Single-click login process

By generating anonymous identifiers and encryption keys on personal computing devices, the low security and management difficulties of username and password login systems in existing technologies are solved, enabling secure and convenient login without usernames and passwords, and protecting the privacy of personal data.

CN113826095BActive Publication Date: 2026-03-27MEDISSEDA DAUS DE SAUD AG
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-02-11
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In existing technologies, login systems based on usernames and passwords suffer from low security, difficulty in management, susceptibility to tampering, and inability to effectively protect personal data. In particular, the use of usernames and passwords poses security risks when processing sensitive data.

Method used

Login software applications on personal computing devices (such as smartphones) are used to generate anonymous identifiers and associated encryption keys. Login is performed on the application server using the anonymous identifiers, and identity verification is performed in conjunction with the identity verification server to ensure that the login process is anonymous and secure.

Benefits of technology

It enables secure login without a username and password, reduces the complexity of password management, improves the security and convenience of the login process, protects the privacy of personal data, and prevents system administrators from tampering with or accessing the data without permission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113826095B_ABST
    Figure CN113826095B_ABST
Patent Text Reader

Abstract

A method and apparatus for securely logging a computer user into a computer system using an anonymous identifier is presented, thereby eliminating the use of a username and password and requiring only a single click or touch of the user to log into the computer. The anonymous identifier uniquely identifies the user and can be used as an encryption key.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application is in the field of secure identification of computer users when logging into computer systems, with the aid of an anonymous identifier. BACKGROUND

[0002] Logging into a computer network - the process by which a user in a client computer is identified by a server computer and granted access - is almost universally accomplished by the user keying in a username and password into a software application or operating system with a user key. This requires a registration process in which the user enters a name, personal identification data and preferences, and a selected user name (usually public and usually linked to the person's name), and a user-defined, user-remembered password (known only to that user and that host computer). The registration process occurs in the computer or computer terminal, and the username and password are recorded by the host computer. During use, the user is granted access by the host computer matching the data string entered by the user in the appropriate username and password fields with the corresponding username and password (in plain text or some form of encryption or hashing) recorded at the time of the user's registration.

[0003] However, the proliferation of computer user accounts has resulted in a problem that is characteristic of the Internet. Whereas in the past, a user typically had one school or work computer account, today's users sometimes need to manage dozens of school or work computer accounts, making the process more difficult due to the fact that many host computers require users to change their passwords frequently. This leads to unsafe behavior such as writing down someone's password. It is a difficult process to remember all passwords at the time of use, and this difficulty can lead to behavior that reduces security.

[0004] Furthermore, in most computer systems that use a username and password based user login system, the system administrator has access to the user's password to reset the password if needed. This means that the system administrator has the opportunity to reset the password of a username to a new value and log in as the user, potentially performing unauthorized or illegal operations under the unsuspecting identity of the user. Bypassing the system administrator's password reset process by sending a password reset link to the user's email address is more secure, but requires the host computer to know the identity of the user. There are other ways to enhance security, such as giving the user's electronic device that generates a code associated with the current time and requiring them to enter that session code after the username and password. Such a system is cumbersome and expensive, requiring each host computer to access a new electronic device. Recently, smartphones have begun to be used as session code generators, with the advantage of being larger than dedicated devices, but this still requires each application server to make its particular login software application available to each computer user, resulting in a clutter of applications in the smartphone.

[0005] Furthermore, there is a growing concern about unlicensed or unapproved use of personal data. Computer systems that typically require a user to reveal their identity via their well-known username and then confirm their identity using a password that is inherently insecure, which can be changed without the user's immediate knowledge, are very inadequate for protecting personal data.

[0006] Clearly, there is a need for a new secure login system that can address all of the above problems and this should be done by completely eliminating the username / password method. This is particularly desirable in computer systems that handle very sensitive data such as, for example, health, biometric, genetic, racial, financial, property, assets, tax, voting, purchase and transaction history data. It would be particularly useful to manage all of these data in a way that clearly and securely associates these data with a person, provided that these data are not linked by means of the person's name or a personal identifier that can be traced back to the person's name.

[0007] There are attempts in the prior art to eliminate passwords rather than usernames.

[0008] US patent 8954758 replaces passwords with user-generated gestures that are interpreted, mathematically converted into a string, which is appended to a login key to complete a full login expression. In other words, it replaces an alphanumeric password with an alphanumeric password derived from points in space traced by a human gesture and therefore still requires a host computer to store a username and full login expression.

[0009] US patent 9264423 allows passwordless login by sending a prompt to a user's pre-registered communication device, such as the user's mobile phone, to accept or reject a user's login request initiated at a different computer or terminal. The response to the prompt is sent to a login authority server, which then sends the user's response to an application server to grant or deny access. This is a complex system that requires four different computers: the user's client device where the user session starts; the application server that receives the user identifier of the client through a user-editable field as part of the user's login process; the login authority server that receives the application server's request for user authentication; and the user device, for example a mobile phone, where the same user receives a confirmation request from the login authority server to accept the login request and responds to it affirmatively or negatively. Furthermore, the user is identified by means of a user identifier, which can be a random number or user-selected. The described method requires the application server to know the user's name and all four computers need to participate whenever there is a login attempt.

