IP Library › Granted Patent US 11,936,775
Granted Patent B2
US 11,936,775 · App. 17/840,969 · Granted Mar 19, 2024

Authentication processing services for generating high-entropy cryptographic keys

Inventors: Paolo Gasti (New York, NY); Paul Galwas (St. Ives, GB); Andrea Carmignani (Rome, IT); Jaroslav {hacek over (S)}ed{hacek over (e)}nka (Hranice, CZ)
Assignee: KEYLESS TECHNOLOGIES SRL
H04L9/0825G06F21/6245H04L9/0866H04L9/14H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,936,775
App. No.
17/840,969
Granted
Mar 19, 2024
Kind
B2
Abstract

Systems, methods, and computer-readable media for facilitating an authentication processing service are provided.

Claims (95)

1. A method for enrolling a user in a system comprising a first subsystem and a second subsystem storing a server secret, the method comprising:

selecting, at the first subsystem, an enrollment codeword from a codeword space;

obtaining, at the first subsystem, an enrollment template indicative of enrollment information provided by the user;

computing, at the first subsystem, a trusted user secret based on the enrollment codeword and the enrollment template; and

running, at the first subsystem, an instance of a two-party protocol with the second subsystem using the enrollment codeword and the server secret to generate an enrollment key;

obtaining ( 522 , 722 ), at the first subsystem, an authentication sample indicative of authentication information provided by an entity;

computing ( 524 , 724 ), at the first subsystem, an authentication codeword by decoding a decombination of the trusted user secret and the authentication sample; and

running ( 525 , 725 ), at the first subsystem, an instance ( 527 d , 727 d ) of the two-party protocol with the second subsystem using the authentication codeword and the server secret to generate an authentication key.

2. The method of claim 1 , further comprising protecting, at the first subsystem, sensitive data using the enrollment key.

3. The method of claim 2 , further comprising storing the protected sensitive data on the first subsystem.

4. The method of claim 2 , further comprising storing the protected sensitive data on a third subsystem remote from the first subsystem.

5. The method of claim 2 , further comprising, after the protecting, deleting sensitive enrollment information from the first subsystem, wherein the sensitive enrollment information comprises:

the selected enrollment codeword;

the obtained enrollment template; and

the generated enrollment key.

6. The method of claim 2 , further comprising, after the protecting but prior to each one of the following:

the obtaining, at the first subsystem, the authentication sample indicative of the authentication information provided by the entity;

the computing, at the first subsystem, the authentication codeword by decoding the decombination of the trusted user secret and the authentication sample; and

the running, at the first subsystem, the instance of the two-party protocol with the second subsystem using the authentication codeword and the server secret to generate the authentication key, deleting sensitive enrollment information from the first subsystem, wherein the sensitive enrollment information comprises:

the selected enrollment codeword;

the obtained enrollment template; and

the generated enrollment key.

7. The method of claim 6 , further comprising:

accessing, at the first subsystem, the protected sensitive data; and

unprotecting, at the first subsystem, the protected sensitive data using the authentication key.

8. The method of claim 7 , further comprising, after the unprotecting, deleting sensitive authentication information from the first subsystem, wherein the sensitive authentication information comprises:

the obtained authentication sample;

the computed authentication codeword; and

the generated authentication key.

9. The method of claim 1 , further comprising:

generating, at the first subsystem, an enrollment payload based on the enrollment key;

sending, from the first subsystem to a third subsystem remote from the first subsystem, at least a first portion of the enrollment payload; and

after the sending, deleting sensitive enrollment information from the first subsystem, wherein the sensitive enrollment information comprises:

the selected enrollment codeword;

the obtained enrollment template;

the generated enrollment key; and

at least a second portion of the enrollment payload.

10. The method of claim 9 , wherein the enrollment payload comprises an enrollment user keypair comprising an enrollment user public key and an enrollment user private key.

11. The method of claim 10 , wherein:

the sending comprises sending, from the first subsystem to the third subsystem, the enrollment user public key of the enrollment user key pair of the enrollment payload; and

the at least a second portion of the enrollment payload comprises the enrollment user private key of the enrollment user key pair.

12. The method of claim 11 , further comprising, after the deleting the sensitive enrollment information and after each one of the following:

the obtaining, at the first subsystem, the authentication sample indicative of the authentication information provided by the entity;

the computing, at the first subsystem, the authentication codeword by decoding the decombination of the trusted user secret and the authentication sample; and

the running, at the first subsystem, the instance of the two-party protocol with the second subsystem using the authentication codeword and the server secret to generate the authentication key, generating, at the first subsystem, an authentication payload based on the authentication key, wherein the authentication payload comprises an authentication user keypair comprising an authentication user public key and an authentication user private key;

sending, from the first subsystem to the third subsystem, a challenge response comprising a challenge signed by the authentication user private key of the authentication payload; and

after the sending the challenge response, deleting sensitive authentication information from the first subsystem, wherein the sensitive authentication information comprises:

the obtained authentication sample;

the computed authentication codeword;

the generated authentication key; and

at least the authentication user private key of the authentication payload.

