IP Library Granted Patent US 11,698,957
Granted Patent B2
US 11,698,957 · App. 16/904,017 · Granted Jul 11, 2023

Pre-registration of authentication devices

Inventors: Jakob Ehrensvärd (Palo Alto, CA); Christopher Harrell (San Jose, CA); Jerrod Chong (Palo Alto, CA)
Assignee: Yubico AB
G06F21/44G06F21/62H04L63/06H04L63/0876G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,698,957
App. No.
16/904,017
Granted
Jul 11, 2023
Kind
B2
Abstract

A system is disclosed for pre-registering authentication devices. A security key provider system may receive a request to pre-register a security key with identified applications from an enterprise. Responsive to receiving the request, the security key provider system instructs the security key to generate a unique authentication code for each of the applications. The security key provider system may generate pre-registration information based on the authentication codes and pre-register the authentication codes of the security key to the applications by providing the pre-registration information to the applications on behalf of the enterprise. The security key provider system may instead provide the pre-registration information to the enterprise to allow the enterprise to pre-register the authentication codes.

Claims (34)

1. A method for pre-registering a plurality of security keys to one or more applications including an application, the method comprising:

receiving, by a security key provider system, an instruction to pre-register the plurality of security keys to the application from an enterprise, wherein the plurality of security keys are physical devices, each physical device associated with a user of the enterprise;

identifying, by the security key provider system, respective authentication codes generated by the plurality of security keys to pre-register each respective security key of the plurality of security keys to the application, wherein each authentication code comprises a respective public key and a respective private key; and

pre-registering, by the security key provider system, a respective public key of a respective authentication code of each security key to the application, wherein, responsive to determining a respective user attempt to authenticate with the application after the pre-registering by interaction with a respective security key, the application grants access to the respective user using the respective authentication code without requiring registration, by the respective user, of the respective security key, based on the respective private key of the respective security key matching the respective public key, and wherein the pre-registering is performed for the plurality of security keys at a same time in batch.

2. The method of claim 1 , wherein pre-registering the authentication code of the security key to the application comprises uploading, by the security key provider system, the authentication code to the application.

3. The method of claim 1 , wherein pre-registering the authentication code of the security key to the application comprises providing the authentication code to the enterprise, the authentication code uploaded to the application by the enterprise.

4. The method of claim 1 , wherein pre-registering the authentication code of the security key to the application comprises:

emulating a connection to the application; and

providing the authentication code to the application through the emulated connection.

5. The method of claim 1 , wherein the security key is pre-registered to a set of applications comprising the application, and wherein the security key is pre-registered to each application of the set of application with a different authentication code.

6. The method of claim 1 , wherein the application is associated with a plurality of sites, and the plurality of sites are pre-registered with a same authentication code.

7. The method of claim 1 , wherein the application is associated with a plurality of domains, and the plurality of domains are pre-registered with a same authentication code.

8. The method of claim 1 , wherein the security key is pre-registered to the application under a plurality of accounts, each of the plurality of accounts pre-registered with a different authentication code.

9. The method of claim 1 , wherein the authentication code comprises a public key and a private key, wherein the public key is transmitted to the application in pre-registering the application, and wherein the application authenticates the user based on the private key matching the public key.

10. A non-transitory computer-readable medium comprising computer program instructions that, when executed by one or more computer processors, cause the processor to perform steps comprising:

receiving, by a security key provider system, an instruction to pre-register a plurality of security keys to an application from an enterprise, wherein the plurality of security keys are physical devices, each physical device associated with a user of the enterprise;

identifying, by the security key provider system, respective authentication codes generated by the plurality of security keys to pre-register each respective security key of the plurality of security keys to the application, wherein each authentication code comprises a respective public key and a respective private key; and

pre-registering, by the security key provider system, a respective public key of a respective authentication code of each security key to the application, wherein, responsive to determining a respective user attempt to authenticate with the application after the pre-registering by interaction with a respective security key, the application grants access to the respective user using the respective authentication code without requiring registration, by the respective user, of the respective security key, based on the respective private key of the respective security key matching the respective public key, and wherein the pre-registering is performed for the plurality of security keys at a same time in batch.

11. The non-transitory computer-readable medium of claim 10 , wherein pre-registering the authentication code to the security key comprises uploading the authentication code to the application.

12. The non-transitory computer-readable medium of claim 10 , wherein pre-registering the authentication code to the security key comprises providing the authentication code to the enterprise, the authentication code uploaded to the application by the enterprise.

13. The non-transitory computer-readable medium of claim 10 , wherein pre-registering the authentication code to the security key comprises:

emulating a connection to the application; and

providing the authentication code to the application through the emulated connection.

14. A system comprising:

one or more processors; and

a non-transitory computer-readable medium comprising computer program instructions that, when executed by the one or more processors, causes the one or more processors to perform steps comprising:

receiving, by a security key provider system, an instruction to pre-register a plurality of security keys to an application from an enterprise, wherein the plurality of security keys are physical devices, each physical device associated with a user of the enterprise;

identifying, by the security key provider system, respective authentication codes generated by the plurality of security keys to pre-register each respective security key of the plurality of security keys to the application, wherein each authentication code comprises a respective public key and a respective private key; and

pre-registering, by the security key provider system, a respective public key of a respective authentication code of each security key to the application, wherein, responsive to determining a respective user attempt to authenticate with the application after the pre-registering by interaction with a respective security key, the application grants access to the respective user using the respective authentication code without requiring registration, by the respective user, of the respective security key, based on the respective private key of the respective security key matching the respective public key, and wherein the pre-registering is performed for the plurality of security keys at a same time in batch.

15. The system of claim 14 , wherein pre-registering the authentication code of the security key to the application comprises uploading, by the security key provider system, the authentication code to the application.

16. The system of claim 14 , wherein pre-registering the authentication code of the security key to the application comprises providing the authentication code to the enterprise, the authentication code uploaded to the application by the enterprise.

17. The system of claim 14 , wherein pre-registering the authentication code to the security key comprises:

emulating a connection to the application; and

providing the authentication code to the application through the emulated connection.

Assignments (3)
MERGER Recorded Nov 30, 2023
From: YUBICO AB
To: ACQ BURE AB
Reel/Frame 065713/0908 →
CHANGE OF NAME Recorded Nov 30, 2023
From: ACQ BURE AB
To: YUBICO AB
Reel/Frame 065724/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2020
From: EHRENSVÄRD, JAKOB; HARRELL, CHRISTOPHER; CHONG, JERROD
To: YUBICO AB
Reel/Frame 053195/0762 →