IP Library Granted Patent US 12,278,901
Granted Patent B2
US 12,278,901 · App. 17/547,467 · Granted Apr 15, 2025

Systems and methods for registering or authenticating a user with a relying party

Inventors: Yolan Romailler (Cheseaux-sur-Lausanne, CH); Nils Amiet (Cheseaux-sur-Lausanne, CH)
Assignee: NAGRAVISION SARL
H04L9/3073H04L9/0894H04L9/3242H04L9/3247H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,278,901
App. No.
17/547,467
Granted
Apr 15, 2025
Kind
B2
Abstract

A method of registering or authenticating a user with a relying party is provided, the method including: receiving a request to generate a key pair, the request including key-generation data, the key-generation data including relying party information; deterministically generating, based on at least the key-generation data and a secret key stored in a memory of the authenticator, a key pair comprising a public key and a private key; either: transmitting the public key, or performing further processing using the private key; and deleting the key pair. An authenticator configured to perform the process is also provided.

Claims (60)

1. A method of registering or authenticating a user with a relying party, the method comprising:

receiving, at an authenticator, a request to generate a key pair, the request including key-generation data, the key-generation data including relying party information associated with the relying party and user information associated with the user;

deterministically generating, at the authenticator, based on the relying party information, the user information, and a secret key stored in a memory of the authenticator, a key pair comprising a public key and a private key;

one or more of transmitting the public key or performing further processing using the private key to register or authenticate the user with the relying party; and

deleting the key pair from the memory of the authenticator.

2. The method of claim 1 , wherein the key pair is an elliptic curve key pair.

3. The method of claim 2 , wherein:

either:

the memory of the authenticator stores an elliptic curve equation, a base point, and a predetermined function, or

the key-generation data includes an elliptic curve equation, a base point, and a predetermined function; and

wherein generating the key pair comprises deterministically generating an integer based on the secret key and the key-generation data; and deriving a point based on the integer and the key-generation data, wherein:

the point is the public key, and

the integer is the private key.

4. The method of claim 3 , wherein:

the method further includes applying a one-way function to a one-way-function input, the one-way-function input being based on the key-generation data, to generate a one-way-function output; and

either:

the one-way-function output is the integer; or

the method further includes generating the integer from the one-way function output.

5. The method of claim 4 , further comprising combining a salt with the one-way-function input before applying the one-way function.

6. The method of claim 4 , wherein the one-way function is a keyed one-way function, an output of which is dependent on a function key.

7. The method of claim 6 , wherein the keyed one-way function is a hash-based method authentication code (HMAC) function, and the function key is an HMAC key.

8. The method of claim 4 , further comprising combining the one-way-function output with a master key to generate the integer.

9. The method of claim 1 , wherein the key-generation data includes a tuple of data comprising at least a relying party ID and a user ID.

10. The method of claim 1 , further comprising:

receiving an authorization input from a user; and

validating the authorization input by comparing data derived from the authorization input with stored data corresponding to an expected authorization input associated with the user in question;

wherein the key pair is deterministically generated responsive to validating the authorization input.

11. The method of claim 1 , further comprising:

registering a user with the relying party; and

transmitting an attestation object to a client device of the user, the attestation object including the public key, and one or more of: a credential ID associated with the public key, and an attestation signature.

12. The method of claim 1 , wherein:

the method is a method of authenticating a user with the relying party; and

the method further comprises:

receiving authentication challenge data from a client device of the user;

generating an assertion signature using an authentication algorithm such as a digital signature algorithm; and

transmitting the generated assertion signature to the client device.

13. An authenticator for registering or authenticating a user with a relying party, the authenticator configured to:

receive a request to generate a key pair, the request including key-generation data, the key-generation data including relying party information associated with the relying party and user information associated with the user;

deterministically generate, based on the relying party information, the user information, and a secret key stored in a memory of the authenticator, a key pair comprising a public key and a private key;

one or more of transmit the public key or perform further processing using the private key to register or authenticate the user with the relying party; and

delete the key pair from the memory of the authenticator.

