Passkey Integration Techniques for Identity Management

The identity management platform integrates passkey authentication by generating and verifying public and private keys, addressing inefficiencies and security issues in traditional password management by enabling flexible and secure login options.

JP2025528723APending Publication Date: 2025-09-02OKTA INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025503352
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-23
Filing Date
2023-08-09
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

Users face the burden of remembering multiple usernames and passwords for different applications, leading to inefficiency and security risks, while traditional password management systems lack flexibility in integrating passkey authentication options.

Method used

An identity management platform enables passkey authentication through user interface configurations, allowing users to select passkey login options, generates and stores public and private keys, and verifies identities using biometric methods, providing a dynamic and secure login process.

Benefits of technology

Enhances security and efficiency by allowing users to log in with passkeys, reducing manual interactions and minimizing exposure to password-related risks, while offering flexibility in enabling or disabling passkey authentication for clients.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025528723000001_ABST
    Figure 2025528723000001_ABST
Patent Text Reader

Abstract

Methods, systems, devices, and apparatuses for passkey authentication in an identity management platform are described. According to the described techniques, an administrator of the identity management platform can enable passkey authentication for a client of the identity management platform. Once passkey authentication is enabled, the identity management platform can display a passkey login option to a user associated with the client of the identity management platform. If a user associated with the client of the identity management platform selects the passkey login option, a device associated with the user can generate a passkey including a private key and a public key. The device can store the private key and transmit an indication of the public key to the identity management platform. The identity management platform can use the public key to verify the user's identity on subsequent login attempts.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This patent application claims the benefit of U.S. patent application Ser. No. 17 / 821,748 by Bertocci et al., filed Aug. 23, 2022, and entitled "PASSKEY INTEGRATION TECHNIQUES FOR IDENTITY MANAGEMENT," which is assigned to the assignee of this patent.

[0002] Technical Field

[0002] The present disclosure relates generally to user authentication, and more particularly to passkey integration techniques for identity management. [Background technology]

[0003] background

[0003] After navigating to a software application's login page, a user may be prompted to enter identifying information (e.g., a username and password). Users who have accounts for different services, applications, and websites may need to remember an excessive number of usernames, passwords, account numbers, etc. Logging into each application can impose a significant burden on the user, as each login attempt often requires the user to manually enter a username and corresponding password.

[0004] In some cases, an application may use a software platform to manage the login process. The software platform may store or maintain a record of the credentials and other information used to access the software application. However, in some cases, traditional information management techniques may be improved upon. Summary of the Invention [Means for solving the problem]

[0005] overview

[0005] The described techniques relate to improved methods, systems, devices, and apparatus for enabling passkey authentication in an identity management platform. According to one or more aspects of the present disclosure, an identity management platform may receive an instruction to enable passkey authentication for a client of the identity management platform. The instruction may be received from an administrator or developer of the identity management platform via a first user interface configured for the identity management platform. Once passkey authentication is enabled, the identity management platform may display a passkey login option to a user associated with the client of the identity management platform. The passkey login option may be displayed via a second user interface configured for the client of the identity management platform. When the user selects the passkey login option, the identity management platform may obtain the user's public key and use the public key to verify the user's identity in subsequent login attempts.

[0006] A method for passkey authentication in an identity management platform is described. The method may include receiving, from an administrator of the identity management platform via a first user interface configured for the identity management platform, an instruction to enable passkey authentication for a client of the identity management platform. The method may further include transmitting, for display in a second user interface configured for the client of the identity management platform and based on enabling passkey authentication, an option to use passkey authentication for a login procedure. The method may further include receiving, from a user associated with the client via the second user interface, a selection of the option to use passkey authentication for the login procedure. The method may further include obtaining a public key of the user in response to the user selecting the option to use passkey authentication for the login procedure. The method may further include performing the login procedure using at least the public key to authenticate the identity of the user.

