IP Library › Granted Patent US 11,750,385
Granted Patent B2
US 11,750,385 · App. 16/764,439 · Granted Sep 5, 2023

System and method for authenticating a user

Inventor: Cheuk Yiu So (Quarry Bay, HK)
Assignee: Prisec Innovation Limited
H04L9/3213G06K19/06009H04L9/0825H04L9/3265H04L67/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,750,385
App. No.
16/764,439
Granted
Sep 5, 2023
Kind
B2
Abstract

A system and a method for an electronic method of authenticating a user to establish a service session the method comprising the steps of receiving an access request at a service provider device from a user device, authenticating a user based on a unique user credential associated with the user, by the service provider, establishing a service session between the user device and the service device.

Claims (51)

1. A system for authenticating a user to establish a service session, the system comprising:

a user device, the user device being a client device, a service provider device configured for accessing by the user via the user device, the service provider device being a cloud server in electronic communication with the user device, the service provider device and user device configured for two way communication with each other via a communication network, the service provider device associated with a service provider and the user device associated with a user,

a user credential issuer device, the user credential issuer device being a server associated with a user credential issuer, configured for two way communication with the service provider device and the user device, the user credential issuer configured to manage identities of users, extract user credential information, and write user credential information to a user credential database,

the service provider device configured to receive an access request from the user device, and authenticate a user based on a unique user credential associated with the user, wherein the unique user credential is issued by the user credential issuer that is authorized by the service provider to issue user credentials,

the service provider device configured to establish a service session between the user device and the service provider device to allow the user to use a service provided by the service provider,

wherein the service provider device is further configured to generate a session token that corresponds to the service session, and encode the session token with an authorization criteria; and wherein the service provider device is configured to:

receive a response data packet comprising at least a user credential identifier from the user device,

determine a user credential that corresponds to the user credential identifier;

wherein the user device is configured to generate the response data packet comprising the user credential identifier, and the user device is configured to sign the response data packet with at least a private key using an asymmetric cryptographic process,

wherein the service provider device is configured to verify the response data by a public key located in the user credential received from the user credential issuer device, and

the service provider device is configured to determine a user credential is a match if the public key corresponds to the private key used to sign the response data packet.

2. The system in accordance with claim 1 , wherein the unique user credential is a unique ID certificate associated with the user, wherein the ID certificate is a data object defining at least a user identity and a user credential issuer identity.

3. The system in accordance with claim 1 , wherein

the user credential issuer device is configured to issue the unique user credential to a user, and wherein the user credential issuer is authorized by the service provider as an accepted user credential issuer.

4. The system in accordance with claim 1 , wherein the service provider device is configured to query the credential issuer device with the received user credential identifier,

the user credential issuer device configured to transmit a user credential corresponding to the user credential identifier,

the service provider device configured to receive the user credential corresponding to the user credential identifier, and

the service provider device configured to check the received user credential corresponds to the received user credential identifier.

5. The system in accordance with claim 4 , wherein the service provider device establishes a service session if the received user credential from the credential issuer device corresponds to the user credential identifier received by the service provider device, as part of the response data packet transmitted by the user device.

6. The system in accordance with claim 1 , wherein the session token is a data object that comprises one or more of an ID of a session data field and an authorization criteria data field.

7. The system in accordance with claim 1 wherein the authorization criteria comprises at least an accepted user credential issuer data field that defines the user credential issuer that will be accepted by the service provider in order to authenticate the user.

8. The system in accordance with claim 1 , wherein the service provider device is configured to provide a visual code to the user device, wherein the visual code comprises the session token.

9. The system in accordance with claim 8 , wherein the visual code is a machine readable optical code that is configured to be read or scanned by the user device to extract information from the visual code.

10. The system in accordance with claim 8 , wherein the visual code is one of a one dimensional barcode or a two dimensional code.

11. The system in accordance with claim 8 , wherein the user device receives the visual code from the service provider device in response to a use request, the user device is configured to decode the visual code to extract the session token from the visual code, and the user device is configured to process the session token to extract a user credential identifier.

12. The system in accordance with claim 8 , wherein the user device is further configured to identify a user credential issuer from the user credential issuer data field in of the session token, the user device is configured to identify a user credential issuer from the user credential issuer data field of the session token, the user device configured to identify a user credential that corresponds to the user credential issuer, and; the user device configured to identify the user credential identifier based on the identified user credential.

13. The system in accordance with claim 1 , wherein the system comprises a key generator, the user device configured to obtain a key pair from the key generator, wherein the key pair comprises the public key and the private key, and wherein the user device comprises the key generator and the key generator being controlled by the user device.

14. The system in accordance with claim 13 , wherein the user device is configured to query a user database of user credentials to identify a user credential that corresponds to a received user credential issuer defined in a user credential issuer data field within the received session token, the user database comprising a list of one or more user credentials issued by each user credential issuer, the database relating each user credential with the user credential issuer that issued the user credential,

the database being populated by an electronic registration process, and;

wherein the user device is configured to identify the user credential that corresponds to the user credential issuer listed in the session token.

15. The system in accordance with claim 1 , wherein the electronic registration process is implemented by the system for authenticating a user wherein

the user credential issuer is configured to receive a request for a unique user credential from the user device,

the user credential issuer configured to create a unique user credential associated with the user based on a verified identity of the user, the identity of the user being verified by the user credential issuer,

the user credential issuer device configured to transmit the user credential to the user device, and

the user device configured to receive and store the user credential from the user credential issuer device in the user database.

16. The system in accordance with claim 15 , wherein the user device is further configured to generate a key pair of a private key and a public key, the user device configured to associated the received user credential with the generated key pair, and the user device is configured to provide the public key of the key pair associated with the user credential to the user credential issuer device for storing by the user credential issuer device.

17. A computer implemented method of authentication of a user, the method comprising steps of:

providing a use request to a service provider device from a user device,

receiving the use request by the service provider device,

generating a session token by the service provider device, wherein the session token is a data object that comprises one or more of an ID of the session data field and an authorization criteria data field,

wherein the authorization criteria comprises at least an accepted user credential issuer data field that defines the user credential issuer that will be accepted by the service provider in order to authenticate the user,

providing a visual code to the user device by the service provider device, wherein the visual code comprises the session token generated by the service provider device,

the visual code is a machine readable optical code that is configured to be read or scanned by the user device to extract information from the visual code, wherein the visual code is a machine readable code is a barcode,

decoding the visual code to extract the session token from the visual code,

processing the session token to extract a user credential issuer from the user credential issuer data field of the session token,

querying a user database of user credentials to identify a unique user credential that corresponds to a received user credential issuer, the user database storing a list of one or more unique user credentials that correspond to each user credential issuer, wherein each of the unique user credentials is issued by a said user credential issuer which is authorized by the service provider to issue user credentials,

the user database being populated by a computer implemented registration process,

identifying the user credential that corresponds to the user credential issuer listed in the session token,

generating a response data packet comprising the user credential identifier,

signing the response data packet with a private key using an asymmetric cryptographic process, a challenge data field of the response data packet being signed by the private key, and

verifying the response data packet by a public key located in the user credential received from the user credential issuer, and the received user credential is considered to match if the public key corresponds to the private key used to sign the response data packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2020
From: SO, CHEUK YIU
To: PRISEC INNOVATION LIMITED
Reel/Frame 052669/0990 →
Continuity (1)
Related Publication 20200366484A1 · Nov 19, 2020