[0010] We have now invented a method and apparatus in which the login control resides in the user's personal computing device, such as a smartphone, the login method does not utilize a traditional user name or use any kind of password or the user's smart phone number or email address, only the user computer and an application server. The application server is the server that the user wants to connect to for the data processing of interest. At login, the user remains anonymous to the application server or host computer and is identified only by means of an anonymous identifier. SUMMARY

[0011] The present disclosure describes an apparatus for use by a user to login to an application server, the apparatus designated as a personal computing device, such as a smartphone, tablet computer, laptop computer or personal computer. The personal computing device is provided with a processor, memory, data storage media, a display unit, one or more input devices such as a keyboard, pointing device, camera, microphone, motion detector, etc., a communication subsystem, an operating system, a power supply and means to execute software program instructions. The personal computing device is connected to one or more application servers, such as host computing systems, company servers, web servers, cloud computing systems, etc., through a communication network, such as a private network, public network or the Internet.

[0012] The application server essentially includes the same components as the personal computing device, but its processing power, memory and storage media will have much greater capacity and it will have access to the communication network through much greater bandwidth to accommodate simultaneous processing of multiple users.

[0013] To verify the user's identity and authenticate the user's personal computing device as a device under the user's control, in one embodiment of the present disclosure, an identity verification server is used and its components and capacity are similar to those of the application server described above.

[0014] To process data in the manner described in the present disclosure, the participating computers are programmed by computer programs specifically written for the tasks described. The personal computing device includes at least a login software application, the application server includes at least a user registration software application and a login and access software application (collectively, application server software applications) and the identity verification server includes at least a user identity verification software application. All software applications in each type of computer (personal computing device, identity verification server and application server) also include encryption software to at least generate asymmetric keys and digital signatures to ensure secure communication between all three computer systems.

[0015] In one aspect of the invention, a method for performing a secure user login process without a user-defined username or a user-defined password is described, wherein a user's personal computing device connects to a software distribution service and downloads and installs a login software application into the personal computing device, wherein the login software application generates a private key that will also serve as an anonymous identifier for the user and an associated public key. In this disclosure, the public key is known only by the login software application in the personal computing device and the login and access software application in the application server. At runtime, this login software application connects to the login and access software application in the application server and transmits the anonymous identifier to it, and the application server records this anonymous identifier in its user registration database through the user registration software application. Once the user registration process is over, the user can run the login software application, request to login to the application server and identify himself through the anonymous identifier, and the login process and the user anonymous identifier are confirmed by the login and access software application running in the application server. This happens without the user having to enter a username or enter a system password, as the username or system password is never created, so there is no username or system password. Similarly, this login method between the personal computing device and the application server does not employ any kind of biometric files, fingerprint files, and facial image files stored in the application server as a password for login authentication, as these elements are too precise in identifying the actual person, and the application server can then easily re-identify its anonymous user.

[0016] To increase security, the login software application running in the personal computing device can include a screen lock device that will be stored locally in the personal computing device and require the user to unlock it to allow the operation of the application to continue. When the login software application has been installed and is running, it requires the user to unlock the screen lock device to ensure that it is being used by the authorized user of the personal computing device. Unlocking the screen lock device can be by means of a regular PIN number, or can be achieved through facial or fingerprint recognition, depending on the security features present in the smartphone or tablet computer. This PIN or digital representation of the user's face or fingerprint will not be sent to the application server as a system password, and the personal computing device and the login software application are accessed by opening this local screen lock device. Failure to open the screen lock device will prevent further use of the login software application, and the login process will not be authorized by it. If the screen lock device is successfully opened, the login software application will take over the login process from the user.

[0017] In another embodiment, it is important to absolutely confirm the identity of the user so that the application server can trust the user registration request from a user whose name identity is unknown to it. This requires the functionality of a separate, independent user identity verification server, which already contains the demographic user data. This server can authenticate the identity of the user by using the demographic data containing at least the user's name and contact details. This would be done only once at the time of user registration and can allow the user to input user preferences, including consent for the application server to use the user's personal data and other legal procedures. In this case, the user would input the name and possibly all the personal identifiers that facilitate their positive identification, such as name, date of birth, gender, address, postal code, and official identification codes such as ID number of a citizen, passport number, etc. Advantageously, this data can be acquired by taking a picture of the user's ID card or driver's license using the personal computing device and using the character recognition software therein to automatically and reliably obtain the data of interest. The login software application in the personal computing device then sends the name and personal identifiers to the user identity verification server, which uses these personal identifiers to search for the personal record of the particular person stored in its database, and upon finding one, reads the person's known cell phone number or email address. Useful identity verification servers include the official government databases of the national identity card or driver's license department and the user databases of the mobile phone operators or banks. Once a match between the received personal identifiers and the personal record in its database is found, the user identity verification server sends a command to the user's known mobile phone number via an SMS message, or to its known email account via an email, or any other kind of electronic message, prompting the user to confirm the response, which knows and is responsible for the ongoing new user registration process. When the positive response is received, the identity of the user is confirmed, the user's personal computing device is authenticated as the user's login and access device, and the identity verification software application in the identity verification server sends a command to the login software application, which is authorized to end its installation in the personal computing device and become operational. In this authentication process, the user login software application needs to contact the identity verification server only once, the user identity verification software application verifies the user's identity, and the login software application is authenticated with the personal computing device as the user's login and access device.