[0007] An apparatus for passkey authentication in an identity management platform is described. The apparatus may include a processor, a memory coupled to the processor, and instructions stored in the memory. The instructions may be executable by the processor to cause the apparatus to receive, via a first user interface configured for the identity management platform, instructions to enable passkey authentication for a client of the identity management platform from an administrator of the identity management platform. The instructions may be further executable by the processor to cause the apparatus to display, on a second user interface configured for the client of the identity management platform, and to transmit, based on enabling passkey authentication, an option to use passkey authentication for a login procedure. The instructions may be further executable by the processor to receive, via the second user interface, from a user associated with the client, a selection of the option to use passkey authentication for the login procedure, and to cause the apparatus to obtain a public key for the user in response to the user selecting the option to use passkey authentication for the login procedure. The instructions may be further executable by the processor to cause the apparatus to perform the login procedure using at least the public key to authenticate the identity of the user.

[0008] Another apparatus for passkey authentication in an identity management platform is described. The apparatus may include means for receiving, via a first user interface configured for the identity management platform, instructions to enable passkey authentication for a client of the identity management platform from an administrator of the identity management platform. The apparatus may further include means for transmitting, for display in a second user interface configured for the client of the identity management platform and based on enabling passkey authentication, an option to use passkey authentication for a login procedure. The apparatus may further include means for receiving, via the second user interface, from a user associated with the client, a selection of the option to use passkey authentication for the login procedure. The apparatus may further include means for obtaining the user's public key in response to the user selecting the option to use passkey authentication for the login procedure. The apparatus may further include means for performing the login procedure using at least the public key to authenticate the user's identity.

[0009] A non-transitory computer-readable medium storing code for passkey authentication in an identity management platform is described. The code may include instructions executable by a processor to receive instructions to enable passkey authentication for a client of the identity management platform from an administrator of the identity management platform via a first user interface configured for the identity management platform. The instructions may be further executable by the processor to display in a second user interface configured for the client of the identity management platform and to transmit, based on enabling passkey authentication, an option to use passkey authentication for a login procedure. The instructions may be further executable by the processor to receive, from a user associated with the client via the second user interface, a selection of the option to use passkey authentication for the login procedure. The instructions may be further executable by the processor to obtain the user's public key in response to the user selecting the option to use passkey authentication for the login procedure. The instructions may be further executable by the processor to perform the login procedure using at least the public key to authenticate the user's identity.

[0010]

[0010] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, performing a login procedure may include an operation, function, means, or instruction for transmitting an indication of a cryptographic challenge to a device associated with the user.

[0011]

[0011] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, performing a login procedure may include an operation, function, means, or instruction for receiving an indication of a cryptographic response from the device in response to a cryptographic challenge, the cryptographic response including a digital signature.

[0012]

[0012] In some examples of the methods, devices, and non-transitory computer-readable media described herein, performing a login procedure may include operations, functions, means, or instructions for authenticating a user based on verifying a digital signature in a cryptographic response using a public key.

[0013]

[0013] Some examples of methods, devices, and non-transitory computer-readable media described herein may further include operations, functions, means, or instructions for determining that the device has access to a private key associated with the user based on a digital signature in the cryptographic response, and authenticating the user is based on determining that the device has access to the private key.

[0014]

[0014] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, a private key may be unlocked locally on the device after a user successfully performs a facial recognition procedure, a voice recognition procedure, a fingerprint recognition procedure, a personal identification number verification procedure, a security key verification procedure, or a combination thereof.

[0015]

[0015] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, a secret key may be generated and stored on the device after a user selects the option to use passkey authentication for the login procedure.

[0016]

[0016] Some examples of methods, devices, and non-transitory computer-readable media described herein may further include an operation, function, means, or instruction for receiving an indication that a user has registered a public key with a client of the identity management platform, and obtaining the user's public key is based on the indication.

[0017]

[0017] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, receiving a selection of the option to use passkey authentication may include an operation, function, means, or instruction for receiving the selection via a web browser running on a device associated with the user, and the user's public key is stored in an identity management platform in association with the user, the web browser, the device, the device's operating system, or a combination thereof.

[0018]

[0018] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may further include operations, functions, means, or instructions for receiving an indication of capability information associated with a device via a web browser running on a device associated with a user.

[0019]

[0019] Some examples of methods, apparatus, and non-transitory computer-readable media described herein may further include operations, functions, means, or instructions for determining, based on the capability information, that the device supports passkey authentication, and displaying an option for using passkey authentication for the login procedure is based on determining that the device supports passkey authentication.

