IP Library Granted Patent US 12,489,746
Granted Patent B2
US 12,489,746 · App. 17/956,740 · Granted Dec 2, 2025

App free authentication across channels

Inventors: Justin Chin (Raleigh, NC); John Hamilton Kimble, II (Allen, TX)
Assignee: Ping Identity International, Inc.
H04L63/0853H04L63/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,746
App. No.
17/956,740
Granted
Dec 2, 2025
Kind
B2
Abstract

The technology disclosed teaches performing biometric app free authentication or authorization of a user to access a web-based application, with the user interacting with a workstation browser running on a workstation to access the web-based application using built-in resources of a smart/mobile device. A web application uses methods to authenticate and authorize users before the users are permitted to access the application. A demand exists for improving the security and ease of use of authentication and access management. Access management and authentication of users has evolved to more than just entering a username and password. Multi-factor authentication (MFA) is common. The numerous paths involved in authentication use numerous forms of identification of users during the authentication journey. An opportunity arises to combine paths used for non-standard circumstances with device codes and biometrics for users to log into web applications conveniently and securely without installing another app for authentication and authorization.

Claims (46)

1 . A method of app free authentication or authorization of a user to access a web-based application, wherein the user is interacting with a workstation browser running on a workstation to access the web-based application and using resources of a smart/mobile device for biometric authentication, including:

using the workstation browser, requesting access to the web-based application and sending an authorization server at least a username;

receiving, at the workstation browser, an encoding of parameters including at least a user code or the username plus a universal resource indicator (URI), and transmitting a version of the encoding to the smart/mobile device;

using the smart/mobile device to process the version of the encoding, including decoding at least the user code or the username plus the URI and using decoded parameters to initiate contact, directly or indirectly, with the authorization server;

receiving a message from the authorization server triggering biometric authentication by the smart/mobile device;

using biometric authentication resources of the smart/mobile device, authenticating the user, signing the message to define a signed message and sending the signed message to the authorization server; and

receiving, at the workstation browser, access to the web-based application, responsive to the signed message.

2 . The method of claim 1 , wherein the version of the encoding transmitted to the smart/mobile device is a QR code.

3 . The method of claim 2 , wherein the QR code encodes the user code, the username and the URI.

4 . The method of claim 1 , wherein the version of the encoding transmitted to the smart/mobile device is by near field communications (NFC) or Bluetooth.

5 . The method of claim 1 , wherein the URI is a universal resource locator (URL).

6 . The method of claim 1 , further including in the encoding received at the workstation browser both the URI and a universal resource locator (URL).

7 . The method of claim 1 , further including in the encoding received at the workstation browser the user code, the username and the URI assigned by the authorization server.

8 . A method of app free authentication or authorization by an authorization server of a user to access a web-based application using a workstation browser running on a workstation, and further using resources of a smart/mobile device for biometric authentication, including:

receiving at the authorization server a request from the workstation browser for access to the web-based application, the request including at least a username of the user;

sending the workstation browser an encoding of parameters including at least a user code or the username plus a universal resource indicator (URI), in a format suitable for transmission to the smart/mobile device;

receiving from the smart/mobile device a call made to the URI to initiate biometric authentication by the smart/mobile device;

sending the smart/mobile device approval to proceed with biometric authentication for access to the web-based application;

receiving a signed message from the smart/mobile device indicating successful biometric authentication using the resources of the smart/mobile device, authenticating the user responsive to the signed message and generating a token held by the authorization server that authorizes the workstation browser to access the web-based application; and

sending the workstation browser a redirection for access to the web-based application.

9 . The method of claim 8 , wherein the encoding sent to the workstation browser for transmission to the smart/mobile device is a QR code.

10 . The method of claim 9 , wherein the QR code encodes the user code, the username and the URI.

11 . The method of claim 8 , wherein the encoding sent to the workstation browser for transmission to the smart/mobile device is by near field communications (NFC) or Bluetooth.

