IP Library › Granted Patent US 12,615,137
Granted Patent B2
US 12,615,137 · App. 18/900,144 · Granted Apr 28, 2026

Passwordless vault access through secure vault enrollment

Inventors: Jordan Melberg (Folsom, CA); Arpit Gupta (Newcastle, WA); Nicolas Backal Stavchansky (San Francisco, CA); Natan Becker Bessudo (San Francisco, CA); Kevin Huang (Alameda, CA); Vivek Raman (Orinda, CA)
H04L9/0825H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,137
App. No.
18/900,144
Granted
Apr 28, 2026
Kind
B2
Abstract

Methods, systems, and devices are described. A client may perform a sign-in or registration process to register a user with an application of an identity management system. The sign-in or registration process may include receiving an indication of at least one credential associated with an identity of the user. The client may perform a vault enrollment process to configure a secure vault for the user of the application. The client may upload data to the identity management system. The data may be associated with the secure vault configured for the user of the application. The client may perform a device pairing operation to transfer a Recovery Key from the first client device to a second client device of the user. The client may use one or more keys stored in the vault to access the application of the identity management system via the second client device of the user.

Claims (61)

1 . A method, comprising:

performing a sign-in or registration process to register a user with an application of an identity management system, wherein the sign-in or registration process comprises receiving an indication of at least one credential associated with an identity of the user;

performing a vault enrollment process to configure a secure vault for the user of the application, wherein the vault enrollment process comprises:

generating a cryptographically random identifier;

combining the cryptographically random identifier with one or more attributes of the user to generate a Recovery Key;

using a client-side encryption function to derive a symmetric key from the Recovery Key;

generating a cryptographically random asymmetric keypair that includes a private key and a public key;

encrypting the private key of the cryptographically random asymmetric keypair with the symmetric key derived from the Recovery Key;

storing one or more of the Recovery Key, a vault key, the symmetric key, the private key, and the public key on a first client device of the user; and

uploading, to the identity management system, data associated with the secure vault configured for the user of the application;

performing a device pairing operation to transfer the Recovery Key from the first client device to a second client device of the user, wherein the second client device is operable to use the Recovery Key to generate the symmetric key, the private key, the public key, or a combination thereof; and

using one or more of the symmetric key, the private key, or the public key to access the application of the identity management system via the second client device of the user.

2 . The method of claim 1 , wherein the sign-in or registration process comprises:

receiving, via the first client device or the second client device, a user input comprising the at least one credential of the user and a one-time password (OTP) provided by the identity management system.

3 . The method of claim 2 , wherein the OTP comprises a 6-digit email verification code.

4 . The method of claim 1 , wherein the first client device comprises a mobile client and the second client device comprises a web client.

5 . The method of claim 1 , wherein the first client device comprises a web client and the second client device comprises a mobile client.

6 . The method of claim 1 , further comprising:

installing the application or a browser extension associated with the application on the first client device or the second client device, wherein at least one step of the vault enrollment process is performed using the application or the browser extension.

7 . The method of claim 1 , wherein the Recovery Key is transferred from the first client device to the second client device via a quick response (QR) code, a user input, or a secure communication link between the first client device and the second client device.

8 . An apparatus, comprising:

one or more memories storing processor-executable code; and

one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to:

perform a sign-in or registration process to register a user with an application of an identity management system, wherein the sign-in or registration process comprises receiving an indication of at least one credential associated with an identity of the user;

perform a vault enrollment process to configure a secure vault for the user of the application, wherein the vault enrollment process comprises:

generating a cryptographically random identifier;

combining the cryptographically random identifier with one or more attributes of the user to generate a Recovery Key;

using a client-side encryption function to derive a symmetric key from the Recovery Key;

generating a cryptographically random asymmetric keypair that includes a private key and a public key;

encrypting the private key of the cryptographically random asymmetric keypair with the symmetric key derived from the Recovery Key;

storing one or more of the Recovery Key, a vault key, the symmetric key, the private key, and the public key on a first client device of the user; and

uploading, to the identity management system, data associated with the secure vault configured for the user of the application;

perform a device pairing operation to transfer the Recovery Key from the first client device to a second client device of the user, wherein the second client device is operable to use the Recovery Key to generate the symmetric key, the private key, the public key, or a combination thereof; and

use one or more of the symmetric key, the private key, or the public key to access the application of the identity management system via the second client device of the user.

9 . The apparatus of claim 8 , wherein the sign-in or registration process comprises:

receiving, via the first client device or the second client device, a user input comprising the at least one credential of the user and a one-time password (OTP) provided by the identity management system.

10 . The apparatus of claim 9 , wherein the OTP comprises a 6-digit email verification code.

11 . The apparatus of claim 8 , wherein the first client device comprises a mobile client and the second client device comprises a web client.

12 . The apparatus of claim 8 , wherein the first client device comprises a web client and the second client device comprises a mobile client.

13 . The apparatus of claim 8 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

install the application or a browser extension associated with the application on the first client device or the second client device, wherein at least one step of the vault enrollment process is performed using the application or the browser extension.

