IP Library › Granted Patent US 12,744,669
Granted Patent B2
US 12,744,669 · App. 18/868,351 · Granted Sep 22, 2026

Multi-device assistive identity verification method and system

Inventor: Yongtao Wang (Hangzhou, CN)
Assignee: Alipay (Hangzhou) Information Technology Co., Ltd.
H04L9/3213H04L9/3228
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,669
App. No.
18/868,351
Granted
Sep 22, 2026
Kind
B2
Abstract

The present disclosure provides a multi-device assistive identity verification method and system. The method includes: receiving an identity key allocation request and an identity key sharing request of a user; and allocating and storing an identity key, and sending the identity key to the user and a sharer. The method further includes: when a transaction request of the user is received, inviting the user and the sharer to assist in confirmation, and comparing tokens to perform identity verification.

Claims (48)

1 . A multi-device assistive identity verification method, wherein the method comprises:

receiving an identity key allocation request and an identity key sharing request of a user;

allocating, in response to the identity key allocation request, an identity key for the user, and storing the identity key in a server, wherein the allocated identity key is bound to a user identifier and a device identifier of the user and a user identifier and a device identifier of a sharer, to form a contract;

sending the identity key to the user and the sharer;

receiving a transaction request of the user, and inviting, based on the transaction request, the user and the sharer to send confirmation;

in response to the confirmation of the user and the sharer, separately calculating a first token of the user and a second token of the sharer based on a time-based one-time password (TOTP) algorithm, the identity key and a current timestamp;

comparing the first token and the second token;

in response to determining that the first token and the second token are the same, obtaining a third token calculated by a server;

comparing the first token and the third token; and

returning an identity verification result based on the comparison of the first token and the third token.

2 . The method according to claim 1 , wherein the allocated identity key is stored on a blockchain in an encrypted manner.

3 . The method according to claim 2 , wherein inviting, based on the transaction request, the user and the sharer to send confirmation further comprises:

obtaining a corresponding identity key from the blockchain based on the transaction request and the user identifier and the device identifier of the user; and

inviting the user and the sharer bound to the obtained identity key to send the confirmation.

4 . The method according to claim 1 , wherein the third token calculated in the server is calculated in the server based on an identity key obtained from a blockchain.

5 . The method according to claim 1 , further comprising:

in response to that the transaction request of the user is received, performing password verification, SMS message verification, or biometric verification before inviting the user and the sharer to send confirmation.

6 . A non-transitory computer-readable storage medium storing instructions which when executed by a processor, cause the processor to:

receive an identity key allocation request and an identity key sharing request of a user;

allocate, in response to the identity key allocation request, an identity key for the user, and store the identity key in a server, wherein the allocated identity key is bound to a user identifier and a device identifier of the user and a user identifier and a device identifier of a sharer, to form a contract;

send the identity key to the user and the sharer;

receive a transaction request of the user, and inviting, based on the transaction request, the user and the sharer to send confirmation;

in response to the confirmation of the user and the sharer, separately calculate a first token of the user and a second token of the sharer based on a time-based one-time password (TOTP) algorithm, the identity key and a current timestamp;

compare the first token and the second token;

in response to determining that the first token and the second token are the same, obtain a third token calculated by a server;

compare the first token and the third token; and

return an identity verification result based on the comparison of the first token and the third token.

7 . The non-transitory computer-readable storage medium according to claim 6 , wherein the allocated identity key is stored on a blockchain in an encrypted manner.

8 . The non-transitory computer-readable storage medium according to claim 7 , wherein the processor being caused to invite, based on the transaction request, the user and the sharer to send confirmation further comprises being caused to:

obtain a corresponding identity key from the blockchain based on the transaction request and the user identifier and the device identifier of the user; and

invite the user and the sharer bound to the obtained identity key to send the confirmation.

9 . The non-transitory computer-readable storage medium according to claim 6 , wherein the third token calculated in the server is calculated in the server based on an identity key obtained from a blockchain.

