client;

storing the encrypted token in association with a client-created hash of a decrypted version of the encrypted token;

comparing the stored client-created hash with a created hash; and

determining whether to verify the identity based on a result of the comparing.

2. The system of claim 1 , wherein the operations further comprise computing the created hash.

3. The system of claim 1 , wherein the operations further comprise:

transmitting the encrypted token to the client;

receiving from the client a client-decrypted version of the encrypted token, the client-decrypted version of the encrypted token having been decrypted by the client using the cryptographic key based on identity-inherent data of the identity of the client; and

computing, based on the received client-decrypted version of the encrypted token, the created hash.

4. The system of claim 1 , wherein the identity-inherent data of the identity is at least one of: biometric data, biological data, personal verification data, or signature data associated with a human user or application.

5. The system of claim 1 , wherein the operations further comprise transmitting an encryption key to the client.

6. The system of claim 5 , wherein the client is configured to encrypt, using the transmitted encryption key, at least one of: a client-decrypted version of the encrypted token or the client-created hash based on the client-decrypted version of the encrypted token.

7. The system of claim 6 , wherein the operations further comprise decrypting, using a key corresponding to the transmitted encryption key, the at least one of: the client-decrypted version of the encrypted token or the client-created hash.

8. The system of claim 7 , wherein the transmitted encryption key is a public key and the key corresponding to the transmitted encryption key is a private key.

9. The system of claim 1 , wherein the receiving of the encrypted token from the client is part of a registration process for the client.

10. The system of claim 1 , wherein the operations further comprise transmitting the encrypted token to the client in response to a request from the client for access to a secure resource requiring authentication.

11. A computer-implemented method for verifying identities based on identity-inherent data that is inaccessible to a system, the method comprising:

receiving, from a client, an encrypted token, the encrypted token having been encrypted at the client using a cryptographic key created at the client based on identity-inherent data of an identity of the client;

wherein the identity-inherent data of the identity is not itself received by the system, and wherein the cryptographic key is accessible only to the client;

storing the encrypted token in association with a client-created hash of a decrypted version of the encrypted token;

comparing the stored client-created hash with a created hash; and

determining whether to verify the identity based on a result of the comparing.

12. The computer-implemented method of claim 11 , further comprising computing the created hash.

13. The computer-implemented method of claim 11 , further comprising:

transmitting the encrypted token to the client;

receiving from the client a client-decrypted version of the encrypted token, the client-decrypted version of the encrypted token having been decrypted by the client using the cryptographic key based on identity-inherent data of the identity of the client; and

computing, based on the received client-decrypted version of the encrypted token, the created hash.

14. The computer-implemented method of claim 11 , wherein the identity-inherent data of the identity is at least one of: biometric data, biological data, personal verification data, or signature data associated with a human user or application.

15. The computer-implemented method of claim 11 , further comprising transmitting an encryption key to the client.

16. The computer-implemented method of claim 15 , wherein the client is configured to encrypt, using the transmitted encryption key, at least one of: a client-decrypted version of the encrypted token or the client-created hash based on the client-decrypted version of the encrypted token.

17. The computer-implemented method of claim 16 , further comprising decrypting, using a key corresponding to the transmitted encryption key, the at least one of: the client-decrypted version of the encrypted token or the client-created hash.

18. The computer-implemented method of claim 17 , wherein the transmitted encryption key is a public key and the key corresponding to the transmitted encryption key is a private key.

19. The computer-implemented method of claim 11 , wherein the receiving of the encrypted token from the client is part of a registration process for the client.

20. The computer-implemented method of claim 11 , further comprising transmitting the encrypted token to the client in response to a request from the client for access to a secure resource requiring authentication.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2019
From: AIZIKOVICH, EVGENI; SPIVAK, BORIS; YAVNILOVICH, MICHAEL; KANDEL, TAL; ELKABIR, HADAS
To: CYBERARK SOFTWARE LTD.
Reel/Frame 049839/0104 →
Cited By (2)
US 12,362,947 US 12,432,048