Automatic provisioning and onboarding of offline or disconnected machines
US-12182236-B2 · Dec 31, 2024 · US
US2025181686A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2025181686-A1 |
| Application number | US-202418973708-A |
| Country | US |
| Kind code | A1 |
| Filing date | Dec 9, 2024 |
| Priority date | Jun 21, 2019 |
| Publication date | Jun 5, 2025 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Disclosed herein is an identity network that provides a universal, digital identity for users to be authenticated by an identity provider for relying parties upon sign-in to the relying party. The identity network receives the sign-in request from a relying party for a user using a user device. The identity network can provide a session identifier to the relying party for the request and launch an identity provider application associated with the user via a software development kit in the relying party application. The user may sign-in to the identity provider via the software development kit, thereby authenticating the user for the relying party. Additionally, the identity provider may generate a risk validation score and provide it to the relying party that provides a confidence value that the user is validly using the user device and a risk score based on device activity on the identity network.
Opening claim text (preview).
1 . (canceled) 2 . A method for sign-in using a universal digital identity, the method comprising: receiving, at an identity network, a sign-in request for a user of a user device from a relying party; identifying, by the identity network, an identity provider associated with the sign-in request; launching, by the identity network, an identity provider application of the identity provider on the user device; receiving, by the identity network from the identity provider, confirmation of a digital identity of the user including a digital signature from the user device; receiving, by the identity network from the relying party, a confirmation request that the identity provider authenticated the user; and in response to receiving the confirmation request, providing, by the identity network to the relying party, the digital signature of the user device. 3 . The method for sign-in using a universal digital identity of claim 2 , further comprising: identifying the user based on the sign-in request. 4 . The method for sign-in using a universal digital identity of claim 2 , wherein: the digital signature is tied to the user of the user device. 5 . The method for sign-in using a universal digital identity of claim 2 , wherein: identifying the identity provider associated with the sign-in request comprises receiving the identity provider as a selection from the user device from a list of a plurality of identity providers. 6 . The method for sign-in using a universal digital identity of claim 2 , wherein: identifying the identity provider associated with the sign-in request comprises accessing a token that indicates a previous relationship between the identity provider and the user in use in authenticating the user. 7 . The method for sign-in using a universal digital identity of claim 6 , wherein: the token was generated by the identity network. 8 . The method for sign-in using a universal digital identity of claim 6 , wherein: the token was provided to the identity network by the user device. 9 . An identity network, comprising: one or more processors; and a memory having stored thereon instructions that, upon execution by the one or more processors, cause the one or more processors to: receive a sign-in request for a user of a user device from a relying party; identify an identity provider associated with the sign-in request; launch an identity provider application of the identity provider on the user device; receive, from the identity provider, confirmation of a digital identity of the user including a digital signature from the user device; receive, from the relying party, a confirmation request that the identity provider authenticated the user; and in response to receiving the confirmation request, provide, to the relying party, the digital signature of the user device. 10 . The identity network of claim 9 , wherein: launching the identity provider application of an identity provider is done using a software development kit of a relying party application. 11 . The identity network of claim 9 , wherein: the instructions further cause the identity network to provide a session identifier to the relying party; launching the identity provider application comprises providing the session identifier to the identity provider application; the confirmation of a digital identity of the user comprises the session identifier; the confirmation request comprises the session identifier; and the instructions further cause the identity network to provide the session identifier to the relying party in response to receiving the confirmation request. 12 . The identity network of claim 9 , wherein: the identity provider application is launched using a deep link. 13 . The identity network of claim 9 , wherein the instructions further cause the identity network to: receive a device identifier from the user device; determine whether the user device is associated with any potentially fraudulent activity; generate a risk validation score based on determining whether the user device is associated with any potentially fraudulent activity; and transmit the risk validation score to the relying party. 14 . The identity network of claim 13 , wherein: determining whether the user device is associated with any potentially fraudulent activity comprises accessing data associated with prior activity of the user device with one or both of a relying party and an identity provider. 15 . The identity network of claim 9 , wherein: the digital signature comprises one or both of a token and a credential that is specific to the user of the user device. 16 . A non-transitory, computer-readable medium having stored thereon instructions that, upon execution by one or more processors of an identity network, cause the identity network to: receive a sign-in request for a user of a user device from a relying party; identify an identity provider associated with the sign-in request; launch an identity provider application of the identity provider on the user device; receive, from the identity provider, confirmation of a digital identity of the user including a digital signature from the user device; receive, from the relying party, a confirmation request that the identity provider authenticated the user; and in response to receiving the confirmation request, provide, to the relying party, the digital signature of the user device. 17 . The non-transitory, computer readable medium of claim 16 , wherein the instructions further cause the identity network to: receive data from the user device; and determine whether the user device has been previously used for the user in the identity network. 18 . The non-transitory, computer readable medium of claim 17 , wherein the instructions further cause the identity network to: in response to determining that the user device has been previously used for the user in the identity network, validate the user device. 19 . The non-transitory, computer readable medium of claim 17 , wherein the instructions further cause the identity network to: in response to determining that the user device has not been previously used for the user in the identity network, generate an entry in a data store that associates the user with the user device. 20 . The non-transitory, computer readable medium of claim 17 , wherein: the data comprises at least one of a device identifier, hardware of the user device, software of the user device, data stored on the user device, network connection information of the user device, or mobile provider accounts of the user device. 21 . The non-transitory, computer readable medium of claim 16 , wherein: the confirmation of the digital identity comprises a sign-in result from the identity provider; and the instructions further cause the identity network to validate one or both of the user and the user device.
by remotely controlling device operation · CPC title
using credential vaults, e.g. password manager applications or one time password [OTP] applications · CPC title
Authentication · CPC title
using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title
providing single-sign-on or federations · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.