12 . The method of claim 8 , wherein the URI is a universal resource locator (URL).

13 . The method of claim 8 , further including in the encoding sent to the workstation browser both the URI and a universal resource locator (URL).

14 . The method of claim 8 , further including in the encoding sent to the workstation browser the user code, the username and the URI assigned by the authorization server.

15 . A non-transitory computer readable media impressed with instructions that, when executed on processing hardware of a workstation and a smart/mobile device, cause the processing hardware to implement actions for app free authentication or authorization for a user to access a web-based application, wherein the user is interacting with a workstation browser running on the workstation to access the web-based application and using resources of the smart/mobile device for biometric authentication, the actions including:

using the workstation browser, requesting access to the web-based application and sending an authorization server at least a username;

receiving at the workstation browser an encoding of parameters including at least a user code or the username plus a universal resource indicator (URI), and transmitting a version of the encoding to the smart/mobile device;

using the smart/mobile device to process the version of the encoding, including decoding at least the user code or the username plus the URI and using decoded parameters to initiate contact, directly or indirectly, with the authorization server;

receiving a message from the authorization server triggering biometric authentication by the smart/mobile device;

using biometric authentication resources of the smart/mobile device, authenticating the user, signing the message to define a signed message and sending the signed message to the authorization server; and

receiving, at the workstation browser, access to the web-based application, responsive to the signed message.

16 . The non-transitory computer readable media of claim 15 , wherein the version of the encoding sent to the workstation browser for transmission to the smart/mobile device is a QR code.

17 . A computer system including a workstation having memory, a workstation browser, and a smart/mobile device, wherein the non-transitory computer readable media of claim 15 includes the memory of the workstation and memory of the smart/mobile device holding respective parts of the instructions.

18 . The computer system of claim 17 , wherein a version of the encoding implemented by the instructions to be sent to the workstation browser for transmission to the smart/mobile device is a QR code.

19 . A non-transitory computer readable media impressed with instructions that, when executed on processing hardware of a workstation and a smart/mobile device, cause the processing hardware to implement actions for app free authorization by an authorization server of a user to access a web-based application using a workstation browser running on the workstation and using resources of the smart/mobile device for biometric authentication, the actions including:

receiving at the authorization server a request from the workstation browser for access to the web-based application, the request including at least a username of the user;

sending the workstation browser an encoding of parameters including at least a user code or the username plus a universal resource indicator (URI), in a format suitable for transmission to the smart/mobile device;

receiving from the smart/mobile device a call made to the URI to initiate biometric authentication by the smart/mobile device;

sending the smart/mobile device approval to proceed with biometric authentication for access to the web-based application;

receiving a signed message from the smart/mobile device indicating successful biometric authentication using the resources of the smart/mobile device, authenticating the user responsive to the signed message and generating a token held by the authorization server that authorizes the workstation browser to access the web-based application; and

sending the workstation browser a redirection for access to the web-based application.

20 . The non-transitory computer readable media of claim 19 , wherein a version of the encoding sent to the workstation browser for transmission to the smart/mobile device is a QR code.

21 . A computer system including the authorization server having memory, wherein the non-transitory computer readable media of claim 19 includes the memory of the authorization server holding the instructions.

22 . The computer system of claim 21 , wherein a version of the encoding implemented by the instructions to be sent to the workstation browser for transmission to the smart/mobile device is a QR code.