14. The authenticator of claim 13 , wherein:

the key pair is an elliptic curve key pair;

either:

the memory of the authenticator stores an elliptic curve equation, a base point, and a predetermined function,

or:

the key-generation data includes an elliptic curve equation, a base point, and a predetermined function; and

to generate the key pair, the authenticator is configured to deterministically generate an integer based on the secret key and the key-generation data; and deriving a point based on the integer and the key-generation data, wherein:

the point is the public key, and

the integer is the private key.

15. The authenticator of claim 14 , wherein:

the authenticator is further configured to apply a one-way function to a one-way function input, the one-way function being based on the key-generation data, to generate a one-way function output; and

either:

the one-way function output is the integer; or

the authenticator is further configured to generate an integer from the one-way function output.

16. The authenticator of claim 15 , wherein the authenticator is further configured to combine a salt with the one-way function input before applying the one-way function.

17. The authenticator of claim 15 , wherein the one-way function is a keyed one-way function, and wherein an output of the keyed one-way function is dependent on a function key.

18. The authenticator of claim 17 , wherein the keyed one-way function is a hash-based method authentication code (HMAC) function, and the function key is an HMAC key.

19. The authenticator of claim 13 , wherein the authenticator is a standalone device including an interface for connecting with a client device.

20. The authenticator of claim 13 , wherein the authenticator is a module on an electronic device.

Assignments (2)
CHANGE OF NAME Recorded Sep 29, 2023
From: NAGRAVISION S.A.
To: NAGRAVISION SARL
Reel/Frame 065075/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2022
From: ROMAILLER, YOLAN; AMIET, NILS
To: NAGRAVISION S.A.
Reel/Frame 060791/0345 →
Priority Claims (1)
EP 20213896 · Dec 14, 2020 · regional
Continuity (1)
Related Publication 20220191023A1 · Jun 16, 2022
References Cited (19)
US 4731841A · Rosen · 1988 [cited by examiner]
US 8412943B2 · Pang · 2013 [cited by examiner]
US 9800411B1 · Brown · 2017 [cited by examiner]
US 10075437B1 · Costigan et al. · 2018 [cited by applicant]
US 10990779B1 · Johanson · 2021 [cited by examiner]
US 11888997B1 · Bowen · 2024 [cited by examiner]
US 20190149337A1 · Savanah et al. · 2019 [cited by applicant]
US 20190190723A1 · Lee · 2019 [cited by examiner]
US 20200280550A1 · Lindemann et al. · 2020 [cited by applicant]
US 20220300962A1 · Zia · 2022 [cited by examiner]
US 20230334491A1 · Leddy, III · 2023 [cited by examiner]
European Search Report dated Jun. 1, 2021 for European Patent Application No. 20213896.2, 8 pages. [cited by applicant]
“Web Authentication: An API for accessing Public Key Credentials, Level 1” retrieved from https://www.w3.org/TR/webauthn-1/ on Apr. 13, 2022. 8 pages. [cited by applicant]
“Client to Authenticator Protocol (CTAP)” retrieved from https://fidoalliance.org/specs/fido-v2.0-ps-20190130/fido-client-to-authenticator-protocol-v2.0-ps-20190130.html on Apr. 13, 2022, 5 pages. [cited by applicant]
“Replacing passwords with FIDO2 updated slides and resources” Kudelski Security Research retrieved from https://research.kudelskisecurity.com/2020/07/08/replacing-passwords-with-fido2-updated-slides-and-resources/ on Ap… [cited by applicant]
“FIDO2: Solving the Password Problem”—Kudelski Security Research, retrieved from https://research.kudelskisecurity.com/2019/10/08/fido2-solving-the-password-problem/ on Apr. 13, 2022, 26 pages. [cited by applicant]
“FIDO2: Deep Dive: Attestations, Trust model and Security” Kudelski Security Research retrieved from https://research.kudelskisecurity.com/2020/02/12/fido2-deep-dive-attestations-trust-model-and-security/ on Apr. 13, 20… [cited by applicant]
“Web Authentication: An API for accessing Public Key Credentials, Level 2” retrieved from https://www.w3.org/TR/webauthn/#sctn-attestation on Apr. 13, 2022, 174 pages. [cited by applicant]
“Standards for Efficient Cryptography SEC 1: Elliptic Curve Cryptography” retrieved from https://www.secg.org/sec1-v2.pdf on Apr. 13, 2022, 8 pages. [cited by applicant]