[0018] The authentication process confirms the user's personal computing device as a valid login and access device, and login into the application server will only be performed by the login software application in the personal computing device without any other user intervention. Other processes can be used to positively confirm the identity of the user, such as by sending a confirmation code to a known address of the user that the user will have to enter into the login software application to complete its installation, or even physically appearing in person at a verification center for in-person confirmation. State-provided secure identity verification methods are also useful.

[0019] In one embodiment, the anonymous identifier will be transmitted to the identity verification server in encrypted form, and recorded along with the user's name and personal identifier. In this case, the identity verification server can be used to re-identify the user if needed for legal purposes at a later time.

[0020] It will be noted that when attempting to subsequently log into the application server, in most embodiments the login software application will not transmit the username, personal identifier, or password, or any element that can be used to recover the known identity of the user. This is useful in the handling of valuable but sensitive personal data, where the data needs to be obtained, but doing so without being able to identify the user by their name or receive any personal identifier that would allow the user to be re-identified.

[0021] During the installation process, the cryptography key software program contained in the login software application in the personal computing device generates a pair of cryptographic keys using known methods developed by Rivest, Shamir and Adleman (RSA), or more preferably, known methods of the Elliptic Curve Digital Signature Algorithm (ECDSA), both non-symmetrical cryptographic methods. Each pair of cryptographic keys includes a private key and a public key, and their use is well known in the cryptography community, and they are referred to hereinafter as cryptographic or private and public keys. Conveniently, the public key will be used as an anonymous identifier for the user and will only be used for login purposes to the application server of interest. In fact, several pairs of cryptographic keys can be generated, as many as needed to login to different application servers of interest, so that each public key / anonymous identifier can only be used to login to one application server. Although described as "public", it will be noted that in fact, the public key of the user will only be known to the login and access software application in the application server and the login software application in the personal computing device of the user, and will remain secret from all other parties, including the user. This is an added security feature because the login process can only be initiated in the personal computing device of the user where the login software application is installed. In this way, the public key / anonymous identifier is an effective, secret identifier of the user operating the personal computing device, which generates the cryptographic keys and is used to securely login to the application server of interest, to the exclusion of a conventional user-defined username and password. However, it is not important that the anonymous identifier be the same as the cryptographic public key, and in fact it can be any other sufficiently complex number. In addition to the user, the identity verification server and the application server can also use software to generate their own pair of cryptographic keys to securely communicate with the login software application of the user.

[0022] When not the cryptographic public key, the anonymous identifier can be any randomly generated number similar in length and complexity to the anonymous identifier generated as a public key as described above.

[0023] A necessary feature of the public key / anonymous identifier is that it needs to be as close to unique as possible. The private cryptographic key will be generated by appropriate cryptographic software program included in the login software application, which will calculate the associated public key. At least 10 digits of numbers of the private key (and the associated public key of the same or similar length) are able to assign a single number to every person in the planet, but are too short to ensure that two people will not receive the same number in the random number generation process. A quantity of at least 100 digits will provide a significant increase in the number space and a consequent decrease in the probability that two different people will be assigned the same random number, while 1000 digits or more will give even better security. In the current implementation of the method disclosed herein, a hexadecimal code of 20 bytes representing 40 characters is used, and the hash number can be as long as 2048 bytes. Their complexity can increase in the future as faster computers develop. While the anonymous identifier can be considered as a username or a password, it cannot be considered as neither user-defined nor user-memorable nor user-entered. Its length and lack of meaning will make it almost impossible for the user to easily copy or remember it, even if the user has easy access to it, but it remains hidden in the login software application in the user's personal computing device.

[0024] This login process with random numbers that take the form of public keys or are used as anonymous identifiers allows the application server to consider them as valid and sufficient means to grant the user login access to the application server when sent by the login software application to the login and access software application in the application server.

[0025] The actual length of the anonymous identifier will be determined by the best practices at the time of system implementation, and the continued use of the RSA or ECDSA system or the adoption of newer systems that are more secure against unauthorized use or compromise.

[0026] A method to guarantee that the anonymous identifier is unique and has not been attributed (unlikely but not impossible) includes the step of searching by the identity verification server its user registration database, which includes the anonymous identifier and in which an exact match with the anonymous identifier of the new user received is looked for. If a match is found, the identity verification software application in the identity verification server will issue and transmit a command to the login software application to regenerate a new private key or a new random number, thus producing a new public key / anonymous identifier. Only when the identity verification server verifies that the new anonymous identifier is unique will the identity verification server indicate the end of the installation of the login software application.

[0027] Logging into a computer system and an application server using the method of the present application allows a user to initiate the login and access process by a single click or touch in their login software application, which will trigger the transmission of the anonymous identifier into the application server and access the software application, and it in turn grants login access based only on the received anonymous identifier.

[0028] These operational and design features allow a personal computing device to include a login software application and an anonymous identifier, a login device. Instead of a user logging in, the personal computing device does so under the control of the user. This feature is independent of whether an identity verification server is used to confirm the identity of the user.

[0029] For higher security, a digital signature can be used. A digital signature is a mathematical scheme for verifying the authenticity of digital messages or documents. A valid digital signature gives the recipient a reason to believe that the message was created by a known sender (the user is authenticated), the sender cannot deny having sent the message (the user cannot repudiate it) and the message was not altered in transit (its integrity is verifiable). Known digital signature methods include RSA-based signatures, DSA (Digital Signature Algorithm) signatures and others, and they employ a randomly generated private key and an associated public key. Here, this pair of keys can be the same as the one generated above when generating the anonymous identifier. In one embodiment of the present disclosure, the login software application includes a digital signature software and generates a byte array that will be its digital signature, which is computed using a known mathematical process applied to the content of the message to be signed. Here, the content of the message to be signed is the user's public key / anonymous identifier. Whenever it is necessary to verify that a message originated indeed from the login software application or any other user software application in the user's personal computing device, the digital signature and the message itself are transmitted to an identity verification server or an application server.