Assignments (3)
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: FORGEROCK, INC.
To: PING IDENTITY INTERNATIONAL, INC.
Reel/Frame 066358/0483 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2022
From: CHIN, JUSTIN; KIMBLE, JOHN HAMILTON, II
To: FORGEROCK, INC.
Reel/Frame 061340/0522 →
Continuity (1)
Related Publication 20240121238A1 · Apr 11, 2024
References Cited (102)
US 6633898B1 · Seguchi et al. · 2003 [cited by applicant]
US 8887262B1 · Turner · 2014 [cited by examiner]
US 9167428B2 · Buntinx · 2015 [cited by examiner]
US 9363259B2 · Chenna · 2016 [cited by examiner]
US 9369457B2 · Grajek · 2016 [cited by examiner]
US 9720750B1 · Abrams et al. · 2017 [cited by applicant]
US 9887992B1 · Venkat · 2018 [cited by examiner]
US 10158489B2 · Shastri · 2018 [cited by examiner]
US 10265694B2 · Aizenberg et al. · 2019 [cited by applicant]
US 10299118B1 · Karachiwala · 2019 [cited by examiner]
US 10303576B1 · Seymour et al. · 2019 [cited by applicant]
US 10630501B2 · Ansari et al. · 2020 [cited by applicant]
US 10686885B2 · Goyal et al. · 2020 [cited by applicant]
US 10705808B2 · Chiosi et al. · 2020 [cited by applicant]
US 10742634B1 · Shahbazi · 2020 [cited by examiner]
US 10812473B2 · Ramesh Kumar · 2020 [cited by examiner]
US 10817346B1 · Culp et al. · 2020 [cited by applicant]
US 10922284B1 · Venkatasubramanian et al. · 2021 [cited by applicant]
US 10938940B2 · Alla · 2021 [cited by applicant]
US 11030299B1 · Ilincic · 2021 [cited by examiner]
US 11075791B2 · Prathipati et al. · 2021 [cited by applicant]
US 11165581B2 · Hunt · 2021 [cited by examiner]
US 11321983B2 · Seenivasagam · 2022 [cited by examiner]
US 11347560B2 · Culp et al. · 2022 [cited by applicant]
US 11374759B2 · Pellizzer · 2022 [cited by examiner]
US 11394712B2 · Monica · 2022 [cited by examiner]
US 11405189B1 · Bennison · 2022 [cited by examiner]
US 11562055B2 · Tussy · 2023 [cited by examiner]
US 11777992B1 · Cross et al. · 2023 [cited by applicant]
US 11831754B2 · Barbir · 2023 [cited by examiner]
US 11895225B2 · Bennison · 2024 [cited by examiner]
US 20130111208A1 · Sabin · 2013 [cited by examiner]
US 20130167208A1 · Shi · 2013 [cited by examiner]
US 20130262857A1 · Neuman · 2013 [cited by examiner]
US 20130262858A1 · Neuman · 2013 [cited by examiner]
US 20130262873A1 · Read · 2013 [cited by examiner]
US 20140007205A1 · Oikonomou · 2014 [cited by examiner]
US 20140316797A1 · Biernacki et al. · 2014 [cited by applicant]
US 20150205708A1 · Michelsen · 2015 [cited by applicant]
US 20150341344A1 · Dorfman · 2015 [cited by examiner]
US 20160036809A1 · Bhimanaik · 2016 [cited by examiner]
US 20170118025A1 · Shastri · 2017 [cited by examiner]
US 20170257363A1 · Franke · 2017 [cited by examiner]
US 20170295062A1 · Tang · 2017 [cited by applicant]
US 20170359339A1 · Hevizi · 2017 [cited by examiner]
US 20180088982A1 · Abrams et al. · 2018 [cited by applicant]
US 20180197128A1 · Carstens et al. · 2018 [cited by applicant]
US 20190356693A1 · Cahana et al. · 2019 [cited by applicant]
US 20190384662A1 · Bonnell · 2019 [cited by applicant]
US 20190391897A1 · Vijendra et al. · 2019 [cited by applicant]
US 20200034254A1 · Natanzon · 2020 [cited by applicant]
