IP Library › Patent Application 18896716
Patent Application
App. No. 18/896,716

ANONYMOUS DEVICE FINGERPRINTING FOR DEVICE VERIFICATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/896,716
Abstract

Systems, methods, and computer readable media are described herein that use a user-agent-based non-extractable cryptographic keypair to generate a cryptographic proof containing a device fingerprint that an authentication system can use to subsequently identify and/or register a known device. Specifically, the systems disclosed herein may generate the device's “fingerprint” in an isolated and secured environment. Although the private key cannot be extracted from the isolated and secured environment, the authentication system can verify the truthfulness of the device's identity. This cryptographic “fingerprint,” in concert with a synchronous authentication system, has the ability to essentially eliminate authentication phishing. By ensuring that the cryptographic fingerprint of the device answering the synchronous authentication challenge has the same cryptographic fingerprint as the device that initiated the authentication request, the operation ensures the integrity of the authentication mechanism by verifying the legitimacy of the requesting device.

Claims (39)

1 . A method, comprising:

causing generation of a fingerprint for a device;

causing sending of the fingerprint, along with a device verification request, to a device fingerprinting server, wherein the device verification request comprises a secure context identifier for a user of the device;

in response to the device fingerprint server determining that the fingerprint matches a previously-known fingerprint for the secure context identifier:

causing receiving, at the device, of a notification that the device has been verified; and

in response to the device fingerprint server determining that the fingerprint does not match a previously-known fingerprint for the secure context identifier:

causing receiving, at the device, of a device verification challenge;

responding, at the device, to the device verification challenge; and

in response to the device fingerprint server verifying the fingerprint as part of the device verification challenge:

causing receiving, at the device, of a notification that the device has been verified.

2 . The method of claim 1 , wherein the fingerprint comprises a cryptographic proof that is generated from a cryptographic keypair.

3 . The method of claim 2 , wherein the cryptographic keypair is stored in an unextractable fashion in the device.

4 . The method of claim 1 , wherein the device further comprises a browser or mobile app executing on the device and configured to perform the device verification request and the device verification challenge.

5 . The method of claim 1 , wherein the response to the device verification challenge comprises an email challenge response.

6 . The method of claim 1 , wherein the fingerprint comprises an anonymous and unique cryptographic proof for the device.

7 . The method of claim 1 , wherein the secure context identifier comprises one of: an email address, a telephone number, or some other unique user identifier.

8 . The method of claim 1 , wherein the device verification request further comprises an app identifier.

9 . The method of claim 1 , wherein verifying the fingerprint as part of the device verification challenge further comprises: verifying the fingerprint based, at least in part, on a cryptographic public key.

10 . The method of claim 1 , wherein, in response to the device fingerprint server failing to verify the fingerprint as part of the device verification challenge, the method further comprises:

receiving, at the device, a notification that additional verification is required in order to verify the device.

11 . A method, comprising:

receiving, at a device fingerprinting server, a fingerprint generated for a device and a device verification request, wherein the device verification request comprises a secure context identifier for a user of the device;

in response to the device fingerprint server determining that the fingerprint matches a previously-known fingerprint for the secure context identifier:

sending, to the device, a notification that the device has been verified; and

in response to the device fingerprint server determining that the fingerprint does not match a previously-known fingerprint for the secure context identifier:

sending, to the device, a device verification challenge;

receiving, from the device, a response to the device verification challenge; and

in response to the verifying the fingerprint at the device fingerprint server as part of the device verification challenge:

sending, to the device, a notification that the device has been verified.

12 . The method of claim 11 , wherein the fingerprint comprises a cryptographic proof that is generated from a cryptographic keypair.

13 . The method of claim 12 , wherein the cryptographic keypair is stored in an unextractable fashion in the device.

14 . The method of claim 11 , wherein the device further comprises a browser or mobile app executing on the device and configured to perform the device verification request and the device verification challenge.

15 . The method of claim 11 , wherein the response to the device verification challenge comprises an email challenge response.

16 . The method of claim 11 , wherein the fingerprint comprises an anonymous and unique cryptographic proof for the device.

17 . The method of claim 11 , wherein the secure context identifier comprises one of: an email address, telephone number, or some other unique identifier.

18 . The method of claim 11 , wherein the device verification request further comprises an app identifier.

19 . The method of claim 11 , wherein verifying the fingerprint as part of the device verification challenge further comprises: verifying the fingerprint based, at least in part, on a cryptographic public key.

20 . The method of claim 11 , wherein, in response to the device fingerprint server failing to verify the fingerprint as part of the device verification challenge, the method further comprises:

sending, to the device, a notification that additional verification is required in order to verify the device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2026
From: MAGIC LABS, INC.
To: PAYWARD, INC.
Reel/Frame 075774/0621 →