IP Library Patent Application 18379129
Patent Application
App. No. 18/379,129

SYSTEM AND METHOD FOR SPECULATIVE ATTESTATION AND ASSOCIATED TECHNIQUES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/379,129
Abstract

A system, apparatus, method, and machine-readable medium are described for speculative attestation conveyance, such as over an out-of-band channel. For example, one embodiment of a method comprises: associating a credential provider with a credential provider instance, the credential provider instance to generate credentials for authenticating a user to relying parties from a client device; associating a new credential with the credential provider instance, the new credential having a public portion and a non-public portion; transmitting over an out-of-band communication channel, a request for an identifying attestation to a plurality of trusted credential provider servers, the request including an identifier based on the new credential or the public portion of the new credential; receiving from a trusted credential provider server of the plurality of trusted credential provider servers the identifying attestation; attempting to validate the identifying attestation; and using or storing the identifying attestation when validated.

Claims (43)

1 . A method comprising:

associating a credential provider with a credential provider instance, the credential provider instance for authenticating a user to relying parties from a client device;

associating a new credential with the credential provider instance, the new credential having a public portion and a non-public portion;

transmitting over an out-of-band communication channel, a request for an identifying attestation to a plurality of trusted credential provider servers, the request including an identifier based on the new credential or the public portion of the new credential;

receiving from a trusted credential provider server of the plurality of trusted credential provider servers the identifying attestation;

attempting to validate the identifying attestation; and

using or storing the identifying attestation when validated.

2 . The method of claim 1 wherein the out-of-band communication channel comprises a communication channel which does not rely on a credential provider restricted platform application programming interface (API) of the client device and/or which will not be blocked by the platform associated with the client device.

3 . The method of claim 1 wherein the identifier includes a cryptographic hash generated over the new credential or the public portion of the new credential.

4 . The method of claim 3 wherein the cryptographic hash is generated over a combination of the new credential and a plurality of additional bits which are different for each request.

5 . The method of claim 3 wherein only the trusted credential provider server which maintains the new credential is capable of generating the identifying attestation based on the credential identified by the cryptographic hash.

6 . The method of claim 1 further comprising:

generating the credential provider instance, if one does not already exist on the client device.

7 . The method of claim 6 wherein generating the credential provider instance comprises:

authenticating the user on the trusted credential provider server; and

generating the credential provider instance associated with a corresponding trusted credential provider.

8 . The method of claim 7 wherein authenticating the user and generating the credential provider instance are performed via a platform application programming interface (API) of the client device.

9 . The method of claim 7 wherein the credential provider instance comprises a set of credential attributes to allow the corresponding trusted credential provider to indicate a particular credential provider server to be used for each of a plurality of relying parties.

10 . The method of claim 1 further comprising:

combining the identifying attestation and the new credential in an object, the object usable for processing by a relying party for authentication.

11 . The method of claim 1 wherein information associated with the new credential is to be communicated to a corresponding relying party, the information related to potential risk associated with the new credential.

12 . The method of claim 1 wherein the new credential is generated by the credential provider instance or by the trusted credential provider server.

13 . A machine-readable medium having program code stored therein which, when executed by one or more processors, cause the one or more processors to perform operations, comprising:

associating a credential provider with a credential provider instance, the credential provider instance to generate credentials for authenticating a user to relying parties from a client device;

associating a new credential with the credential provider instance, the new credential having a public portion and a non-public portion;

transmitting over an out-of-band communication channel, a request for an identifying attestation to a plurality of trusted credential provider servers, the request including an identifier based on the new credential or the public portion of the new credential;

receiving from a trusted credential provider server of the plurality of trusted credential provider servers the identifying attestation;

attempting to validate the identifying attestation; and

using or storing the identifying attestation when validated.

14 . The machine-readable medium of claim 13 wherein the out-of-band communication channel comprises a communication channel which does not rely on a credential provider restricted platform application programming interface (API) of the client device and/or which will not be blocked by the platform associated with the client device.

15 . The machine-readable medium of claim 13 wherein the identifier includes a cryptographic hash generated over the new credential or the public portion of the new credential.

16 . The machine-readable medium of claim 15 wherein the cryptographic hash is generated over a combination of the new credential and a plurality of additional bits which are different for each request.

17 . The machine-readable medium of claim 15 wherein only the trusted credential provider server which maintains the new credential is capable of generating the identifying attestation based on the credential identified by the cryptographic hash.

18 . The machine-readable medium of claim 13 further comprising program code to cause the operation of:

generating the credential provider instance, if one does not already exist on the client device.

19 . The machine-readable medium of claim 18 wherein generating the credential provider instance comprises:

authenticating the user on the trusted credential provider server; and

generating the credential provider instance associated with a corresponding trusted credential provider.

20 . The machine-readable medium of claim 19 wherein authenticating the user and generating the credential provider instance are performed via a platform application programming interface (API) of the client device.

21 . The machine-readable medium of claim 19 wherein the credential provider instance comprises a set of credential attributes to allow the corresponding trusted credential provider to indicate a particular credential provider server to be used for each of a plurality of relying parties.

22 . The machine-readable medium of claim 13 further comprising: combining the identifying attestation and the new credential in an object, the object usable for processing by a relying party for authentication.

23 . The machine-readable medium of claim 13 wherein information associated with the new credential is to be communicated to a corresponding relying party, the information related to potential risk associated with the new credential.

24 . The machine-readable medium of claim 13 wherein the new credential is generated by the credential provider instance or by the trusted credential provider server.

Assignments (2)
SECURITY INTEREST Recorded Jul 1, 2025
From: NOK NOK LABS, INC.
To: MUFG BANK, LTD.
Reel/Frame 071773/0493 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2023
From: LINDEMANN, ROLF
To: NOK NOK LABS, INC.
Reel/Frame 065231/0752 →