EP4016920A1

Confidential authentication and provisioning

Abstract

Some embodiments provide systems and methods for confidentially and securely provisioning data to an authenticated user device. A user device may register an authentication public key with an authentication server. The authentication public key may be signed by an attestation private key maintained by the user device. Once the user device is registered, a provisioning server may send an authentication request message including a challenge to the user device. The user device may sign the challenge using an authentication private key corresponding to the registered authentication public key, and may return the signed challenge to the provisioning server. In response, the provisioning server may provide provisioning data to the user device. The registration, authentication, and provisioning process may use public key cryptography while maintaining confidentiality of the user device, the provisioning server, and then authentication server.

EP4016920A1, drawing sheet 1
Sheet 1 of 8

Term

9.8 yearsto projected expiry

Projected expiry 30 June 2036, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 2 independent, 13 dependent

  1. 1
    A computer-implemented method comprising:obtaining, by an authentication server, a user device authentication public key via a registration process, the registration process comprising: receiving, by the authentication server, from the user device, a signed user device authentication public key generated by the user device signing the user device authentication public key using a user device attestation private key, the user device attestation private key corresponding to a user device attestation public key and validating, by the authentication server, the signed user device authentication public key using the user device attestation public key;sending, by the authentication server, an authentication challenge to the user device;receiving, by the authentication server, an authentication response from the user device, the authentication response comprising a signed authentication challenge;and authenticating, by the authentication server, the user device based on verifying the signed authentication challenge using the user device authentication public key.
  2. 7
    A computer-implemented method comprising:signing, by a user device, a user device authentication public key using a user device attestation private key to obtain a signed user device authentication public key, the user device attestation private key corresponding to a user device attestation public key;sending, by the user device, a registration response to an authentication server, the registration response including the signed user device authentication public key;receiving, by the user device, an authentication challenge from the authentication server;generating, by the user device, a signed authentication challenge by signing the authentication challenge using a user device authentication private key corresponding to the user device authentication public key;and sending, by the user device, an authentication response including the signed authentication challenge to the authentication server, wherein the authentication server authenticates the user device based on verifying the signed authentication challenge using the user device authentication public key.