IP Library › Granted Patent US 11,531,783
Granted Patent B2
US 11,531,783 · App. 16/365,390 · Granted Dec 20, 2022

Digital credentials for step-up authentication

Inventors: Bjorn Hamel (Dublin, CA); Jonathan David Ruggiero (Danville, CA)
Assignee: Workday, Inc.
G06F21/629G06F21/6227H04L63/0428H04L63/062H04L63/0823H04L63/102G06F2221/2113
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,531,783
App. No.
16/365,390
Granted
Dec 20, 2022
Kind
B2
Abstract

The system comprises an interface and a processor. The interface is configured to receive a request from an application for authorization to access, wherein access to the application is requested by a user, and receive a task request from the application for authorization to access a task, wherein access to the task is requested by the user. The processor is configured to authenticate the request from the application for authorization to access, determine that the task comprises a sensitive task, determine a user authentication device, provide a challenge for a digital credential to the user authentication device, wherein the digital credential is backed by data stored in a distributed ledger, receive a response from the user authentication device, determine the response is valid, and provide an authorization to access the sensitive task.

Claims (62)

1. A system for credential authentication, comprising:

an interface configured to:

receive a request from an application for authorization to access, wherein access to the application is requested by a user; and

receive a task request from the application for authorization to access a task, wherein access to the task is requested by the user; and

a processor configured to:

authenticate the request from the application for authorization to access;

determine that the task comprises a sensitive task;

determine a user authentication device;

provide a challenge for a digital credential to the user authentication device, wherein the digital credential is backed by data stored in a distributed ledger, wherein the user authentication device:

determines a credential request from the challenge;

determines one or more credentials that match the credential request;

provides a credential list including the one or more credentials to the user; and

receives a selection from the user of at least one credential of the one or more credentials;

receive a response from the user authentication device, wherein the response comprises the at least one credential;

determine the response is valid using the distributed ledger; and

provide an authorization to access the sensitive task when the response is determined to be valid.

2. The system of claim 1 , wherein the challenge for the digital credential to the user authentication device is based at least in part on rules.

3. The system of claim 1 , wherein the task request from the application for authorization to access the sensitive task is received via an encrypted JSON message.

4. The system of claim 1 , wherein the application prompts the user to confirm access to the sensitive task prior to providing the task request for authorization to access the sensitive task.

5. The system of claim 1 , wherein authenticating the request from the application for authorization to access comprises providing an access token to the application.

6. The system of claim 1 , wherein the processor is further configured to validate a signature on the task request from the application for authorization to access the task.

7. The system of claim 1 , wherein the processor is further configured to determine a user identifier based at least in part on the request from an application for authorization to access.

8. The system of claim 7 , wherein the processor is further configured to determine the user authentication device based at least in part on the user identifier.

9. The system of claim 1 , wherein the response is encrypted.

10. The system of claim 9 , wherein the response is encrypted with a per-channel key.

11. The system of claim 1 , wherein the response comprises the challenge signed with a user authentication device private key.

12. The system of claim 11 , wherein the user authentication device signs the challenge with the user authentication device private key in response to user provided biometric data.

13. The system of claim 12 , wherein determining the response is valid comprises validating the challenge signature.

14. The system of claim 1 , wherein the credential is selected from a credential wallet.

15. The system of claim 1 , wherein the challenge to the user authentication device comprises a set of credentials for satisfying the challenge.

16. The system of claim 15 , wherein the set of credentials is based at least in part on a context of the task and on rules that enable access.

17. The system of claim 1 , wherein the processor is further configured to access a public key in the distributed ledger and verify the public key corresponds to a decentralized identifier stored by the credential.

18. The system of claim 1 , wherein determining the response is valid comprises determining that the credential is not expired and that the credential comprises a valid signature associated with the user.

19. The system of claim 1 , wherein determining the response is valid comprises querying the distributed ledger to determine that the credential is not revoked.

20. A method for credential authentication, comprising:

receiving a request from an application for authorization to access, wherein access to the application is requested by a user;

receiving a request from the application for authorization to access a task, wherein access to the task is requested by the user;

authenticating, using a processor, the request from the application for authorization to access;

determining that the task comprises a sensitive task;

determining a user authentication device;

providing a challenge for a digital credential to the user authentication device, wherein the digital credential is backed by data stored in a distributed ledger, wherein the user authentication device:

determines a credential request from the challenge;

determines one or more credentials that match the credential request;

provides a credential list including the one or more credentials to the user; and

receives a selection from the user of at least one credential of the one or more credentials;

receiving a response from the user authentication device, wherein the response comprises the at least one credential;

determining the response is valid using the distributed ledger; and

providing an authorization to access the sensitive task when the response is determined to be valid.

21. A computer program product for credential authentication, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a request from an application for authorization to access, wherein access to the application is requested by a user;

receiving a request from the application for authorization to access a task, wherein access to the task is requested by the user;

authenticating the request from the application for authorization to access;

determining that the task comprises a sensitive task;

determining a user authentication device;

providing a challenge for a digital credential to the user authentication device, wherein the digital credential is backed by data stored in a distributed ledger, wherein the user authentication device:

determines a credential request from the challenge;

determines one or more credentials that match the credential request;

provides a credential list including the one or more credentials to the user; and

receives a selection from the user of at least one credential of the one or more credentials;

receiving a response from the user authentication device, wherein the response comprises the at least one credential;

determining the response is valid using the distributed ledger; and

providing an authorization to access the sensitive task when the response is determined to be valid.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2019
From: HAMEL, BJORN; RUGGIERO, JONATHAN DAVID
To: WORKDAY, INC.
Reel/Frame 049411/0498 →
Continuity (15)
Continuation In Part 16021240 · Jun 28, 2018
Continuation In Part 16021234 · Jun 28, 2018
Continuation In Part 16021243 · Jun 28, 2018
Provisional Application 62798400 · Jan 29, 2019
Provisional Application 62798398 · Jan 29, 2019
Provisional Application 62798389 · Jan 29, 2019
Provisional Application 62798397 · Jan 29, 2019
Provisional Application 62798393 · Jan 29, 2019
Provisional Application 62798403 · Jan 29, 2019
Provisional Application 62798387 · Jan 29, 2019
Provisional Application 62798404 · Jan 29, 2019
Provisional Application 62798402 · Jan 29, 2019
Provisional Application 62798391 · Jan 29, 2019
Provisional Application 62648854 · Mar 27, 2018
Related Publication 20190303600A1 · Oct 3, 2019
Cited By (4)
US 12,367,319 US 12,609,836 US 12,719,684 US 12,739,130