IP Library › Granted Patent US 10,628,566
Granted Patent B2
US 10,628,566 · App. 15/817,424 · Granted Apr 21, 2020

Authentication using delegated identities

Inventors: Philipp Hoffmann (Hamburg, DE); David Lebutsch (Tuebingen, DE); Martin Oberhofer (Bondorf, DE); Daniel Pittner (Steinenbronn, DE); Mehmet Uenluetepe (Herrenberg, DE)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/31G06F21/33G06F21/41H04L9/3226H04L63/0815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,628,566
App. No.
15/817,424
Granted
Apr 21, 2020
Kind
B2
Abstract

The invention relates to a computer-implemented method for user authentication using a cryptographically secured register. An authentication request for authenticating the user is received. The user is authenticated using a root identity of the user. A successful authentication requires receiving a credential assigned to a root identifier of the root identity of the user. An authentication context of the requested authentication is identified. One of the one or more delegated identities assigned to the root identity of the user and assigned to the identified authentication context is identified. In response to a successful authentication of the user, an authentication token is issued confirming the successful user authentication and identifying the successfully authenticated user by the delegated identifier of the identified delegated identity.

Claims (14)

1. A computer program product comprising a non-volatile computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code being configured to implement a method for user authentication using a cryptographically secured register, the cryptographically secured register comprising a root identity of the user, the root identity comprising a root identifier and a credential assigned to the root identifier for authenticating the user, the cryptographically secured register further comprising one or more delegated identities assigned to the root identity, each of the delegated identities comprising a delegated identifier and being assigned to an authentication context, the method comprising:

receiving an authentication request for authenticating the user,

authenticating the user using the root identity of the user, a successful authentication requiring receiving the credential assigned to the root identifier of the root identity of the user,

identifying an authentication context of the requested authentication,

identifying one of the one or more delegated identities assigned to the root identity of the user and assigned to the identified authentication context using the cryptographically secured register,

in response to a successful authentication of the user using the root identity, issuing an authentication token confirming the successful user authentication and identifying the authenticated user by the delegated identifier of the identified delegated identity,

wherein the root identity includes more than one delegated identities assigned to the root identity, the more than one delegated identities being assigned to the root identity in form of a tree-structure with at least a first one of the more than one delegated identities assigned to the root identity via at least a second one of the more than one delegated identities.

2. A computer system for user authentication using a cryptographically secured register, the cryptographically secured register comprising a root identity of the user, the root identity comprising a root identifier and a credential assigned to the root identifier for authenticating the user, the cryptographically secured register further comprising one or more delegated identities assigned to the root identity, each of the delegated identities comprising a delegated identifier and being assigned to an authentication context, the computer system being configured for:

receiving an authentication request for authenticating the user,

authenticating the user using the root identity of the user, a successful authentication requiring receiving the credential assigned to the root identifier of the root identity of the user,

identifying an authentication context of the requested authentication,

identifying one of the one or more delegated identities assigned to the root identity of the user and assigned to the identified authentication context using the cryptographically secured register,

in response to a successful authentication of the user using the root identity, issuing an authentication token confirming the successful user authentication and identifying the authenticated user by the delegated identifier of the identified delegated identity,

wherein the root identity includes more than one delegated identities assigned to the root identity, the more than one delegated identities being assigned to the root identity in form of a tree-structure with at least a first one of the more than one delegated identities assigned to the root identity via at least a second one of the more than one delegated identities.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2017
From: HOFFMANN, PHILIPP; LEBUTSCH, DAVID; OBERHOFER, MARTIN; PITTNER, DANIEL; UENLUETEPE, MEHMET
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 044176/0890 →
Continuity (1)
Related Publication 20190156000A1 · May 23, 2019
Cited By (2)
US 12,411,863 US 12,417,305