[0020]

[0020] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, the capability information may be received via a web browser running on the user's device.

[0021]

[0021] Some examples of methods, apparatus, and non-transitory computer-readable media described herein may further include operations, functions, means, or instructions for storing a public key in the identity management platform in association with a user identifier, a user password, an account number associated with the user, or a combination thereof, wherein the public key is obtained from the identity management platform after the user initiates a login procedure.

[0022]

[0022] In some examples of the methods, devices, and non-transitory computer-readable media described herein, receiving instructions to enable passkey authentication may include an operation, function, means, or instruction for enabling passkey authentication for a client of the identity management platform in response to an administrator of the identity management platform selecting one or more user interface elements displayed within the first user interface.

[0023]

[0023] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, the one or more user interface elements include a checkbox, a toggle switch, a drop-down list, a button, or a combination thereof.

[0024]

[0024] Some examples of the methods, devices, and non-transitory computer-readable media described herein may further include operations, functions, means, or instructions for configuring a passkey for a user based on executing one or more application programming interface (API) calls to a web authentication service, the passkey including a public key and a corresponding private key associated with the user.

[0025]

[0025] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, displaying an option for using passkey authentication may include an operation, function, means, or instruction for transmitting, for display in a second user interface, a first option for using passkey authentication for the login procedure and a second option for using other credentials for the login procedure, wherein the first option is selected by the user. [Brief explanation of the drawings]

[0026] [Figure 1] 1 illustrates an example system that supports a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure. [Figure 2]1 illustrates an example system that supports a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure. [Figure 3]

[0027] 1 illustrates an example process flow supporting a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure. [Figure 4]

[0027] An example process flow for supporting a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure is shown. [Figure 5]

[0028] 1 illustrates a block diagram of a device that supports a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure. [Figure 6]

[0029] 1 illustrates a block diagram of an authentication manager that supports a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure. [Figure 7]

[0030] 1 illustrates a diagram of a system including an apparatus that supports a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure. [Figure 8]

[0031] 1 illustrates a flowchart illustrating a method for supporting a passkey integration technique for identity management, in accordance with one or more aspects of the present disclosure. [Figure 9] 1 illustrates a flowchart illustrating a method for supporting a passkey integration technique for identity management, according to one or more aspects of the present disclosure. [Figure 10] 1 illustrates a flowchart illustrating a method for supporting a passkey integration technique for identity management, according to one or more aspects of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0027] Detailed Description

[0032] Some software platforms manage identity information associated with different users. Identity information may include personal information (e.g., name, social security number, driver's license number), contact information (e.g., home address, phone number, email address), payment information (e.g., credit card number, banking information), account information (e.g., credentials), or any combination thereof. As described herein, credentials may refer to a username or password, among other examples. In some examples, the software platform may process requests (e.g., login requests, network protocol requests) from users associated with a client of the software platform. For example, the software platform may authenticate users and authorize access to resources associated with the client. In some examples, the software platform may authenticate and authorize users based on one or more credentials (e.g., a username and password combination) provided by the user.

[0028]

[0033] Users may have login credentials (e.g., usernames and passwords) for numerous applications, websites, online services, etc. Keeping track of these login credentials while attempting to make each password unique can be tedious and inefficient. Using the same login credentials across multiple services can pose higher risks and greater potential exposure (in the event of a data breach). Furthermore, user-generated passwords are more predictable and less secure than auto-generated passwords. Passkeys are a more secure and user-friendly alternative to traditional passwords. Passkey authentication methods use public key cryptography techniques to verify identity without a user-entered password. However, in some cases, the passkey integration mechanism may be static, and users may not be able to choose between passkey authentication and other login mechanisms.

[0029]

[0034] Aspects of the present disclosure support techniques for enabling and integrating dynamic passkey authentication for clients of an identity management platform. According to the described techniques, an administrator or developer of an identity management platform (also equivalently referred to herein as a software platform) can enable passkey authentication for a client of the identity management platform. Once passkey authentication is enabled, the identity management platform can display a passkey login option to a user associated with the identity management platform client. For example, when a user navigates to a login page associated with the identity management platform client, the user may be presented with a first option to log in using passkey authentication and a second option to log in using a username, password, account number, etc. If the user selects to use passkey authentication (by clicking or otherwise interacting with one or more user interface elements), the identity management platform can configure a passkey for the user and utilize the passkey to verify the user's identity on subsequent login attempts.

