IP Library Granted Patent US 12,061,686
Granted Patent B2
US 12,061,686 · App. 18/201,653 · Granted Aug 13, 2024

Pre-registration of authentication devices

Inventors: Jakob Ehrensvärd (Palo Alto, CA); Christopher Harrell (San Jose, CA); Jerrod Chong (Palo Alto, CA)
Assignee: Yubico AB
G06F21/44G06F21/62H04L63/06H04L63/0876G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,061,686
App. No.
18/201,653
Granted
Aug 13, 2024
Kind
B2
Abstract

A system is disclosed for pre-registering authentication devices. A security key provider system may receive a request to pre-register a security key with identified applications from an enterprise. Responsive to receiving the request, the security key provider system instructs the security key to generate a unique authentication code for each of the applications. The security key provider system may generate pre-registration information based on the authentication codes and pre-register the authentication codes of the security key to the applications by providing the pre-registration information to the applications on behalf of the enterprise. The security key provider system may instead provide the pre-registration information to the enterprise to allow the enterprise to pre-register the authentication codes.

Claims (37)

1. A method comprising:

receiving, by a security key provider system, instructions to pre-register a plurality of security keys to one or more applications, wherein the plurality of security keys are physical devices, each physical device associated with a user;

identifying, by the security key provider system, respective authentication codes generated by the plurality of security keys to pre-register each respective security key of the plurality of security keys to a respective application of the one or more applications, wherein each authentication code comprises a respective public key and a respective private key; and

pre-registering, by the security key provider system, a respective public key of a respective authentication code of each security key to its respective application, wherein, responsive to determining a respective user attempt to authenticate with an application of the one or more applications after the pre-registering by interaction with a respective security key, the application grants access to the respective user using the respective authentication code without requiring registration, by the respective user, of the respective security key, based on the respective private key of the respective security key matching the respective public key, and wherein the pre-registering is performed for the plurality of security keys at a same time in batch.

2. The method of claim 1 , wherein pre-registering the respective public key of the respective authentication code of the respective security key to its respective application comprises uploading, by the security key provider system, the respective authentication code to the respective application.

3. The method of claim 1 , wherein pre-registering the respective public key of the respective authentication code of the respective security key to its respective application comprises providing the respective authentication code to a respective enterprise, the respective authentication code uploaded to the application by the respective enterprise.

4. The method of claim 1 , wherein pre-registering the respective public key of the respective authentication code of the respective security key to its respective application:

emulating a connection to the respective application; and

providing the respective authentication code to the application through the emulated connection.

5. The method of claim 1 , wherein the respective security key is pre-registered to a set of applications comprising the respective application, and wherein the respective security key is pre-registered to each application of the set of applications with a different authentication code.

6. The method of claim 1 , wherein the respective application is associated with a plurality of sites, and the plurality of sites are pre-registered with a same authentication code.

7. The method of claim 1 , wherein the respective application is associated with a plurality of domains, and the plurality of domains are pre-registered with a same authentication code.

8. The method of claim 1 , wherein the respective security key is pre-registered to the respective application under a plurality of accounts, each of the plurality of accounts pre-registered with a different authentication code.

9. A non-transitory computer-readable medium comprising computer program instructions that, when executed by one or more computer processors, cause the one or more computer processors to perform steps comprising:

receiving, by a security key provider system, instructions to pre-register a plurality of security keys to one or more applications, wherein the plurality of security keys are physical devices, each physical device associated with a user;

identifying, by the security key provider system, respective authentication codes generated by the plurality of security keys to pre-register each respective security key of the plurality of security keys to a respective application of the one or more applications, wherein each authentication code comprises a respective public key and a respective private key; and

pre-registering, by the security key provider system, a respective public key of a respective authentication code of each security key to its respective application, wherein, responsive to determining a respective user attempt to authenticate with an application of the one or more applications after the pre-registering by interaction with a respective security key, the application grants access to the respective user using the respective authentication code without requiring registration, by the respective user, of the respective security key, based on the respective private key of the respective security key matching the respective public key, and wherein the pre-registering is performed for the plurality of security keys at a same time in batch.

