IP Library Granted Patent US 12,316,626
Granted Patent B2
US 12,316,626 · App. 17/475,159 · Granted May 27, 2025

Device authentication via high-entropy token

Inventor: Jeffrey Robert Naujok (Colorado Springs, CO)
Assignee: Prove Identity, Inc.
H04L63/0838H04L9/0861H04L63/0428H04W12/03H04W12/068H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,626
App. No.
17/475,159
Granted
May 27, 2025
Kind
B2
Abstract

Briefly, example methods, apparatuses, and/or articles of manufacture may be implemented to authenticate a communicating device via a communications network. One embodiment may include obtaining, at the communicating device, signals representative of one or more high-entropy tokens via the communications network, the one or more high-entropy tokens including one or more component tokens. The method may additionally include encrypting one or more parameters utilizing a first encryption key derived from at least one component token of the one or more component tokens and transmitting, via the communications network, one or more signals representative of the encrypted one or more parameters. The method may further include obtaining, at the communicating device, one or more signals indicating an outcome of a comparison between the one or more encrypted parameters with one or more similar parameters encrypted by an identity verifier.

Claims (77)

1. A method of authenticating a communicating device via a communications network, the method comprising:

obtaining, at the communicating device, signals representative of one or more high-entropy tokens via the communications network, the one or more high-entropy tokens comprising one or more component tokens;

encrypting one or more parameters utilizing a first encryption key derived from at least one component token of the one or more component tokens;

transmitting, via the communications network, one or more signals representative of the encrypted one or more parameters; and

obtaining, at the communicating device, one or more signals indicating an outcome of a comparison between the one or more encrypted parameters with one or more similar parameters encrypted by an identity verifier.

2. The method of claim 1 , further comprising generating an additional encryption key based, at least in part, on at least one fresh component token.

3. The method of claim 2 , wherein generating the additional encryption key is based, at least in part, on at least one component token of the one or more component tokens in combination with the at least one fresh component token.

4. The method of claim 3 , wherein transmitting the one or more signals is to indicate that at least one expiring component token, of the one or more component tokens, is expiring within a predetermined time period.

5. The method of claim 4 , further comprising generating at least one fresh high-entropy token based, at least in part, on the at least one fresh component token.

6. The method of claim 5 , wherein generating the at least one fresh high-entropy token comprises:

appending the at least one fresh component token to a high-entropy token of the one or more high-entropy tokens; and

discarding the at least one expiring component token.

7. The method of claim 1 , further comprising:

transmitting one or more signals to indicate at least one expiring component token; and

transmitting a signal representative of a parameter specific to the communicating device.

8. A method of authenticating a communicating device via a communications network, comprising:

determining, via a subscriber identifier, whether the communicating device is a known communicating device operating within the communications network;

transmitting signals representative of one or more high-entropy tokens to the communicating device, the one or more high-entropy tokens comprising one or more component tokens;

obtaining one or more encrypted parameters, the one or more encrypted parameters generated utilizing at least one of the one or more component tokens; and

compare the one or more obtained encrypted parameters with one or more similar parameters encrypted via an identity verifier.

9. The method of claim 8 , further comprising

determining that at least one component token is to expire based, at least in part, on one or more indications from the communicating device that a time-to-live parameter is scheduled to expire within a predetermined time period.

10. The method of claim 9 , further comprising:

responsive to determining that at least one component token has expired, generating a fresh high-entropy token by:

appending at least one fresh component token to a portion of a high-entropy token of the one or more high-entropy tokens; and

discarding the at least one expired component token.

11. The method of claim 9 , wherein the one or more indications from the communicating device are received within a period of no more than 10 days.

12. The method of claim 11 , further comprising:

generating an upgraded trustworthiness score responsive to receiving the one or more indications received within the period of no more than 10 days.

13. The method of claim 9 , further comprising:

revoking a bind between or among the identity verifier and the communicating device responsive to passage of a threshold number of consecutive intervals without receipt of at least one indication, of the one or more indications, from the communicating device.

14. The method of claim 13 , further comprising:

generating a degraded trustworthiness score corresponding to the communicating device responsive to revoking the bind between or among the identity verifier and the communicating device.

15. The method of claim 8 , further comprising:

in response to detecting that a high-entropy token is currently in use by more than one communicating device:

invalidating the high-entropy token.

16. The method of claim 15 , further comprising:

transmitting a one-time password exclusively to a communicating device of the more than one communicating devices; and

transmitting a previously unused high-entropy token to the communicating device of the more than one communicating devices.

17. The method of claim 15 , further comprising:

accessing a data store comprising the subscriber identifier and an Internet protocol address corresponding to the communicating device.

18. The method of claim 8 , further comprising:

authenticating one or more additional communicating devices via:

transmitting a one-time password to the one or more additional communicating devices or to the known communicating device;

establishing a communications link between the one or more additional communicating devices; and

obtaining the one-time password via the established communication link.

19. The method of claim 18 further comprising:

transmitting signals representative of one or more additional high-entropy tokens to the one or more additional communicating devices responsive to authenticating, wherein the one or more additional communicating devices correspond to devices having a universally unique identifier (UUID) assigned by the identity verifier.