14 . The apparatus of claim 8 , wherein the Recovery Key is transferred from the first client device to the second client device via a quick response (QR) code, a user input, or a secure communication link between the first client device and the second client device.

15 . A non-transitory computer-readable medium storing code that comprises instructions executable by one or more processors to:

perform a sign-in or registration process to register a user with an application of an identity management system, wherein the sign-in or registration process comprises receiving an indication of at least one credential associated with an identity of the user;

perform a vault enrollment process to configure a secure vault for the user of the application, wherein the vault enrollment process comprises:

generating a cryptographically random identifier;

combining the cryptographically random identifier with one or more attributes of the user to generate a Recovery Key;

using a client-side encryption function to derive a symmetric key from the Recovery Key;

generating a cryptographically random asymmetric keypair that includes a private key and a public key;

encrypting the private key of the cryptographically random asymmetric keypair with the symmetric key derived from the Recovery Key;

storing one or more of the Recovery Key, a vault key, the symmetric key, the private key, and the public key on a first client device of the user; and

uploading, to the identity management system, data associated with the secure vault configured for the user of the application;

perform a device pairing operation to transfer the Recovery Key from the first client device to a second client device of the user, wherein the second client device is operable to use the Recovery Key to generate the symmetric key, the private key, the public key, or a combination thereof; and

use one or more of the Recovery Key, the symmetric key, the private key, or the public key to access the application of the identity management system via the second client device of the user.

16 . The non-transitory computer-readable medium of claim 15 , wherein the instructions to sign-in or registration process are executable by the one or more processors to:

receive, via the first client device or the second client device, a user input comprising the at least one credential of the user and a one-time password (OTP) provided by the identity management system.

17 . The non-transitory computer-readable medium of claim 16 , wherein the OTP comprises a 6-digit email verification code.

18 . The non-transitory computer-readable medium of claim 15 , wherein the first client device comprises a mobile client and the second client device comprises a web client.

19 . The non-transitory computer-readable medium of claim 15 , wherein the first client device comprises a web client and the second client device comprises a mobile client.

20 . The non-transitory computer-readable medium of claim 15 , wherein the instructions are further executable by the one or more processors to:

