IP Library Granted Patent US 11,665,006
Granted Patent B2
US 11,665,006 · App. 17/187,693 · Granted May 30, 2023

User authentication with self-signed certificate and identity verification

Inventors: Nelson Melo (West Palm Beach, FL); Michael Clark (West Palm Beach, FL); James Clark (West Palm Beach, FL)
Assignee: Beyond Identity Inc.
H04L9/3265G06F16/214G06F16/2379G06F21/46H04L9/0825H04L9/0861H04L9/0894H04L9/14H04L9/3073H04L9/3268H04L9/3271H04L63/0428H04L63/061H04L63/083H04L63/0823H04L63/126H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,665,006
App. No.
17/187,693
Granted
May 30, 2023
Kind
B2
Abstract

In embodiments, an authentication server interfaces between a user device with a self-signed certificate and a verifying computer that accepts a user name and password. The user device generates a self-signed certificate signed by a private key on the user device. The self-signed certificate is transmitted to a verifying party computer over a network. The verifying party stores the self-signed certificate with user identification data, including at least one of a user name, user address, user email, user phone number, user tax ID, user social security number and user financial account number. In subsequent communications, the verifying party receives a certificate chain including the self-signed certificate, and matches that with the user identification data stored in a database.

Claims (55)

1. A method for authenticating a user to a verifying party computer over a network, comprising:

generating a self-signed root certificate signed by a root private key on a user device;

storing the root private key externally to the user device;

generating an intermediate private key from a secure enclave on the user device;

signing an intermediate certificate with the root private key;

storing the intermediate private key in the secure enclave on the user device;

linking the intermediate certificate to the root certificate by way of signature to form a certificate chain, the certificate chain including a public key corresponding to the intermediate private key;

transmitting the certificate chain to the verifying party computer over the network;

receiving, as an input to the user device, user identification data, including at least one of a user name, user address, user email, user phone number, user tax ID, user social security number and user financial account number;

using a certificate chain as a credential to transmit user verification data to a verifying party computer;

storing the certificate chain in association with the user identification data in a database by the verifying party computer;

receiving, at the verifying party computer, a subsequent communication from the user device including the certificate chain;

accessing the database by the verifying party computer with the certificate chain to retrieve the user identification data;

determining that the self-signed root certificate belongs to the user by:

issuing a challenge question to the user device, by the verifying party computer, using the intermediate public key to encrypt the challenge question;

decrypting the challenge question by the user device using the intermediate private key; and

sending, by the user device, a response to the verifying computer challenge question, encrypted with the intermediate private key.

2. A method for authenticating a user to a verifying party computer over a network, comprising:

generating a self-signed root certificate signed by a root private key on a user device;

generating an intermediate private key from a secure enclave on the user device;

signing an intermediate certificate with the root private key;

linking the intermediate certificate to the root certificate to form a certificate chain, the certificate chain including a public key corresponding to the intermediate private key;

transmitting the certificate chain to the verifying party computer over the network;

transmitting user identification data to the verifying party computer for linking with the certificate chain; and

transmitting the certificate chain to the verifying party computer in a subsequent communication to identify the user without the user identification data.

3. The method of claim 2 further comprising:

determining that the self-signed root certificate belongs to the user by:

issuing a challenge question to the user device, by the verifying party computer, using the user public key to encrypt the challenge question;

decrypting the challenge question by the user device using the intermediate private key; and

sending, by the user device, a response to the verifying computer challenge question, encrypted with the intermediate private key.

4. The method of claim 2 further comprising:

storing, by the user device, the intermediate private key in a signing application in a memory of the user device.

5. The method of claim 2 further comprising:

storing, by the user device, the root private key externally to the user device.

6. The method of claim 5 , wherein the step of storing the root private key externally to the user device further comprises:

encoding the root private key as a visual code and printing the visual code.

7. A non-transitory computer readable medium having stored thereon software instructions that, when executed by a processor, cause the processor to generate control signals for authenticating a user to a verifying party computer over a network, by executing the steps comprising:

generating a self-signed root certificate signed by a root private key on a user device;

generating an intermediate private key from a secure enclave on the user device;

signing an intermediate certificate with the root private key;

linking the intermediate certificate to the root certificate to form a certificate chain, the certificate chain including a public key corresponding to the intermediate private key;

transmitting the certificate chain to the verifying party computer over the network;

transmitting user identification data to the verifying party computer for linking with the certificate chain; and

transmitting the certificate chain to the verifying party computer in a subsequent communication to identify the user without the user identification data.

8. The non-transitory computer readable medium of claim 7 wherein the software instructions, when executed by a processor, further cause the processor to generate control signals to execute the steps comprising:

determining that the self-signed root certificate belongs to the user by:

issuing a challenge question to the user device, by the verifying party computer, using the user public key to encrypt the challenge question;

decrypting the challenge question by the user device using the intermediate private key; and

sending, by the user device, a response to the verifying computer challenge question, encrypted with the intermediate private key.

9. The non-transitory computer readable medium of claim 7 wherein the software instructions, when executed by a processor, further cause the processor to generate control signals to execute the steps comprising:

storing, by the user device, the intermediate private key in a signing application in a memory of the user device.

10. The non-transitory computer readable medium of claim 7 wherein the software instructions, when executed by a processor, further cause the processor to generate control signals to execute the steps comprising:

storing, by the user device, the root private key in an external electronic device.

11. The non-transitory computer readable medium of claim 10 wherein the software instructions, when executed by a processor, further cause the processor to generate control signals to execute the steps comprising:

encoding the root private key as a visual code and printing the visual code.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2023
From: MELO, NELSON; CLARK, MICHAEL; CLARK, JAMES
To: ZEROPW INC.
Reel/Frame 063382/0220 →
CHANGE OF NAME Recorded Apr 19, 2023
From: ZEROPW INC.
To: BEYOND IDENTITY INC.
Reel/Frame 063399/0728 →
Continuity (7)
Continuation 16931777 · Jul 17, 2020
Continuation 16796021 · Feb 20, 2020
Provisional Application 62809490 · Feb 22, 2019
Provisional Application 62842393 · May 2, 2019
Provisional Application 62857201 · Jun 4, 2019
Provisional Application 62858248 · Jun 6, 2019
Related Publication 20210184867A1 · Jun 17, 2021
Cited By (2)
US 12,450,319 US 12,452,232