[0030]

[0035] In some examples, the identity management platform can configure a passkey for a user by calling a web authentication application programming interface (API). For example, a web browser running on a device associated with the user can make one or more API calls to the web authentication API to configure the passkey (after the user selects the passkey login option). As described herein, the passkey can include a public key and a private key. The private key can be stored (and unlocked locally) on the device associated with the user, while the public key can be communicated (via the web browser) to the identity management platform. The identity management platform can store the public key in association with the user's other credentials (password, email, username) and can use the public key to verify subsequent login attempts from the user.

[0031]

[0036] Aspects of the present disclosure can be implemented to achieve one or more of the following advantages: The described techniques can enable an identity management platform to provide passkey authentication services to clients and end users, which can improve the security and efficiency of login procedures between clients and end users. For example, if passkey authentication is enabled for a client of the identity management platform, a user associated with the client may be presented (upon navigating to a login page associated with the client) with the option to log in using a passkey or other appropriate credentials. If the user selects this option, a passkey may be automatically generated and stored on a device associated with the user. On subsequent login attempts, the user can unlock this passkey through a biometric authentication process (fingerprint recognition, facial recognition, voice recognition) or other local authentication mechanism. Once the passkey is unlocked (and used to complete the login process), the user can access client resources without manually entering a username and password, which can result in greater efficiency and greater user satisfaction, among other benefits.

[0032]

[0037] Aspects of the present disclosure are first described in the context of system and process flows. Aspects of the present disclosure are further illustrated by and described with reference to equipment diagrams, system diagrams, and flowcharts relating to passkey integration techniques for identity management.

[0033]

[0038] FIG. 1 illustrates an example of a computing environment 100 supporting a passkey integration technique for identity management according to various aspects of the present disclosure. The computing environment 100 includes a client device 105, an application 110, an authentication platform 115, and data storage 120. The authentication platform 115 may be an example of a public or private cloud network. The client device 105 can access the authentication platform 115 over a network connection 135. The network may implement Transmission Control Protocol and Internet Protocol (TCP / IP), such as the Internet, or may implement other network protocols. The client device 105 may be an example of a user device, such as a server (e.g., client device 105-a), a smartphone (e.g., client device 105-b), or a laptop (e.g., client device 105-c). In other examples, the client device 105 may be a desktop computer, a tablet, or another computing device or system capable of generating, analyzing, transmitting, or receiving communications. In some examples, the client device 105 may be operated by a user who is part of a company, a business, a nonprofit organization, a startup, or any other type of organization.

[0034]

[0039] A client device 105 can interact with multiple applications 110 through one or more interactions 130. The interactions 130 can include digital communications, API calls, Hypertext Transfer Protocol (HTTP) messages, or any other interaction between the client device 105 and the applications 110. Data can be associated with the interactions 130. The client device 105 can access the authentication platform 115 to store, manage, and process data related to the interactions 130. In some examples, the client device 105 may have an associated security or permission level. Based on the associated security or permission level, the client device 105 may be able to access some applications, data, and database information within the authentication platform 115 and not others.

[0035]

[0040] The application 110 may interact with the client device 105 via email, web, text message, or any other suitable form of interaction. The interaction 130 may be a business-to-business (B2B) interaction or a business-to-consumer (B2C) interaction. The application 110 may also be referred to as a customer, client, website, or some other suitable terminology. In some examples, the application 110 may be an example of a server, a node, a computing cluster, or any other type of computing system, component, or environment. In some examples, the application 110 may be operated by a user or a group of users.

[0036]

[0041] The authentication platform 115 can provide cloud-based services to the client devices 105, the applications 110, or both. In some cases, the authentication platform 115 can provide services to multiple client devices 105 with a single instance of software. However, other types of systems can be implemented, including, but not limited to, client-server systems, mobile device systems, and mobile network systems. The authentication platform 115 can receive data related to the interaction 130 from the client devices 105 over a network connection 135 and can store and analyze the data. In some examples, the authentication platform 115 can receive data directly from the interaction 130 between the application 110 and the client device 105. In some examples, the client device 105 can develop an application to run on the authentication platform 115. The authentication platform 115 can be implemented using a remote server. In some examples, the remote server can be an example of data storage 120.