US 20200073655A1 · Park et al. · 2020 [cited by applicant]
US 20200136987A1 · Nakfour · 2020 [cited by applicant]
US 20200162255A1 · Hunt · 2020 [cited by examiner]
US 20200236113A1 · Monica · 2020 [cited by examiner]
US 20200236116A1 · Bower · 2020 [cited by examiner]
US 20200280517A1 · Kwon et al. · 2020 [cited by applicant]
US 20210004253A1 · Barnes et al. · 2021 [cited by applicant]
US 20210049684A1 · Chen · 2021 [cited by examiner]
US 20210072966A1 · Zong et al. · 2021 [cited by applicant]
US 20210082575A1 · Ji et al. · 2021 [cited by applicant]
US 20210112072A1 · Kratzer · 2021 [cited by examiner]
US 20210173940A1 · Mylrea et al. · 2021 [cited by applicant]
US 20210256111A1 · Ilincic · 2021 [cited by examiner]
US 20210400075A1 · Stergioudis et al. · 2021 [cited by applicant]
US 20220030036A1 · Cirelli et al. · 2022 [cited by applicant]
US 20220070201A1 · Almaz et al. · 2022 [cited by applicant]
US 20220150237A1 · Canfield · 2022 [cited by examiner]
US 20220191247A1 · Dhoble et al. · 2022 [cited by applicant]
US 20220345297A1 · Barbir · 2022 [cited by examiner]
US 20240089117A1 · Vivek · 2024 [cited by examiner]
US 20240121238A1 · Chin · 2024 [cited by examiner]
US 20240380750A1 · Xie · 2024 [cited by examiner]
U.S. Appl. No. 16/579,740, filed Sep. 23, 2019, U.S. Pat. No. 10,817,346, Oct. 27, 2020, Issued. [cited by applicant]
U.S. Appl. No. 17/068,653, filed Oct. 12, 2020, U.S. Pat. No. 11,347,560, May 31, 2022, Issued. [cited by applicant]
U.S. Appl. No. 17/550,916, filed Dec. 14, 2021, U.S. Pat. No. 11,720,410, Aug. 8, 2023, Issued. [cited by applicant]
U.S. Appl. No. 18/231,160, filed Aug. 7, 2023, Pending. [cited by applicant]
U.S. Appl. No. 17/673,692, filed Feb. 16, 2022, 20220263833, Aug. 18, 2022, Allowed. [cited by applicant]
U.S. Appl. No. 18/503,114, filed Nov. 6, 2023, Pending. [cited by applicant]
Hodges et al, Web Authentication an API for accessing Public Key Credentials—Level 2, Section 1.2, W3C, Apr. 8, 2021, pp. 9-12(downloaded Aug. 24, 2022 from https://www.w3.org/TR/webauthn-2/#sctn-usecase-registration). [cited by applicant]
OAuth 2.0 Guide ForgeRock Access Management 7.1.2, ForgeRock, Inc, May 18, 2022, 236 pages. [cited by applicant]
Denniss et al., RFC 8628, OAuth 2.0 Device Authorization Grant, Internet Engineering Task Force (IETF), Jan. 2020, 21 pages (https://www.rfc-editor.org/info/rfc8628f). [cited by applicant]
Orluc, “QRCode login with ForgeRock Identity Cloud,” Medium, Feb. 2022, 10 pages (downloaded Feb. 24, 2022 from https://stephane-orluc.medium.com/qrcode-login-with-forgerock-identity-cloud-bb34ab2aea67). [cited by applicant]
Microsoft identity platform and the OAuth 2.0 device authorization grant flow, Microsoft Docs, Feb. 18, 2022, 7 pages (downloaded on Mar. 16, 2022 from https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-… [cited by applicant]
Iris Recognition vs Retinal Scanning—Is there A Difference?, RightPatient, 2022, 6 pages (downloaded on Apr. 12, 2022 from https://www.rightpatient.com/biometric-patient-identification-system-custom-reference-and-resour… [cited by applicant]
ForgeRock Identity Cloud documentation, ForgeRock, Inc, May 19, 2022, 293 pages. [cited by applicant]