[0030] The recipient is able to convert the received digital signature back to the message containing the user's public key, read the digital signature and compare it to the content of the received message itself. If there is a match, the recipient authenticates the user. Similarly, an identity verification server can digitally sign its command to install the login software application to end successfully in the user's personal computing device by digitally signing the message using the identity verification server's private key, where the signed message is the user's public key / anonymous identifier. In this embodiment, only upon receiving this digitally signed message, the installation of the software login application continues and ends successfully in the personal computing device.

[0031] Once the installation of the login software application has successfully ended, the user can use it to contact an application server known to the login software application and initiate the user registration process. The digital signature is useful here, especially the one generated by the identity verification server, so that when transmitted to the application server, it will guarantee that the user exists, that his name identity has been confirmed, that the anonymous identifier is a valid identifier of an unknown but still authenticated individual, and that the verification process was performed by a known identity verification server. With these guarantees, the user registration software application in the application server can record the user in its user registration database under the anonymous identifier of the user.

[0032] It will be recognized that while the login process is anonymous, the anonymous identifier is a unique code for the individual and it resides in the individual's computing device, which can additionally have been authenticated by the identity verification server as being under the control of the individual. The anonymous identifier is difficult to copy, intrude or penetrate, making the disclosed method a very secure login process. It will be noted that the login software application can be included in any other software application for which the provider wishes to use the functionality of the login device and method described in the present disclosure.

[0033] Thus, when the application server receives an incoming login request originating from the login software application, in which the identity of the user has been confirmed and authenticated by the identity verification server, the application server can grant access to the login request based only on the anonymous identifier of the user and provide a level of application functionality and security commensurate with the user being an authenticated but unknown person. This is the case when the application server handles sensitive personal data.

[0034] If the identity of the user has not been confirmed by the identity verification server, the application server can still grant access to the login request based only on the anonymous identifier of the user and this will be appropriate without requiring absolute certainty of the name identity of the user. This is the case when the application server seeks to track the habits, accesses, preferences or choices of the user and the user is willing to share this information.

[0035] As long as the login process described in the present disclosure can be used not only to open a user session in a server computer, but also every time there is an exchange of information between a client and a server, thus constantly verifying the anonymous identifier of the user, the login process can be considered a continuous access verification process, which expression should also contain the meaning of a continuous access verification process.

[0036] In another aspect, a non-transitory computer readable storage medium is described. The computer readable medium includes computer executable instructions that, when executed, configure a processor of a personal computing device to connect to a software distribution service and download and install a login software application into the personal computing device and generate an anonymous identifier, and then run the login software application that transmits the anonymous identifier to an application server. Further instructions also configure a processor of the application server to receive the anonymous identifier and record it in its user registration database. When a user logs into the application server using the login software application by transmitting its anonymous identifier, the processor of the application server is configured to process the received anonymous identifier to attempt to match the anonymous identifier to one of the entries in its user registration database, and finally grant the login software application and the user access to the application server.

[0037] In use, the login and access method of the present disclosure provides a more convenient and practical method to log into a computer, but this method does not reduce security and in fact enhances security with respect to the methods in the prior art. By automating the process and placing it in the user's personal computing device, the user is no longer required to remember or write down several passwords, nor is the user required to identify himself by means of a username. This greatly reduces key errors, incorrect passwords and locked accounts due to too many consecutive incorrect passwords. However, the most important benefit is that the user only needs to select the application server to be connected in his login software application and is successfully logged in with one single action (mouse click, finger tap or any other pointer action). Without a system password, the personal computing device takes over the process of logging in by means of an anonymous identifier. It is noted that the method of the present disclosure is different from current password management systems in which, for each application server, a login file resident in the user's personal computing device contains one or more specific usernames and passwords defined by the user at the time of registration. In this method of the prior art, the personal computing device logs into the application server of interest by sending the username and system password defined by the user and entered by the user.

[0038] Other exemplifying embodiments of the present application will be apparent to one of ordinary skill in the art upon review of the following detailed description in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF DRAWINGS

[0039] Figure 1a is a block diagram of a system architecture for downloading and installing a login software application and verifying the identity of a user in an identity verification server, according to an example embodiment of the present disclosure.

[0040] Figure 1bis a block diagram of a system architecture for securely logging into an application server according to example embodiments of the present disclosure.

[0041] Figure 2 is a block diagram of a personal computing device according to example embodiments of the present disclosure.

[0042] Figure 3 is a block diagram of an identity verification server according to example embodiments of the present disclosure.

[0043] Figure 4 is a block diagram of an application server according to example embodiments of the present disclosure.

[0044] Figure 5a 、 Figure 5b and Figure 5c is a block diagram of a method for digitally signing a message and for verifying a message as valid according to example embodiments of the present disclosure.

[0045] Figure 6 is a flowchart of a method for downloading and installing a login software application in a personal computing device according to example embodiments of the present disclosure.