20. An apparatus comprising:

a processor coupled to at least one memory device to:

obtain, at a communicating device, signals representative of one or more high-entropy tokens transmitted via a communications network, the one or more high-entropy tokens comprising one or more component tokens;

encrypt, utilizing a first encryption key derived from at least one component token of the one or more component tokens, one or more parameters to be transmitted from the communicating device to an identity verifier;

transmit, via the communications network, one or more signals representative of the encrypted one or more parameters; and

obtain, at the communicating device, one or more signals indicating an outcome of a comparison between the encrypted one or more parameters with one or more similar parameters encrypted by the identity verifier.

21. The apparatus of claim 20 , wherein the processor coupled to the at least one memory is additionally to:

transmit, within a period of no greater than 10 days, one or more indications that at least one component token of the one or more component tokens is to expire within a predetermined time period.

22. The apparatus of claim 20 , wherein the processor coupled to the at least one memory device to transmit one or more signals to indicate at least one expiring component token is additionally to:

transmit a signal representative of a parameter specific to the communicating device.

23. The apparatus of claim 20 , wherein the processor coupled to the at least one memory is additionally to:

generate an additional encryption key based, at least in part, on at least one fresh component token obtained at the communicating device responsive to expiration of at least one component token of the one or more component tokens.

24. The apparatus of claim 23 , wherein the processor coupled to the at least one memory is additionally to:

generate at least one fresh high-entropy token based, at least in part, on the at least one fresh component token.

25. An apparatus to authenticate a communicating device via a communications network, comprising:

a processor coupled to at least one memory to:

recognize, via a subscriber identifier, the communicating device as a known device operating within the communications network;

transmit signals representative of one or more high-entropy tokens to the communicating device, the one or more high-entropy tokens comprising one or more component tokens;

obtain one or more encrypted parameters, the one or more encrypted parameters generated utilizing at least one of the one or more component tokens; and

compare the one or more obtained encrypted parameters with one or more similar parameters encrypted via an identity verifier.

26. The apparatus of claim 25 , wherein the processor coupled to the at least one memory is additionally to:

receive, within a period of no more than 10 days, one or more indications of at least one expiring component token.

27. The apparatus of claim 26 , wherein the processor coupled to the at least one memory is additionally to:

generate an upgraded trustworthiness score responsive to receipt of the one or more indications.

28. The apparatus of claim 26 , wherein the processor coupled to the at least one memory is additionally to:

responsive to detecting expiration of at least one component token of the one or more component tokens, generate a fresh high-entropy token by appending the at least one fresh component token to a portion of a high-entropy token of the one or more high-entropy tokens.

29. The apparatus of claim 25 , wherein the processor coupled to the at least one memory is additionally to:

revoke a bind between or among the identity verifier and the communicating device responsive to passage of a time period greater a threshold number of days without receipt of one or more indications of at least one expiring token.