[0037]

[0042] Data storage 120 may include multiple servers. Multiple servers may be used for data storage, management, and processing. Data storage 120 may receive data from authentication platform 115 via connection 140, directly from client device 105, or from interactions 130 between application 110 and client device 105. Data storage 120 may utilize multiple redundancies for security purposes. In some examples, data stored in data storage 120 may be backed up with copies of the data in multiple locations. Subsystem 125 may include client device 105, authentication platform 115, and data storage 120. In some examples, data processing may occur in any of the components of subsystem 125 or a combination of those components. In some examples, a server may perform the processing of data. The server may be client device 105 or may be located in data storage 120.

[0038]

[0043] As described herein, the authentication platform 115 (equivalently referred to herein as an identity management platform) may receive an indication that a developer or administrative user of the authentication platform 115 has enabled passkey authentication for a client device 105 supported by the authentication platform 115. Accordingly, the authentication platform 115 may transmit an indication of a passkey login option for display in an application 110 associated with the client device 105 (e.g., a web browser running on the user device). For example, if the authentication platform 115 receives an indication that the application 110 associated with the client device 105 has selected the passkey login option, the authentication platform 115 may prompt the application 110 (via one or more API calls to a web authentication service) to generate a passkey. The application 110 may use the passkey to log in and access resources provided by the client device 105.

[0039]

[0044] Aspects of the computing environment 100 can be implemented to achieve one or more of the following advantages: The techniques described with respect to FIG. 1 may enable a developer or administrator of the authentication platform 115 to dynamically configure passkey authentication for clients of the authentication platform 115 via one or more user interface elements. For example, an administrator of the authentication platform 115 may enable (or disable) passkey authentication for clients of the authentication platform by interacting with a button, a toggle switch, a checkbox, or the like. Thus, compared to other (static, hard-coded) passkey integration schemes, the techniques described herein may provide developers with a flexible and user-friendly passkey integration mechanism. Furthermore, providing passkey authentication services to clients of the authentication platform 115 may enable end users of the authentication platform 115 to access client resources with greater security and reduced manual interaction, among other benefits.

[0040]

[0045] Those skilled in the art will appreciate that one or more aspects of the computing environment 100 may be implemented to solve additional or alternative problems other than those discussed above. Furthermore, aspects of the present disclosure may provide technical improvements over the "conventional" systems or processes described herein. However, the description and accompanying drawings contain only examples of technical improvements resulting from implementing aspects of the present disclosure and therefore do not represent all of the technical improvements provided in the claims.

[0041]

[0046] 2 illustrates an example computing environment 200 that supports passkey integration techniques for identity management in accordance with one or more aspects of the present disclosure. Computing environment 200 may implement or be implemented by aspects of computing environment 100. For example, computing environment 200 may include identity management platform 210, which may be an example of authentication platform 115 described with respect to FIG. 1. Computing environment 200 may also include device 205 and device 215 that can communicate or exchange information with identity management platform 210 via one or more user interfaces. Device 205 may be associated with a developer or administrative user of identity management platform 210, while device 215 may be associated with an end user of identity management platform 210 (e.g., a user associated with a client of identity management platform 210). In computing environment 200, identity management platform 210 may display an option for using passkey authentication on device 215.

[0042]

[0047] 2, identity management platform 210 can receive user input 225 from device 205. More specifically, identity management platform 210 can receive user input 225 from an administrative user via a web browser running on device 205. Device 205 can transmit user input 225 in response to the administrative user clicking or otherwise interacting with user interface elements 265 displayed within user interface 220-a. In response to user input 225 from device 205, identity management platform 210 can enable passkey authentication for one or more clients of identity management platform 210 (e.g., client device 105 described with respect to FIG. 1).

[0043]

[0048] When passkey authentication is enabled and device 215 navigates to a login page associated with a client of identity management platform 210, device 215 can receive display information 235 from identity management platform 210. Display information 235 can include instructions for rendering or displaying user interface 220-b on device 215. As shown in the example of FIG. 2, user interface 220-b can include option 270 for logging in using a passkey and option 260 for logging in using other credentials (username, email, password). In some examples, identity management platform 210 can determine whether to display option 270 based on capability information 230 provided by device 215. For example, if capability information 230 indicates that device 215 supports passkey authentication, identity management platform 210 can display option 270 in user interface 220-b.