[0046] Figure 7 is a flowchart of a method for a personal computing device to securely log into an application server according to example embodiments of the present disclosure.

[0047] In the drawings, the numerals refer to equal elements and features throughout the description. DETAILED DESCRIPTION

[0048] Figure 1a is a block diagram of the computer architecture required to download and install the login software application of the present disclosure. This is the first step necessary to successfully install the login software application in a user's personal computing device. The login software application 100 resides in a software distribution service 105 in the Internet. A user operating a personal computing device 110 such as a smartphone, tablet computer, laptop computer, or personal computer downloads the desired login software application 100 from the software distribution service 105. The user installs the login software application 100 in his personal computing device 110 according to the method described in Figure 6 .

[0049] The personal computing device 110 connects to an identity verification server 130 via a communication network 120. This server 130 searches its user database for a matching user and, when a matching user is found, confirms the identity of the user and allows the installation of the login software application 100 to continue according to the method described in steps 600 to 630 in Figure 6 .

[0050] Figure 1bis a block diagram of an example of the computer architecture required to create a new user in the present disclosure. This is the second step, where, after the login software application 100 has been installed, the user's personal computing device sends a request to register the user in the application server of interest. The user runs the login software application 100 in their personal computing device 110 to connect to the application server 140 via the communication network 120 according to the methods described in Figure 7 The methods described in steps 700 to 730 connect to the application server 140 via the communication network 120. The login software application 100 transmits the user's anonymous identifier and identity confirmation data, if issued by the identity verification server when using the optional authentication process. The application server 140 receives the user's anonymous identifier and identity confirmation data, and, upon successful verification of the data, records the user as a valid new user in its user registration database.

[0051] Figure 1b is a block diagram of an example of the computer architecture required to initiate a new login process for a user that is already registered in the user registration database 480 in the application server 140 in the present disclosure. This is the third second step, where, after a new user has been successfully registered, the login software application 100 in the user's personal computing device 110 sends a request to initiate a login process to the application server 140 of interest. The user runs the login software application 100 in their personal computing device 110 to connect to the application server 140 via the communication network 120 according to the methods described in Figure 7 The methods described in steps 700 to 730 connect to the application server 140 via the communication network 120. The login software application 100 transmits the user's anonymous identifier and identity confirmation data, if issued by the identity verification server when using the optional authentication process. The application server 140 receives the user's anonymous identifier and identity confirmation data, and, upon successful verification of the data, records the user as a valid new user in its user registration database. Figure 7 Steps 760 to 790 allow the user to login and initiate a user session at the application server 140 upon successful verification thereof according to the methods described in

[0052] Figure 1a and 1b An example of the minimum computer architecture required for the anonymous login process of the present application is described. The identity verification server 130, if used, is only used once to verify the identity of the user and authenticate their personal computing device 110, which will be used to connect and login to the application server 140.

[0053] In Figure 2 An example personal computing device 110 is shown in block diagram form in

[0054] The communication subsystem 210 is used to connect the personal computing device 110 to other computers, such as the software distribution service 105, the identity verification server 130, and the application server 140, to manage the data exchanges described in this disclosure, for example involving the download and installation of the login software application 100, user identity verification, user registration, anonymous identifier delivery, login flow initiation and termination.

[0055] The main processor 240 is associated with at least one memory 250 that can store data and processor-executable instructions 260 that, when executed, configure the processor 240 to download the login software application 100 and use the cryptographic software program 280 included in the login software application 100 to generate a private key and an associated public key / anonymous identifier, following one of the RSA or ECDSA methods or equivalent.

[0056] In Figure 3 An example identity verification server 130 is shown in block diagram form. In this example, the identity verification server 130 has a main processor 340 connected to a communication subsystem 310. It will be understood that the identity verification server 130 has many other components that are not individually identified.

[0057] The communication subsystem 310 is used to connect the identity verification server 130 to other computers, for example the personal computing device 110, to manage the data exchanges described in this disclosure, for example the data exchanges involved in user authentication and personal computing device 110 certification.

[0058] The main processor 340 is associated with at least one memory 350 that can store data and processor-executable instructions 360 that, when executed, configure the processor 340 to first receive a request for identity verification from the login software application 100 in the user's personal computing device 110, then perform the steps of the identity verification software application 370, and finally and if the verification is successful, issue a command 380 to the login software application 100 to continue and successfully end the installation.

[0059] In Figure 4 An example application server 140 is shown in block diagram form. In this example, the application server 140 is provided with a main processor 440 connected to a communication subsystem 410. It will be understood that the application server 140 has many other components that are not individually identified.

[0060] The communication subsystem 410 is used to connect the application server 140 to other computers, for example the personal computing device 100, to manage the data exchanges described in this disclosure, for example the data exchanges involving the connection to the personal computing device 110, the receipt of transmitted information from the login software application 100 identified with an anonymous identifier.

[0061] The main processor 440 is associated with at least one memory 450 that can store data and processor-executable instructions 460 that, when executed, configure the processor 440 to first receive a request in the form of an anonymous identifier from the login software application 100 in the personal computing device 110, which is handled by the user registration software application 470 in the first connection, and by the login and access software application 475 in all connections. The first connection causes the user registration software application 470 to check whether the anonymous identifier already exists, and if not, create a new entry for it in the user registration database 480. The all connections cause the login and access software application 475 to verify the validity of the anonymous identifier by matching the received anonymous identifier with the user registration database 480 containing the anonymous identifiers. If the anonymous identifier is successfully matched, the processor 440 is configured in the application server 140 to grant login access to the login software application 100 and open a user session 490.

