IP Library Granted Patent US 12,301,705
Granted Patent B2
US 12,301,705 · App. 17/857,001 · Granted May 13, 2025

Optimized authentication system

Inventor: Mindaugas Valkaitis (Vilnius, LT)
Assignee: UAB 360 IT
H04L9/0822H04L9/0866H04L9/14H04L63/0428H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,705
App. No.
17/857,001
Granted
May 13, 2025
Kind
B2
Abstract

A method including encrypting, by a processor associated with a user device, first factor authentication information associated with determining a first authentication factor; enabling, by the processor, encryption of second factor authentication associated with determining a second authentication factor; detecting, by the processor, an attempt by the user device to access a service to be provided by a service provider; determining, by the processor based at least in part on detecting the attempt, the first authentication factor based at least in part on decrypting the first factor authentication information; determining, by the processor, the second authentication factor based at least in part on enabling decryption of the second factor authentication information; and enabling, by the processor, authentication of the user device with the service provider based at least in part on utilizing the first authentication factor and the second authentication factor is disclosed. Various other aspects are contemplated.

Claims (65)

1. A method, comprising:

encrypting, by a processor included in a user device, first factor authentication information associated with determining a first authentication factor;

enabling, by the processor, encryption of second factor authentication associated with determining a second authentication factor;

detecting, by the processor, an attempt by the user device to access a service to be provided by a service provider;

determining, by the processor based at least in part on detecting the attempt, the first authentication factor based at least in part on decrypting the first factor authentication information; and

determining, by the processor, the second authentication factor based at least in part on enabling decryption of the second factor authentication information; and

enabling, by the processor, authentication of the user device with the service provider based at least in part on utilizing the first authentication factor and the second authentication factor, wherein

detecting the attempt to access the service includes comparing, by the user device, a network address associated with the service provider with communication information associated with the service provider.

2. The method of claim 1 , wherein

encrypting the first factor authentication information includes utilizing a first master key determined based at least in part on a master string, and

enabling encryption of the second factor authentication information includes enabling utilization of a second master key that is inaccessible by the processor.

3. The method of claim 1 , wherein encrypting the first factor authentication information includes encrypting a first cryptographic key that is utilized to encrypt the first factor authentication information by utilizing an access public key specific to the first cryptographic key, encrypting an access private key that is associated with the access public key by utilizing an assigned public key specific to the user device, and encrypting an assigned private key that is associated with the assigned public key by utilizing a first master key.

4. The method of claim 1 , wherein decrypting the first factor authentication information includes decrypting an assigned private key associated with the user device by utilizing the first master key, decrypting an access private key associated with a first cryptographic key utilized to encrypt the first factor authentication information by utilizing the assigned private key, decrypting the first cryptographic key by utilizing the access private key, and decrypting the first factor authentication information by utilizing the first cryptographic key.

5. The method of claim 1 , wherein detecting the attempt to access the service includes detecting transmission of a request by the user device for the service to a network address associated with the service provider.

6. The method of claim 1 , wherein determining the second authentication factor includes determining the second authentication factor based at least in part on utilizing a security algorithm and the decrypted second factor authentication information.

7. The method of claim 1 , wherein enabling encryption of the second factor authentication information includes verifying first biometric information, and enabling decryption of the second factor authentication information includes verifying second biometric information.

8. A user device, comprising:

a memory; and

a processor communicatively coupled to the memory, the memory and the processor being configured to:

encrypt first factor authentication information associated with determining a first authentication factor;

enable encryption of second factor authentication associated with determining a second authentication factor;

detect an attempt by the user device to access a service to be provided by a service provider;

determine, based at least in part on detecting the attempt, the first authentication factor based at least in part on decrypting the first factor authentication information;

determine the second authentication factor based at least in part on enabling decryption of the second factor authentication information; and

enable authentication of the user device with the service provider based at least in part on utilizing the first authentication factor and the second authentication factor, wherein

to detect the attempt to access the service, the memory and the processor are configured to compare a network address associated with the service provider with communication information associated with the service provider.

9. The user device of claim 8 , wherein,

to encrypt the first factor authentication information, the memory and the processor are configured to utilize a first master key determined based at least in part on a master string, and

to enable encryption of the second factor authentication information, the memory and the processor are configured to enable utilization of a second master key that is inaccessible by the memory and processor.

10. The user device of claim 8 , wherein, to encrypt the first factor authentication information, the memory and the processor are configured to:

encrypt a first cryptographic key that is utilized to encrypt the first factor authentication information by utilizing an access public key specific to the first cryptographic key,

encrypt an access private key that is associated with the access public key by utilizing an assigned public key specific to the user device, and

encrypt an assigned private key that is associated with the assigned public key by utilizing a first master key.