13. The method of claim 12 , further comprising, prior to the sending the challenge response, receiving, at the first subsystem from the third subsystem, the challenge.

14. The method of claim 9 , wherein the enrollment payload comprises an enrollment hash value comprising the result of a hash function on the enrollment key.

15. The method of claim 14 , wherein:

the sending comprises sending, from the first subsystem to the third subsystem, the enrollment hash value of the enrollment payload and the trusted user secret;

the at least a second portion of the enrollment payload comprises the enrollment hash value of the enrollment payload; and

the sensitive enrollment information further comprises the trusted user secret.

16. The method of claim 15 , further comprising:

after the deleting the sensitive enrollment information and after the obtaining, at the first subsystem, the authentication sample indicative of the authentication information provided by the entity, accessing, at the first subsystem from the third subsystem, the trusted user secret and the enrollment hash value; and

after the computing, at the first subsystem, the authentication codeword by decoding the decombination of the trusted user secret and the authentication sample and after the running, at the first subsystem, the instance of the two-party protocol with the second subsystem using the authentication codeword and the server secret to generate the authentication key:

generating, at the first subsystem, an authentication payload based on the authentication key, wherein the authentication payload comprises an authentication hash value comprising the result of the hash function on the authentication key; and

comparing, at the first subsystem, the authentication hash value with the enrollment hash value.

17. The method of claim 16 , further comprising selectively providing, to the entity with the first subsystem, secure access based on the comparing.

18. The method of claim 16 , further comprising, after the comparing, deleting sensitive authentication information from the first subsystem, wherein the sensitive authentication information comprises:

the obtained authentication sample;

the computed authentication codeword;

the generated authentication key;

the trusted user secret;

the enrollment hash value; and

the authentication hash value.

19. The method of claim 9 , wherein the third subsystem is remote from the second subsystem.

20. The method of claim 1 , wherein the running, at the first subsystem, the instance of the two-party protocol with the second subsystem using the enrollment codeword and the server secret to generate the enrollment key occurs prior to the computing, at the first subsystem, the trusted user secret based on the enrollment codeword and the enrollment template.

21. The method of claim 1 , wherein the enrollment information comprises biometrics of the user.

22. The method of claim 21 , wherein the enrollment information comprises biometrics of the user.

23. The method of claim 1 , wherein the enrollment key is accessible to the first subsystem but not to the second subsystem.

24. The method of claim 1 , wherein the authentication information comprises biometrics of the entity.

25. A non-transitory computer-readable storage medium storing at least one program, the at least one program comprising instructions, which, when executed by at least one processor of an electronic subsystem, cause the at least one processor to:

select an enrollment codeword from a codeword space;

obtain an enrollment template indicative of enrollment information provided by a user;

compute a trusted user secret based on the enrollment codeword and the enrollment template;

run an instance of a two-party protocol with another electronic subsystem using the enrollment codeword and a secret of the other electronic subsystem to generate an enrollment key;

obtain an authentication sample indicative of authentication information provided by an entity;

compute an authentication codeword by decoding a decombination of the trusted user secret and the authentication sample; and

run an instance of the two-party protocol with the other electronic subsystem using the authentication codeword and the secret of the other electronic subsystem to generate an authentication key.

26. A user electronic device comprising:

a memory component;

a communications component; and

a processor coupled to the memory component and the communications component, the processor configured to:

select an enrollment codeword from a codeword space;

obtain an enrollment template indicative of enrollment information provided by a user;

compute a trusted user secret based on the enrollment codeword and the enrollment template;

run, via the communications component, an instance of a two-party protocol with another electronic device using the enrollment codeword and a secret of the other electronic device to generate an enrollment key;

obtain an authentication sample indicative of authentication information provided by an entity;

compute an authentication codeword by decoding a decombination of the trusted user secret and the authentication sample; and

run an instance of the two-party protocol with the other electronic device using the authentication codeword and the secret of the other electronic device to generate an authentication key.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2026
From: KEYLESS TECHNOLOGIES SRL
To: PING IDENTITY LIMITED
Reel/Frame 074590/0371 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2022
From: GASTI, PAOLO; GALWAS, PAUL; CARMIGNANI, ANDREA; SEDENKA, JAROSLAV
To: KEYLESS TECHNOLOGIES SRL
Reel/Frame 060211/0075 →
Continuity (2)
Provisional Application 63231708 · Aug 10, 2021
Related Publication 20230048912A1 · Feb 16, 2023