[0062] In Figure 5a , Figure 5b and Figure 5c , an example of digitally signing and verifying a message is given in the form of a block diagram of the method of the present disclosure. The message to be signed at this point is the anonymous identifier.

[0063] In Figure 5a , the login software application 100 in the personal computing device 110 uses its private key 500 to digitally sign the anonymous identifier message 510 including the anonymous identifier, producing a digitally signed anonymous identifier message 520 using a known method such as the digital signature algorithm.

[0064] In Figure 5b , the login software application 100 in the personal computing device 110 transmits the digitally signed anonymous identifier message 520 and the anonymous identifier message 510 to the application server 140 using the communication network 120.

[0065] In Figure 5c , the digital signature software included in the login and access software application 475 in the application server 140 receives the digitally signed anonymous identifier message 520 and the anonymous identifier message 510, processes the digitally signed anonymous identifier message 520 using a known method such as the digital signature algorithm and compares the result of the processing with the message containing the anonymous identifier message 510. If the two expressions are equal, the application server 140 ensures that the login or access request has originated with the user identified by the anonymous identifier.

[0066] In Figure 6 , an example of downloading the login software application 100, verifying the identity of the user and successfully installing it in the personal computing device 110 is given in the form of a flowchart of the method of the present disclosure.

[0067] In step 600, the user operates a personal computing device 110, such as a smartphone or tablet, and directs it to a software distribution service 105, such as an app store, Google Play, or a software distribution web server, and downloads the desired login software application 100. If a personal computer is used, the user accesses the software distribution service 105 and downloads the required login software application 100. The user initiates installation of the login software application 100 in the personal computing device 110.

[0068] During installation, the login software application 100 also requests the user to enter a code for the screen lock device, such as a four or six digit number or alphanumeric PIN, or longer, or a picture of a face or fingerprint, or any other means using the biometric identification functionality present in the personal computing device 110. This screen lock code and device is retained in the personal computing device 110, and its numeric representation will not be transmitted to external parties, such as the identity verification server 130 or the application server 140. This is a locally stored code. This embodiment will be particularly useful in applications involving the processing of sensitive personal data, where it is important to protect the personal computing device 110 from unauthorized access and unauthorized use as a login device.

[0069] In other embodiments, particularly in corporate systems, the user needs to be known, and in this case, the installation of the login software application 100 will include the user entering a name, a username, personal identifiers, preferences, and other information of interest that can be sent at the time of user registration, enabling the application server 140 to identify the user as a valid member of the organization. Unlike current login systems, the user does not generate a password or store a password in the corporate application server 140. In all embodiments, login will be achieved by the user at least opening the screen lock device on the login software application 100, and selecting and clicking or touching the login button of interest of the application server 140.

[0070] Step 610 describes embodiments where absolute confirmation of the user's identity and authentication of their login to the software application 100 and aspects of the personal computing device 110 is required. If not, the operation continues at step 635. When required, the login software application 100 connects to the identity verification server 130 containing a large amount of personal data, so large that it is likely that the current new user is already known and recorded in the database of the identity verification server 130. Upon receiving the user's name and personal identifier, the identity verification software application 370 in the identity verification server 130 uses the user's identity details to locate the same user in its own database. Once found, the identity verification software application 370 reads in the found user record contact details, such as the user's cell phone number, email address or any other electronic address, and sends a text message to that cell phone or an email message to the user's email account, requesting the holder to confirm their name and whether they are the initiator of the new user registration process. The confirmation can be simple, such as just clicking or touching a link displayed on the screen of the personal computing device 110. Clicking that link sends information back to the identity verification server 130 that the user has confirmed the received information on that known smart phone, tablet computer or computer personal computing device 110. The confirmation can be made more secure by including a digital code in the text message or email that then requests the user to manually enter into the login software application 100, a very secure process used by banking and state agencies. After the user enters their response and the login software application 100 sends that response, the login software application 100 waits for a response from the identity verification server 130.

[0071] In step 620, the identity verification software application 370 processes the response received or not received from the user. The identity verification software application 370 can make a decision based on the user input (positive or negative) or if there is no response after a timer included in the identity verification software application 370 running in the identity verification server 130 counts a certain amount of time, such as 60 seconds, then it judges as negative.

[0072] If the user response is negative or if there is no response, in step 625, the identity verification software application 370 sends a command that the login software application 100 in the user's personal computing device 110 has been waiting for, which in this case stops the installation of the login software application 100 in the user's personal computing device 110.

[0073] If the user response is positive and received within the preset time, in step 630 the identity verification software application 370 sends to the login software application 100 the user identity confirmation data (timestamp, confirmation number, identity verification server 130 name and address) and a command to continue the installation. Both are recorded by the login software application 100.

[0074] In step 635, the login software application 100 uses the encryption software program 280 to generate the user's encryption private key and public key / anonymous identifier.

[0075] In step 640, the login software application 100 connects to the login and access software application 475 in the application server 140 and requests a new user registration procedure for the user identified by its anonymous identifier. After having sent the command, the login software application 100 waits for the response of the application server 140.

[0076] In step 650, the login and access software application 475 in the application server 140 tests whether the request comes from a genuine copy of the login software application 100 and a valid installation, by known cryptographic methods.