[0044]

[0049] When an end user selects option 270 to use passkey authentication by clicking or selecting one or more user interface elements displayed within user interface 220-b, user input 240 may be sent from device 215 to identity management platform 210. Accordingly, identity management platform 210 may call an API to facilitate passkey generation on device 215. For example, a web browser running on device 215 may perform one or more calls to an external API to generate a secure passkey including a private key and a public key. Device 215 may store the private key (in association with the client's login page) and transmit an indication of the public key to identity management platform 210. Accordingly, identity management platform 210 may store the public key in association with the end user's other credentials (username, password, account number) so that the public key can be used (in addition to or instead of the other credentials) to verify the end user's identity.

[0045]

[0050] Once the identity management platform 210 has access to the public key generated by the device 215, the identity management platform 210 can retrieve the public key when the device 215 attempts to log in again. To initiate a passkey-based login procedure, the identity management platform 210 can transmit a cryptographic challenge 245 to the device 215. The cryptographic challenge 245 can be, for example, a string of characters, an integer, a nonce, etc. In response to the cryptographic challenge 245, the device 215 can prompt the end user to provide some form of biometric information or a pre-approved security key to unlock a private key stored on the device 215. For example, the device 215 can prompt the end user to perform facial recognition, voice recognition, fingerprint recognition, etc.

[0046]

[0051] Once the private key is unlocked, device 215 can use the private key to sign cryptographic challenge 245. That is, device 215 can apply a digital signature to cryptographic challenge 245 using the private key stored on device 215. Device 215 can then transmit an indication of the signed cryptographic challenge to identity management platform 210 in the form of cryptographic response 250. Identity management platform 210 can receive cryptographic response 250 and verify the authenticity of cryptographic response 250 using the public key (obtained from device 215). More specifically, identity management platform 210 can use the public key to determine whether cryptographic response 250 was signed using the private key. If identity management platform 210 determines that cryptographic response 250 is valid, then identity management platform 210 can approve the login attempt by device 215. Otherwise, identity management platform 210 can reject the login attempt.

[0047]

[0052] 3 illustrates an example process flow 300 supporting a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure. Process flow 300 may implement or be implemented by aspects of computing environment 100 or computing environment 200. For example, process flow 300 may include identity management platform 310, which may be an example of identity management platform 210 described with respect to FIG. 2. Process flow 300 may also include device 305 and device 315, which may be examples of corresponding devices described herein. In the following description of process flow 300, operations among device 305, identity management platform 310, and device 315 may be added, omitted, or performed in a different order (relative to the example order shown).

[0048]

[0053] At 320, identity management platform 310 may receive user input from an administrative user via a web browser running on device 305. The user input may indicate a request to enable passkey authentication for clients of identity management platform 310. In some examples, identity management platform 310 may receive or detect the user input in response to a developer or administrator interacting with one or more elements displayed within a user interface configured for identity management platform 310 (e.g., user interface element 265 described with respect to FIG. 2 ). At 325, identity management platform 310 may enable passkey authentication for clients of identity management platform 310 based on the user input.

[0049]

[0054] At 330, an end user of the device 315 may navigate to a login page associated with a client of the identity management platform 310. The end user may be an example of a customer or contact associated with the client of the identity management platform 310. At 335, the identity management platform 310 may (in some examples) receive capability information associated with the device 315. The capability information may indicate whether the device 315 supports passkey authentication. At 340, the identity management platform 310 may display options for the end user to set and use a passkey. If the end user selects this option at 345, the device 315 may generate a passkey at 350 by making one or more calls to an external API. As described herein, the passkey may include a private key and a public key.

[0050]

[0055] At 355, the device 315 may store the private key (locally) and transmit an indication of the public key to the identity management platform 310. To maintain the confidentiality of the locally generated private key, the device 315 may not share the private key with the identity management platform 310 (or any other device). At 360, the identity management platform 310 may store the public key in association with the end user's other credentials (e.g., email, username, account number). In some examples, the identity management platform 310 may store multiple passkeys for an end user. For example, if the end user attempts to access the same login page using different devices (smartphone, tablet, desktop) or operating systems, the identity management platform 310 may prompt the end user to create a new passkey, which may be stored in association with the particular device, operating system, web browser, etc.