11. The method of claim 1 , wherein, to decrypt the first factor authentication information, the memory and the processor are configured to:

decrypt an assigned private key that is associated with the user device by utilizing the first master key,

decrypt an access private key that is associated with a first cryptographic key utilized to encrypt the first factor authentication information by utilizing the assigned private key,

decrypt the first cryptographic key by utilizing the access private key, and

decrypt the first factor authentication information by utilizing the first cryptographic key.

12. The user device of claim 8 , wherein, to detect the attempt to access the service, the memory and the processor are configured to detect transmission of a request by the user device for the service to a network address associated with the service provider.

13. The user device of claim 8 , wherein, to determine the second authentication factor, the memory and the processor are configured to determine the second authentication factor based at least in part on utilizing a security algorithm and the decrypted second factor authentication information.

14. The user device of claim 8 , wherein

to enable encryption of the second factor authentication information, the memory and the processor are configured to verify first biometric information, and

to enable decryption of the second factor authentication information, the memory and the processor are configured to verify second biometric information.

15. A non-transitory computer-readable medium configured to store instructions, which when executed by a processor included in a user device, configure the processor to:

encrypt first factor authentication information associated with determining a first authentication factor;

enable encryption of second factor authentication associated with determining a second authentication factor;

detect an attempt by the user device to access a service to be provided by a service provider;

determine, based at least in part on detecting the attempt, the first authentication factor based at least in part on decrypting the first factor authentication information;

determine the second authentication factor based at least in part on enabling decryption of the second factor authentication information; and

enable authentication of the user device with the service provider based at least in part on utilizing the first authentication factor and the second authentication factor, wherein

to detect the attempt to access the service, the memory and the processor are configured to compare a network address associated with the service provider with communication information associated with the service provider.

16. The non-transitory computer-readable medium of claim 15 , wherein

to encrypt the first factor authentication information, the processor is configured to utilize a first master key determined based at least in part on a master string, and

to enable encryption of the second factor authentication information, the processor is configured to enable utilization of a second master key that is inaccessible by the memory and processor.

17. The non-transitory computer-readable medium of claim 15 , wherein, to encrypt the first factor authentication information, the processor is configured to:

encrypt a first cryptographic key that is utilized to encrypt the first factor authentication information by utilizing an access public key specific to the first cryptographic key,

encrypt an access private key that is associated with the access public key by utilizing an assigned public key specific to the user device, and

encrypt an assigned private key that is associated with the assigned public key by utilizing a first master key.

18. The non-transitory computer-readable medium of claim 15 , wherein, to decrypt the first factor authentication information, the memory and the processor are configured to:

decrypt an assigned private key that is associated with the user device by utilizing the first master key,

decrypt an access private key that is associated with a first cryptographic key utilized to encrypt the first factor authentication information by utilizing the assigned private key,

decrypt the first cryptographic key by utilizing the access private key, and

decrypt the first factor authentication information by utilizing the first cryptographic key.

19. The non-transitory computer-readable medium of claim 15 , wherein, to detect the attempt to access the service, the processor is configured to detect transmission of a request by the user device for the service to a network address associated with the service provider.

20. The non-transitory computer-readable medium of claim 15 , wherein, to determine the second authentication factor, the processor is configured to determine the second authentication factor based at least in part on utilizing a security algorithm and the decrypted second factor authentication information.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2022
From: VALKAITIS, MINDAUGAS
To: UAB 360 IT
Reel/Frame 060763/0257 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2022
From: VALKAITIS, MINDAUGAS
To: UAB 360 IT
Reel/Frame 060601/0191 →
Continuity (2)
Continuation 17853887 · Jun 29, 2022
Related Publication 20240007445A1 · Jan 4, 2024
References Cited (11)
US 11228421B1 · Mesh et al. · 2022 [cited by applicant]
US 11405387B1 · Griffin et al. · 2022 [cited by applicant]
US 20140321641A1 · Khosravi et al. · 2014 [cited by applicant]
US 20170357867A1 · Kursun · 2017 [cited by examiner]
US 20190052467A1 · Bettger · 2019 [cited by applicant]
US 20200028832A1 · Proulx et al. · 2020 [cited by applicant]
US 20200358761A1 · Ya · 2020 [cited by examiner]
US 20220060317A1 · Ponnuswamy · 2022 [cited by examiner]
US 20220109574A1 · Narumanchi · 2022 [cited by examiner]
US 20220255923A1 · Szigeti et al. · 2022 [cited by applicant]
US 20220353233A1 · Helfinstine · 2022 [cited by examiner]