10 . The non-transitory computer-readable storage medium according to claim 6 , wherein the processor further comprises being caused to:

in response to that the transaction request of the user is received, perform password verification, SMS message verification, or biometric verification before inviting the user and the sharer to send confirmation.

11 . A computing device, comprising a memory and a processor, wherein the memory stores executable code, and wherein the processor is configured to execute the executable code to cause the computing device to:

receive an identity key allocation request and an identity key sharing request of a user;

allocate, in response to the identity key allocation request, an identity key for the user, and store the identity key in a server, wherein the allocated identity key is bound to a user identifier and a device identifier of the user and a user identifier and a device identifier of a sharer, to form a contract;

send the identity key to the user and the sharer;

receive a transaction request of the user, and inviting, based on the transaction request, the user and the sharer to send confirmation;

in response to the confirmation of the user and the sharer, separately calculate a first token of the user and a second token of the sharer based on a time-based one-time password (TOTP) algorithm, the identity key and a current timestamp;

compare the first token and the second token;

in response to determining that the first token and the second token are the same, obtain a third token calculated by a server;

compare the first token and the third token; and

return an identity verification result based on the comparison of the first token and the third token.

12 . The computing device according to claim 11 , wherein the allocated identity key is stored on a blockchain in an encrypted manner.

13 . The computing device according to claim 12 , wherein the computing device being caused to invite, based on the transaction request, the user and the sharer to send confirmation further comprises being caused to:

obtain a corresponding identity key from the blockchain based on the transaction request and the user identifier and the device identifier of the user; and

invite the user and the sharer bound to the obtained identity key to send the confirmation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2024
From: WANG, YONGTAO
To: ALIPAY (HANGZHOU) INFORMATION TECHNOLOGY CO., LTD.
Reel/Frame 069400/0838 →
Priority Claims (1)
CN 202210661230.7 · Jun 13, 2022 · national
Continuity (1)
Related Publication 20250337579A1 · Oct 30, 2025
References Cited (27)
US 10630682B1 · Bhattacharyya et al. · 2020 [cited by applicant]
US 10887095B2 · Chopra · 2021 [cited by examiner]
US 20070050845A1 · Das et al. · 2007 [cited by applicant]
US 20190190710A1 · Chopra · 2019 [cited by examiner]
US 20190305952A1 · Hamel · 2019 [cited by examiner]
US 20210067340A1 · Ferenczi · 2021 [cited by examiner]
US 20210217007A1 · Menon · 2021 [cited by examiner]
US 20220360448A1 · Sahni · 2022 [cited by examiner]
CN 103065240A · 2013 [cited by applicant]
CN 104680372A · 2015 [cited by applicant]
CN 105931421A · 2016 [cited by applicant]
CN 107623681A · 2018 [cited by applicant]
CN 108960815A · 2018 [cited by applicant]
CN 109146489A · 2019 [cited by applicant]
CN 109146496A · 2019 [cited by applicant]
CN 109155029A · 2019 [cited by applicant]
CN 109479049A · 2019 [cited by applicant]
CN 110084612A · 2019 [cited by applicant]
CN 110995642A · 2020 [cited by applicant]
CN 111047740A · 2020 [cited by applicant]
CN 112398645A · 2021 [cited by applicant]
CN 113011891A · 2021 [cited by applicant]
CN 115150093A · 2022 [cited by applicant]
WO 2020051710A1 · 2020 [cited by applicant]
“European Search Report” regarding application No. 23822907.4, mailed on Sep. 8, 2025. pp. 1-9. [cited by applicant]
Ozkan Can et al: “Security Analysis of 1-12 Mobile Authenticator Applications”, 2020 International Conference on Information Security and Cryptology (ISCTURKEY), IEEE, Dec. 3, 2020 (Dec. 3, 2020), pp. 18-30, XP033899457… [cited by applicant]
“International Search Report” regarding Intl. Application No. PCT/CN2023/096629, mailed on Jun. 26, 2023, pp. 1-9. [cited by applicant]