[0077] If the test is not successful, in step 655 the login and access software application 475 in the application server 140 denies the request for a new user registration procedure and sends to the login software application 100 a command to terminate its operation. If it is successful, in step 660 the login and access software application 475 sends to the login software application 100 a command to continue its operation and to the application server 140 the user's encryption public key / anonymous identifier and the user identity confirmation data, if any.

[0078] In step 670, the login and access software application 475 in the application server 140 receives from the login software application 100 the transmitted cryptographic public key / anonymous identifier and the user identity confirmation data, if any, and causes the user registration software application 470 to create a new user in the user registration database 480.

[0079] In step 680, the successful registration of the new user by the application server 140 results in the command sent by the login and access software application 475 being transmitted to the login software application 100, signalling to it that it can record the installation of the login software application 100 as successfully completed. The login software application 100 records the name of the application server 140 as the computer system that has confirmed the user for the login operation and authenticates the software login application 100 with its personal computing device 110 as the login device. Only the login software application 100 that has been successfully installed to this point will be recognised by the login and access software application 475 in the application server 140 of interest that receives the incoming login request; this fails, the application server 140 will not allow the login attempt.

[0080] In Figure 7 the flowchart of the method of the present disclosure is given an example of logging into an application server 140 after successful installation of the login software application 100 in the user's personal computing device 110 without a username or password and by means of an anonymous identifier.

[0081] In step 700, the user runs their login software application 100 in their personal computing device 110 and is prompted to unlock the screen-locked device previously defined in step 600.

[0082] In step 710, the login software application 100 in the personal computing device 110 tests the unlock input to the screen-locked device and determines whether it is valid or invalid. A valid input will be a PIN entered that matches the PIN defined at the time of installation of the login software application 100, or the face or fingerprint of the user recognised by the biometric verification function of the personal computing device 110.

[0083] If the unlock input to the screen-locked device is deemed invalid in step 715, the login software application 100 denies continued operation to the user. If deemed valid in step 720, the user is authorised to continue operation and, in the presence of more than one application that allows the user to log in, is allowed to select the application server 140 for login in the login software application 100.

[0084] In step 730, a connection is established to the selected application server 140 and a login procedure is requested.

[0085] In step 740, the login and access software application 475 in the application server 140 tests whether the request is from a genuine copy and valid installation of the login software application 100 and this is achieved by known cryptographic methods. To verify that the copy of the login software application 100 is legitimate, the login and access software application 475 can also query the commands sent to the login software application 100 in steps 660 and 670 and confirm that they exist and are identical to those originally issued.

[0086] If the test is unsuccessful, then in step 745, the login and access software application 475 in the application server 140 denies login access and sends a command to the login software application 100 to terminate its operation. The identity details and other identifying details of the login software application 100 and the personal computing device 110 can be logged in a security log file by the application server 140.

[0087] If the test is successful, then in step 750, the login and access software application 475 in the application server 140 authorizes the user login process to continue and sends a command to the login software application 100 to transmit the user's public key / anonymous identifier.

[0088] In step 760, the login and access software application 475 in the application server 140 receives the public key / anonymous identifier and searches for a matching anonymous identifier in its user registration database 480. In step 770, the login and access software application 475 in the application server 140 tests whether a match is found.

[0089] If no match is found in step 775, then the login and access software application 475 denies login access to the user's login software application 100. If a match is found in step 780, then the login and access software application 475 grants login access to the user's login software application 100. In step 790, the user session is started at the application server 140 using these or other software applications resident in the personal computing device 110 or the application server 140. The user session is ended in step 795 when the user issues a logout command in the login software application 100 or the application server 140, or if a preset timeout device in the login software application 100 or the login and access software application 475 is triggered after a given user inactivity period.

[0090] The present invention allows a user to securely login to an application server by a single click or touch, wherein in the preferred embodiment of the present invention, no user name or no user memorable user name is disclosed, and no identity details and no password exist, and the user is positively identified and authenticated only by the user's anonymous identifier.

[0091] It will be appreciated that, in the preceding description of exemplary embodiments of the application, various features are sometimes grouped together in a single embodiment, figure, or description of related features. This method of disclosure, however, is not to be interpreted as reflecting an intention that the claimed application requires more features than are explicitly recited in each claim. Rather, inventive aspects lie in less than all features of a single foregoing disclosed embodiment. Each embodiment describes a different set of related features and the application includes each individual embodiment, but not to the exclusively grouped sets of features.

[0092] While the application has been particularly shown and described with reference to embodiments thereof, it will be understood by those skilled in the art that various other changes in the form and details can be made therein without departing from the spirit and scope of the application.

Claims

1. A method of performing a secure user login process in an application server, comprising: a. a processor 240 of a personal computing device 110 of a user downloading and installing a login software application 100 into the personal computing device 110 and generating an anonymous identifier, b. the processor 240 of the personal computing device 110 running the login software application 100 of the personal computing device 110, connecting to an application server 140 of interest and sending the anonymous identifier of the user to the application server 140, c. a processor 440 of the application server 140 receiving the anonymous identifier of the user and recording the anonymous identifier of the user in a user registration database 480 of the application server 140 by means of a user registration software application 470 of the application server 140, d. the processor 440 of the application server 140 receiving a login or access request from the personal computing device 110, the login or access request including the anonymous identifier of the user, verifying that the login or access request is a known anonymous identifier and granting the user access to the application server 140 by means of a login and access software application 475 of the application server 140, wherein, during the login process, the processor 240 of the personal computing device 110 does not disclose its identity in the form of a user-defined username, does not use a system password and performs the login process to obtain access to the application server 140 by means of the login software application 100, the user is identified by the anonymous identifier and does not require manual or biometric login input from the user.