Cichonski et al., “Computer Security Incident Handling Guide”, National Institute of Standards and Technology, U.S. Department of Commerce, Special Publication 800-61, Revision 2, http://dx.doi.org/10.6028/NIST.SP.800-6… [cited by applicant]
“Hardening your cluster's security”, Kubernetes Engine, (https://cloud.google.com/kubernetes-engine/docs/concepts/security-overview), Jul. 2019, 10 pages. [cited by applicant]
Dempsey, et al., “Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations”, NIST National Institute of Standards and Technology, U.S. Dept. of Commerce, NIST Special Publicati… [cited by applicant]
“Configuring Vertical Pod Autoscaling”, Kubernetes Engine, Google Cloud (https://cloud.google.com/kubernetes-engine/), Aug. 14, 2019, 8 pages. [cited by applicant]
Wilkin, “Kubernetes Deployment Dependencies”, https://medium.com/google-cloud/kubernetes-deployment-dependencies-ef703e563956, Jul. 2, 2018, 21 pages. [cited by applicant]
“Vertical Pod Autoscaling”, Kubernetes Engine, https://cloud.google.com/kubernetes-engine/docs/concepts/verticalpodautoscaler), Aug. 29, 2019, 8 pages. [cited by applicant]
Sakimura et al., “OpenID Connect Dynamic Client Registration 1.0 incorporating errata set 1”, https://openid.net/specs/openid-connect-registration-1_0.html, Oct. 1, 2019, 19 pages. [cited by applicant]
Jayanandana, “Enable Rolling updates in Kubernetes with Zero downtime”, https://medium.com/platformer-blog/enable-rolling-updates-in-kubernetes-with-zero-downtime-31d7ec.388c81, Sep. 27, 2018, 6 pages. [cited by applicant]
“FAQ: IDM/OpenIDM performance and tuning”, https://backstage.forgerock.com/knowledge/kb/article/a32504603, Jun. 26, 2019, 7 pages. [cited by applicant]
Amazon; AWS Elastic Beanstalk Developer Guide; Aug. 2019; 924 pgs (https://web.archive.org/web/20190805110626/https:// docs.aws.amazon.com/elasticbeanstalk/latest/dg/awseb-dg.pdf). [cited by applicant]
Amazon; AWS Elastic Beanstalk Developer Guide API version Dec. 1, 2012 dated Nov. 14, 2016, 965 pgs. [downloaded Aug. 9, 2023 from https://web.archive.org/web/20161114152137/https://docs.aws.amazon.com/elasticbeanstalk/… [cited by applicant]
Protect Users Witthout Frustrating Them Using AI-Driven Behavorial Biometrics, White Pater, Behavion Sec, 2020, (retrieved Dec. 14, 2021 from https://www.behaviosec.com/wp-content/uploads/2020/11/bhs-whitepaper.pdf). [cited by applicant]
Behavioral Biometrics for Mobile, BioCatch, 2021, 3 pages (retrieved Dec. 14, 2021 from https://www.biocatch.com/hubfs/New%20Boilerplate/BC%20SB%20Mobile%20Data%20v6%20NBP.pdf). [cited by applicant]
Innovating the Customer Experience Without Opening Fraud Floodgates, BioCatch, 10 pages (retrieved Dec. 14, 2021 from https://www.biocatch.com/hubfs/WP-Innovate-Customer-Experience-Without-Fraud.pdf). [cited by applicant]
Threat Matrix Guide, ID Dataweb, 7 pages (retrieved Dec. 14, 2021 from https://docs.iddataweb.com/docs/threatmetrix-1). [cited by applicant]
Zimny, Marcin, “Trust vs Authority in Access Recovery Procedures”, IAM World, Marcin's Identity and Access Management Blog, Aug. 18, 2022, 6 pgs, (dowloaded Jun. 26, 2023 from https://iamworld.co.uk/wp/2022/08/18/trust-… [cited by applicant]