10. The non-transitory computer-readable medium of claim 9 , wherein pre-registering the respective public key of the respective authentication code of the respective security key to its respective application comprises uploading, by the security key provider system, the respective authentication code to the respective application.

11. The non-transitory computer-readable medium of claim 9 , wherein pre-registering the respective public key of the respective authentication code of the respective security key to its respective application comprises providing the respective authentication code to a respective enterprise, the respective authentication code uploaded to the application by the respective enterprise.

12. The non-transitory computer-readable medium of claim 9 , wherein pre-registering the respective public key of the respective authentication code of the respective security key to its respective application:

emulating a connection to the respective application; and

providing the respective authentication code to the application through the emulated connection.

13. The non-transitory computer-readable medium of claim 9 , wherein the respective security key is pre-registered to a set of applications comprising the respective application, and wherein the respective security key is pre-registered to each application of the set of applications with a different authentication code.

14. The non-transitory computer-readable medium of claim 9 , wherein the respective application is associated with a plurality of sites, and the plurality of sites are pre-registered with a same authentication code.

15. The non-transitory computer-readable medium of claim 9 , wherein the respective application is associated with a plurality of domains, and the plurality of domains are pre-registered with a same authentication code.

16. The non-transitory computer-readable medium of claim 9 , wherein the respective security key is pre-registered to the respective application under a plurality of accounts, each of the plurality of accounts pre-registered with a different authentication code.

17. A system comprising:

one or more processors; and

a non-transitory computer-readable medium comprising computer program instructions that, when executed by the one or more processors, causes the one or more processors to perform steps comprising:

receiving, by a security key provider system, instructions to pre-register a plurality of security keys to one or more applications, wherein the plurality of security keys are physical devices, each physical device associated with a user;

identifying, by the security key provider system, respective authentication codes generated by the plurality of security keys to pre-register each respective security key of the plurality of security keys to a respective application of the one or more applications, wherein each authentication code comprises a respective public key and a respective private key; and

pre-registering, by the security key provider system, a respective public key of a respective authentication code of each security key to its respective application, wherein, responsive to determining a respective user attempt to authenticate with an application of the one or more applications after the pre-registering by interaction with a respective security key, the application grants access to the respective user using the respective authentication code without requiring registration, by the respective user, of the respective security key, based on the respective private key of the respective security key matching the respective public key, and wherein the pre-registering is performed for the plurality of security keys at a same time in batch.

18. The system of claim 17 , wherein pre-registering the respective public key of the respective authentication code of the respective security key to its respective application comprises uploading, by the security key provider system, the respective authentication code to the respective application.

19. The system of claim 17 , wherein pre-registering the respective public key of the respective authentication code of the respective security key to its respective application comprises providing the respective authentication code to a respective enterprise, the respective authentication code uploaded to the application by the respective enterprise.

20. The system of claim 17 , wherein pre-registering the respective public key of the respective authentication code of the respective security key to its respective application:

emulating a connection to the respective application; and

providing the respective authentication code to the application through the emulated connection.

Assignments (3)
MERGER Recorded Nov 30, 2023
From: YUBICO AB
To: ACQ BURE AB
Reel/Frame 065713/0908 →
CHANGE OF NAME Recorded Nov 30, 2023
From: ACQ BURE AB
To: YUBICO AB
Reel/Frame 065724/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2023
From: EHRENSVÄRD, JAKOB; HARRELL, CHRISTOPHER; CHONG, JERROD
To: YUBICO AB
Reel/Frame 064216/0295 →
Continuity (3)
Continuation 16904017 · Jun 17, 2020
Provisional Application 62949728 · Dec 18, 2019
Related Publication 20230306103A1 · Sep 28, 2023