In-band identity verification and man-in-the-middle defense

US9716714B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9716714-B1
Application numberUS-201615381052-A
CountryUS
Kind codeB1
Filing dateDec 15, 2016
Priority dateJun 27, 2014
Publication dateJul 25, 2017
Grant dateJul 25, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A variety of techniques for performing identity verification are disclosed. As one example, a verification request is received from a remote user. The verification request pertains to a cryptographic key. In response to receiving a confirmation from a local user of the local device, a verification process is initiated. A result of the verification process is transmitted to the remote user. As a second example, a verification request can be received at the local device, from a local user of the device. A verification process with respect to the local user is initiated, and a result of the verification process is transmitted to a remote user that is different from the local user.

First claim

Opening claim text (preview).

What is claimed is: 1. A method, comprising: receiving, at a local device, a verification request from a remote user in conjunction with a contact made by the remote user with a local user, wherein the verification request includes a request for a representation of a cryptographic hash value of a cryptographic key of the local user; in response to a confirmation received from the local user of the local device, initiating a verification process, wherein the verification process includes capturing audiovisual content by the local device and the audiovisual content includes the representation of the cryptographic hash value; and transmitting a result of the verification process to the remote user. 2. The method of claim 1 wherein the verification request comprises a fingerprint verification. 3. The method of claim 1 wherein the verification process includes displaying a script to the is local user. 4. The method of claim 3 wherein the script includes a dynamic element. 5. The method of claim 4 wherein the dynamic element includes at least one of a date and time. 6. The method of claim 4 wherein the dynamic element includes a representation of a fingerprint. 7. The method of claim 6 wherein the fingerprint corresponds to a public key associated with the local user. 8. The method of claim 1 wherein the result, when viewed by the remote user, includes an audiovisual component and an overlay component. 9. The method of claim 8 wherein the overlay component includes a representation of a fingerprint. 10. The method of claim 8 wherein the overlay component is provided by a device used by the remote user to view the result. 11. The method of claim 1 wherein the verification request is received from the remote user in conjunction with a first contact made by the remote user with the local user. 12. A method, comprising: receiving at a local device, in conjunction with a contact made by a remote user with a local user, content purporting to establish an identity of the remote user at a remove device, wherein the content includes an audiovisual component that includes a representation of a cryptographic hash value of a cryptographic key of the remote user; displaying, to the local user, the received content; and recording an authentication verdict provided by the local user in conjunction with reviewing the received response, wherein an indication of the verdict is provided to the remote user in a messaging interface. 13. The method of claim 12 wherein displaying the received response includes displaying an overlay component. 14. The method of claim 13 wherein the overlay component includes a representation of a fingerprint. 15. The method of claim 14 wherein the fingerprint is associated with the remote user. 16. The method of claim 12 wherein the system is configured to transmit the verdict to a remote server. 17. A non-transitory computer-readable medium comprising instructions that when, executed by at least one hardware processor, perform the steps of, comprising: receiving, at a local device, a verification request from a remote user in conjunction with a contact made by the remote user with a local user, wherein the verification request includes a request for a representation of a cryptographic hash value of a cryptographic key of the local user; in response to a confirmation received from the local user of the local device, initiating a verification process, wherein the verification process includes capturing audiovisual content by the local device and the audiovisual content includes the representation of the cryptographic hash value; and transmitting a result of the verification process to the remote user. 18. A non-transitory computer-readable medium comprising instructions that when, executed by at least one hardware processor, perform the steps of, comprising: receiving at a local device, in conjunction with a contact made by a remote user with a local user, content purporting to establish an identity of the remote user at a remove device, wherein the content includes an audiovisual component that includes a representation of a cryptographic hash value of a cryptographic key of the remote user; displaying, to the local user, the received content; and recording an authentication verdict provided by the local user in conjunction with reviewing the received response, wherein an indication of the verdict is provided to the remote user in a messaging interface.

Assignees

Inventors

Classifications

  • G06F21/32Primary

    using biometric data, e.g. fingerprints, iris scans or voiceprints · CPC title

  • received data contents, e.g. message integrity · CPC title

  • File encryption · CPC title

  • for key distribution, e.g. centrally by trusted party (cryptographic mechanisms or cryptographic arrangements for key distribution involving a central third party H04L9/0819) · CPC title

  • Hash functions, e.g. MD5, SHA, HMAC or f9 MAC · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9716714B1 cover?
A variety of techniques for performing identity verification are disclosed. As one example, a verification request is received from a remote user. The verification request pertains to a cryptographic key. In response to receiving a confirmation from a local user of the local device, a verification process is initiated. A result of the verification process is transmitted to the remote user. As a…
Who is the assignee on this patent?
Wickr Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/32. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jul 25 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).