2. The method of claim 1, wherein, The installation process of the login software application 100 includes a user identity verification step, the user identity verification step comprising: a. the processor 240 of the personal computing device 110 accepting user operation to input a name and a personal identifier, b. the processor 240 of the personal computing device 110 sending the name and the personal identifier to an identity verification server 130, c. a processor 340 of the identity verification server 130 matching the received data with stored names and personal identifiers by means of an identity verification software application 370 of the identity verification server 130, d. upon obtaining a match, the processor 340 of the identity verification server 130 reading the known contact number or electronic address of the user of the personal computing device 110 of the user from the data of the matching user by means of the identity verification software application 370 of the identity verification server 130, e. the processor 340 of the identity verification server 130 sending a command to the known contact number or electronic address of the personal computing device 110 of the matching user and prompting the user to confirm the response by means of the identity verification software application 370 of the identity verification server 130. f. the processor 240 of the personal computing device 110 responds to the confirmation prompt in its personal computing device 110, which transmits the response to the identity verification server 130, g. upon receiving the user confirmation, the processor 340 of the identity verification server 130 sends a command to the personal computing device 110 that the user identity has been confirmed and the installation can be ended, wherein the identity verification server 130 only needs to be contacted once by the user's login software application 100, and wherein the identity verification software application 370 verifies the identity of the user and authenticates the login software application 100 as the user's login and access device together with the personal computing device 110.

3. The method of claim 1, wherein, The anonymous identifier is a public key derived from a randomly generated private key in an asymmetric system, the public key having at least 10 characters.

4. The method of claim 1, wherein, The anonymous identifier is an arbitrarily randomly generated number of at least 10 characters.

5. The method of claim 1, wherein, The login or access request is a single user action.

6. The method of claim 1, wherein, The incoming request for login originating from the login software application 100 received by the application server 140 is considered valid and sufficient to grant the user login access to the application server 140.

7. The method of claim 6, wherein, The incoming request for login received by the application server 140 is authenticated by the identity verification server 130 as being associated with a valid anonymous identifier.

8. A login device comprising a personal computing device 110, a login software application 100 and an anonymous identifier, wherein, The login device transmits the anonymous identifier to the login and access software application 475 in the application server 140 and is identified by the login and access software application 475 as an authorized device to initiate the login process and be granted access based solely on the login and access software application 475 matching the received anonymous identifier to one of several stored anonymous identifiers recorded in the user registration database 480 of the application server 140.

9. At least one non-transitory machine readable storage medium having stored thereon instructions that, when executed by a processor 240 in a personal computing device 110 and a processor 440 in an application server 140, cause the respective processors to: a. download and install a login software application 100 into a user's personal computing device 110 and generate an anonymous identifier, b. run the login software application 100 in the personal computing device 110, connect to an application server 140 of interest and send the user's anonymous identifier to its user registration software application 470, c. receive and record the user's anonymous identifier in the user registration database 480 of the application server 140 by means of the user registration software application 470, d. receive a login or access request in the application server 140 from the login software application 100 in the personal computing device 110, the login or access request including the user's anonymous identifier, verify by means of the login and access software application 475 that the request is a known anonymous identifier and grant the login software application 100 and the user access to the application server 140, wherein, During the login process, the user does not disclose his identity in the form of a user-defined username, does not use a system password and performs the login process to gain access to the application server 140 by means of the login software application 100, the user is identified by the anonymous identifier and does not require manual or biometric login input from the user.

10. At least another non-transitory machine-readable storage medium having stored thereon instructions that, when executed by a processor 240 in a personal computing device 110 and a processor 340 in an identity verification server 130, cause the respective processors to: a. accept user operation to enter a name and a personal identifier in a login software application 100 of a personal computing device 110, b. transmit the name and personal identifier from the login software application 100 to an identity verification server 130, c. in the identity verification server 130, match the received data with stored names and personal identifiers by means of an identity verification software application 370, d. upon obtaining a match, read the user's known contact number or electronic address of the user's personal computing device 110 from the matching user information by means of the identity verification software application 370, e. send a command from the identity verification software application 370 in the identity verification server 130 to the user's known contact number or electronic address of the matching user's personal computing device 110 and prompt the user to confirm a response, f. when the user responds to the confirmation prompt in their login software application 100, transmit the response from the personal computing device 110 to the identity verification software application 370 in the identity verification server 130, g. upon receiving the user confirmation response, transmit a command from the identity verification software application 370 to the user's login software application 100 that the user's identity has been verified and that the installation of the login software application 100 can be completed in the personal computing device 110, wherein the identity verification server 130 is contacted only once by the user's login software application 100 and wherein the identity verification software application 370 verifies the identity of the user and authenticates the login software application 100 together with the personal computing device 110 as the user's login device.

Citation Information

Patent Citations

  • Password-less security and protection of online digital assets

    US8954758B2

  • Password-less authentication system and method

    US9264423B2

  • Universal anonymous cross-site authentication

    US20160105290A1