×

Automatic replacement of passwords with secure claims

  • US 10,484,372 B1
  • Filed: 12/14/2015
  • Issued: 11/19/2019
  • Est. Priority Date: 12/14/2015
  • Status: Active Grant
First Claim
Patent Images

1. A computer system, comprising:

  • a network interface configured to transmit data over a network;

    a biometric sensor configured to acquire biometric data of a user;

    a secure storage element configured to store data including the biometric data acquired by the biometric sensor;

    an input device;

    one or more hardware processors operatively coupled to the network interface, the biometric sensor, the secure storage element, and the input device; and

    memory operatively coupled to the one or more hardware processors, the memory storing an operating system and an application program that includes instructions executable by the one or more hardware processors that, as a result of execution by the one or more hardware processors, cause the one or more hardware processors to;

    establish a secure session between the computer system and a server using a user credential;

    responsive to receiving a selection via the input device for authentication using the biometric data, configure the application program for authentication using the biometric data, and generate an asymmetric cryptographic key pair;

    store a first key of the cryptographic key pair in the secure storage element via the operating system, without storing the user credential in the secure storage element, wherein access to the first key is secured by the biometric data;

    transmit a second key of the cryptographic key pair to the server via the network for storage in association with a user account associated with the user;

    responsive to receiving a request to perform an action that requires the application program to authenticate an identity of the user of the computing system with the server, activate a presentation device associated with the computer system so as to prompt the user to input new biometric data using the biometric sensor;

    responsive to the operating system authenticating the identity of the user using the new biometric data, retrieve the first key via the operating system from the secure storage element;

    encrypt an authentication data object using the first key to form an encrypted data object;

    transmit the encrypted data object to the server to enable the server to authorize the action that required authentication in lieu of the user credential, based on decrypting the encrypted data object using the stored second key; and

    as a result of authorization by the server responsive to the decrypting of the encrypted data object using the stored second key, proceed to conduct the action requested.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×