30. The apparatus of claim 29 , wherein the threshold number of days corresponds to no more than 10 days.

Assignments (3)
CHANGE OF NAME Recorded May 1, 2024
From: PAYFONE, INC.
To: PROVE IDENTITY, INC.
Reel/Frame 067282/0935 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2024
From: NAUJOK, JEFFREY ROBERT
To: PROVE IDENTITY, INC.
Reel/Frame 067269/0146 →
CHANGE OF NAME Recorded Apr 30, 2024
From: PAYFONE, INC.
To: PROVE IDENTITY, INC.
Reel/Frame 067274/0307 →
Continuity (1)
Related Publication 20230085137A1 · Mar 16, 2023
References Cited (57)
US 7644434B2 · Pollutro · 2010 [cited by examiner]
US 8606640B2 · Brody · 2013 [cited by applicant]
US 10693872B1 · Larson et al. · 2020 [cited by applicant]
US 10868724B2 · Rzezak · 2020 [cited by examiner]
US 11076001B1 · Mohamad · 2021 [cited by applicant]
US 11165586B1 · Rule et al. · 2021 [cited by applicant]
US 20080084870A1 · Taylor · 2008 [cited by examiner]
US 20080201401A1 · Pugh · 2008 [cited by applicant]
US 20100130169A1 · Narayanaswamy et al. · 2010 [cited by applicant]
US 20110047610A1 · Mylavarapu · 2011 [cited by examiner]
US 20140053241A1 · Norrman · 2014 [cited by applicant]
US 20150296379A1 · Nix · 2015 [cited by applicant]
US 20160105540A1 · Kwon · 2016 [cited by applicant]
US 20160277930A1 · Li · 2016 [cited by applicant]
US 20170041964A1 · Yerli · 2017 [cited by applicant]
US 20190028443A1 · Chin · 2019 [cited by examiner]
US 20190037401A1 · Egner et al. · 2019 [cited by applicant]
US 20190312878A1 · Brown et al. · 2019 [cited by applicant]
US 20190327609A1 · Schell et al. · 2019 [cited by applicant]
US 20200374694A1 · Fan et al. · 2020 [cited by applicant]
US 20200380598A1 · Spector · 2020 [cited by examiner]
US 20200412539A1 · Uy · 2020 [cited by applicant]
US 20210029522A1 · Cao · 2021 [cited by applicant]
US 20210081632A1 · Batchu · 2021 [cited by applicant]
US 20210105142A1 · Lee et al. · 2021 [cited by applicant]
U.S. Appl. No. 17/183,208: Final Office Action dated Mar. 9, 2023, 37 pages, Doc 1901. [cited by applicant]
U.S. Appl. No. 17/407,041: Notice of Publication dated Feb. 23, 2023, pp. 1, Doc 1902. [cited by applicant]
U.S. Appl. No. 17/407,041: Non-Final Office Action dated Feb. 27, 2023, 32 pages, Doc 1903. [cited by applicant]
U.S. Appl. No. 17/183,208: Advisory Action dated Aug. 26, 2022, 8 pages, Doc 1854. [cited by applicant]
U.S. Appl. No. 17/183,208: RCE & Response to Final Office Action dated Sep. 8, 2022, 30 pages, Doc 1855. [cited by applicant]
U.S. Appl. No. 17/183,208: Non-final Office Action dated Oct. 4, 2022, 29 pages, Doc 1856. [cited by applicant]
U.S. Appl. No. 17/183,208: Patent Application filed Feb. 23, 2021, 61 pages, Doc 1803. [cited by applicant]
U.S. Appl. No. 17/183,208: Filing Receipt dated Mar. 10, 2021, 3 pages, Doc 1804. [cited by applicant]
U.S. Appl. No. 17/183,208: Non-final Office Action dated Jan. 14, 2022, 27 pages, Doc 1805. [cited by applicant]
U.S. Appl. No. 17/183,208: Amendment filed Apr. 14, 2022, 23 pages, Doc 1806. [cited by applicant]
PCT/US22/16568: PCT Application filed Feb. 16, 2022, 63 pages, Doc 1807. [cited by applicant]
PCT/US22/16568: International Search Report and Written Opinion dated Mar. 4, 2022, 13 pages, Doc 1808. [cited by applicant]
U.S. Appl. No. 17/407,041: Patent Application filed Aug. 19, 2021, 67 pages, Doc 1809. [cited by applicant]
U.S. Appl. No. 17/407,041: Filing Receipt and Notice to File Missing Parts dated Aug. 31, 2021, 6 pages, Doc 1810. [cited by applicant]
U.S. Appl. No. 17/407,041: Response to File Missing Parts filed Oct. 7, 2021, 6 pages, Doc 1811. [cited by applicant]
U.S. Appl. No. 17/407,041: Updated Filing Receipt dated Oct. 13, 2021, 4 pages, Doc 1812. [cited by applicant]
U.S. Appl. No. 17/183,208: Final Office Action dated Jun. 9, 2022, 29 pages, Doc 1843. [cited by applicant]
U.S. Appl. No. 17/183,208: Response to Final Office Action dated Aug. 1, 2022, 25 pages, Doc 1844. [cited by applicant]
U.S. Appl. No. 17/183,208: AFCP Request & Response to Final Office Action filed May 9, 2023, pages, Doc 1956. [cited by applicant]
U.S. Appl. No. 17/183,208: Advisory Action dated Jun. 2, 2023, pages, Doc 1957. [cited by applicant]
U.S. Appl. No. 17/183,208: RCE & Amendment filed Jun. 9, 2023, 30 pages, Doc 1958. [cited by applicant]
U.S. Appl. No. 17/183,208: Notice of Allowance & Allowability dated Jul. 19, 2023, 14 pages, Doc 1959. [cited by applicant]
BR Application No. 1120230168767: Brazil Application filed Aug. 22, 2023, 39 pages, Doc 1952. [cited by applicant]
CA Application No. 3209181: Canada Application filed Aug. 21, 2023, 75 pages, Doc 1953. [cited by applicant]
EP Application No. 22760222.4: European Application filed Aug. 21, 2023, 6 pages, Doc 1954. [cited by applicant]
IN Application No. 202347056479: India Application filed Aug. 23, 2023, 59 pages, Doc 1955. [cited by applicant]
U.S. Appl. No. 17/407,041: Response to Non-Final Office Action filed May 30, 2023, 20 pages, Doc 1960. [cited by applicant]
U.S. Appl. No. 17/407,041: Final Office Action dated Aug. 28, 2023, 21 pages, Doc 1961. [cited by applicant]
U.S. Appl. No. 17/183,208: Response to Non-Final Office Action filed Jan. 9, 2023, 25 pages, Doc 1869. [cited by applicant]
PCT Application No. PCT/US22/16568: Demand & Response to Written Opinion filed Dec. 22, 2022, 31 pages, Doc 1880. [cited by applicant]
PCT Application No. PCT/US22/39174: PCT Application filed Aug. 2, 2022, 65 pages, Doc 1870. [cited by applicant]
PCT Application No. PCT/US22/39174: International Search Report and Written Opinion dated Dec. 6, 2022, 13 pages, Doc 1871. [cited by applicant]