install the application or a browser extension associated with the application on the first client device or the second client device, wherein at least one step of the vault enrollment process is performed using the application or the browser extension.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2024
From: MELBERG, JORDAN; GUPTA, ARPIT; BACKAL STAVCHANSKY, NICOLAS; BECKER BESSUDO, NATAN; HUANG, KEVIN; RAMAN, VIVEK
To: OKTA, INC.
Reel/Frame 068901/0962 →
Continuity (2)
Provisional Application 63587060 · Sep 29, 2023
Related Publication 20250112764A1 · Apr 3, 2025
References Cited (101)
US 8321682B1 · Read · 2012 [cited by examiner]
US 9690949B1 · Diorio · 2017 [cited by examiner]
US 10108811B1 · Walker · 2018 [cited by examiner]
US 10225255B1 · Jampani · 2019 [cited by examiner]
US 10305862B2 · Bone · 2019 [cited by applicant]
US 10501055B1 · Yi · 2019 [cited by examiner]
US 10868672B1 · Farrugia · 2020 [cited by examiner]
US 11025598B1 · Laghaeian · 2021 [cited by examiner]
US 11080138B1 · Grube · 2021 [cited by examiner]
US 11184157B1 · Gueron · 2021 [cited by examiner]
US 11341265B1 · Gunawardena · 2022 [cited by examiner]
US 11811924B1 · Spraggs · 2023 [cited by examiner]
US 11895232B1 · Stapleton · 2024 [cited by examiner]
US 12003493B2 · Bilger · 2024 [cited by examiner]
US 12355873B1 · Chase · 2025 [cited by examiner]
US 20040103288A1 · Ziv · 2004 [cited by examiner]
US 20050273843A1 · Shigeeda · 2005 [cited by examiner]
US 20080313473A1 · Provencher · 2008 [cited by examiner]
US 20100043056A1 · Ganapathy · 2010 [cited by examiner]
US 20100211787A1 · Bukshpun · 2010 [cited by examiner]
US 20110113235A1 · Erickson · 2011 [cited by examiner]
US 20120089519A1 · Peddada · 2012 [cited by examiner]
US 20120155635A1 · Vaikuntanathan · 2012 [cited by examiner]
US 20140047237A1 · Parrish · 2014 [cited by examiner]
US 20140068261A1 · Malek · 2014 [cited by examiner]
US 20140281505A1 · Zhang · 2014 [cited by examiner]
US 20150100978A1 · Isozaki · 2015 [cited by examiner]
US 20150269566A1 · Gaddam · 2015 [cited by examiner]
US 20160028540A1 · Ko · 2016 [cited by examiner]
US 20160028698A1 · Antipa · 2016 [cited by examiner]
US 20160140335A1 · Proulx · 2016 [cited by examiner]
US 20160261566A1 · Parviainen-Jalanko · 2016 [cited by examiner]
US 20170012974A1 · Sierra · 2017 [cited by examiner]
US 20170085543A1 · Choi · 2017 [cited by examiner]
US 20170250974A1 · Antonyraj · 2017 [cited by examiner]
US 20170272433A1 · Jaggi · 2017 [cited by examiner]
US 20170339559A1 · Caracas · 2017 [cited by examiner]
US 20170373844A1 · Sykora · 2017 [cited by examiner]
US 20180007037A1 · Reese · 2018 [cited by examiner]
US 20180063105A1 · Poon · 2018 [cited by examiner]
US 20180063119A1 · Gullicksen · 2018 [cited by examiner]
US 20180089029A1 · Resch · 2018 [cited by examiner]
US 20180332015A1 · Oberheide · 2018 [cited by examiner]
US 20190013945A1 · Hamlin · 2019 [cited by examiner]
US 20190020647A1 · Sinha · 2019 [cited by examiner]
US 20190052632A1 · Takagi · 2019 [cited by examiner]
US 20190087588A1 · Baboval · 2019 [cited by examiner]
US 20190132299A1 · Tucker · 2019 [cited by examiner]
US 20190205898A1 · Greco · 2019 [cited by examiner]
US 20190245686A1 · Rahimi · 2019 [cited by examiner]
US 20190312726A1 · Sierra · 2019 [cited by examiner]
US 20190312731A1 · Eldefrawy · 2019 [cited by examiner]
US 20190318356A1 · Martin · 2019 [cited by examiner]
US 20190325146A1 · Lei · 2019 [cited by examiner]
US 20190327092A1 · Kareti · 2019 [cited by examiner]
US 20200021567A1 · Salgaonkar · 2020 [cited by examiner]
US 20200029208A1 · Winoto · 2020 [cited by examiner]
US 20200084027A1 · Duchon · 2020 [cited by examiner]
US 20200162247A1 · Nix · 2020 [cited by examiner]
US 20200193011A1 · Ruster · 2020 [cited by examiner]
US 20200259636A1 · Gottipati · 2020 [cited by examiner]
US 20200267547A1 · Tal · 2020 [cited by examiner]
US 20200304299A1 · Medvinsky · 2020 [cited by examiner]
US 20200313898A1 · Troia · 2020 [cited by examiner]
US 20200313909A1 · Mondello · 2020 [cited by examiner]
US 20200314074A1 · Mondello · 2020 [cited by examiner]
US 20200351255A1 · Gwak · 2020 [cited by examiner]
US 20200396092A1 · Cambou · 2020 [cited by examiner]
US 20210026966A1 · Ghetie · 2021 [cited by examiner]
US 20210091937A1 · Dange · 2021 [cited by examiner]
US 20210144004A1 · Gray · 2021 [cited by examiner]
US 20210157939A1 · Bilger · 2021 [cited by examiner]
US 20210173897A1 · Jakobsson · 2021 [cited by examiner]
US 20210266309A1 · Guccione · 2021 [cited by examiner]
US 20210328976A1 · Leavy · 2021 [cited by examiner]
US 20210365547A1 · Atkinson · 2021 [cited by examiner]
US 20210377049A1 · Nix · 2021 [cited by examiner]
US 20220004661A1 · Dange · 2022 [cited by examiner]
US 20220029794A1 · Malhotra · 2022 [cited by examiner]
US 20220052843A1 · Carver · 2022 [cited by examiner]
US 20220109666A1 · Collier · 2022 [cited by examiner]
US 20220187989A1 · Resch · 2022 [cited by examiner]
US 20220209944A1 · Nix · 2022 [cited by examiner]
US 20220209965A1 · Montgomery · 2022 [cited by examiner]
US 20220350615A1 · Grobelny · 2022 [cited by examiner]
US 20220360448A1 · Sahni · 2022 [cited by examiner]
US 20230006994A1 · Krishna · 2023 [cited by examiner]
US 20230060803A1 · Moon · 2023 [cited by examiner]
US 20230198785A1 · Henning · 2023 [cited by examiner]
US 20230214464A1 · Dange · 2023 [cited by examiner]
US 20230224150A1 · Serguieva · 2023 [cited by examiner]
US 20230237146A1 · Balakrishnan · 2023 [cited by examiner]
US 20230308424A1 · Nix · 2023 [cited by examiner]
US 20230325526A1 · Resch · 2023 [cited by examiner]
US 20230328050A1 · Grover · 2023 [cited by examiner]
US 20240022565A1 · Keith, Jr. · 2024 [cited by examiner]
US 20240267224A1 · Chen · 2024 [cited by examiner]
US 20240273243A1 · Lindskog · 2024 [cited by examiner]
US 20250077256A1 · Farley · 2025 [cited by examiner]
US 20250112928A1 · Tahaliyani · 2025 [cited by examiner]
Melberg et al., Passwordless Vault Access Through Secure Vault Enrollment, U.S. Appl. No. 63/587,060, Sep. 29, 2023, pp. 23-27, paras. [0063]-[0076], Figs. 7-8, U.S. Patent and Trademark Office. [cited by applicant]