[0051]

[0056] In some examples, device 315 can upload or store the private key in the cloud-based password management application so that the passkey can be used on other devices that have access to the cloud-based password management application. For example, if an end user generates a passkey for a login page using a first device (e.g., a desktop) and then navigates to the same login page on a second device (e.g., a smartphone), the first device can store the passkey in the cloud-based password management application so that the second device can obtain the passkey for the login page (via the cloud-based password management application). As a result, the end user can access the same passkey across different devices, operating systems, web browsers, etc.

[0052]

[0057] Aspects of process flow 300 can be implemented to achieve one or more of the following advantages: The techniques described with respect to FIG. 3 may allow a developer or administrative user of the identity management platform 310 to dynamically enable or disable passkey authentication for a client of the identity management platform 310. For example, the techniques described may allow a developer of the identity management platform 310 to control whether an end user is presented with an option to set and use a passkey when the end user attempts to access a protected resource associated with a client of the identity management platform 310. Furthermore, the identity management platform 310 may selectively display the option on devices enabled for passkey integration, which may reduce the likelihood of compatibility issues, errors, etc.

[0053]

[0058] FIG. 4 illustrates an example process flow 400 supporting a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure. Process flow 400 may be implemented by or with any of the computing environments and process flows described with respect to FIGS. 1 through 3. For example, process flow 400 may include an identity management platform 410, which may be an example of identity management platform 210 or identity management platform 310 described with respect to FIGS. 2 and 3. Process flow 400 may also include an apparatus 415, which may be an example of apparatus 315 described with respect to FIG. 3. In the following description of process flow 400, operations between identity management platform 410 and apparatus 415 may be added, omitted, or performed in a different order (relative to the example order shown).

[0054]

[0059] At 420, a user of device 415 may navigate to a login page associated with a client of identity management platform 410. The user may be an example of a customer or contact of the client. The user may navigate to the login page via a web browser running on device 415. The login page may be displayed according to display information provided by one or both of the client or identity management platform 410. In some examples, the user may be presented with the login page after attempting to access a protected or guarded resource of the client. The identity management platform 410 may detect a login attempt from device 415 and obtain identity information associated with one or both of the user and device 415. The identity management platform 410 may obtain this information based on a device identifier associated with the login attempt, an Internet Protocol (IP) address of device 415, etc.

[0055]

[0060] If the identity management platform 410 determines that the user of the user device 415 has previously configured and registered a passkey with the client (using the techniques described with respect to FIG. 3 ), the identity management platform 410 may issue a cryptographic challenge to the device 415 at 425. The cryptographic challenge may be an example of a string, an integer, a nonce, etc. The identity management platform 410 may issue the cryptographic challenge to verify that the device 415 has access to the previously generated passkey. At 430, the device 415 may prompt the user to perform some form of local authentication (such as facial or fingerprint recognition) to unlock a private key stored on the device 415. The private key may be an example of a secret cryptographic variable used (in combination with a cryptographic algorithm) to decrypt and encrypt data.

[0056]

[0061] Once the user successfully completes the local authentication procedure (by providing biometric information or some form of security key), the device 415 may unlock the private key at 435 and use the private key to sign a cryptographic challenge at 440 (e.g., cryptographic challenge 245 described with respect to FIG. 2). At 445, the device 415 may transmit an indication of the signed cryptographic challenge to the identity management platform 410 in the form of a cryptographic response (e.g., cryptographic response 250 described with respect to FIG. 2). The cryptographic response may therefore include a digital signature generated using the private key.

[0057]

[0062] At 455, the identity management platform 410 may verify the cryptographic response from the device 415 using a public key stored in association with either or both of the user and the device 415. For example, if the identity management platform 410 determines that the cryptographic response is valid (based on the digital signature in the cryptographic response), the identity management platform 410 may approve the login request at 460 and authorize the device 415 to access the client's protected resources. Otherwise, if the identity management platform 410 determines that the cryptographic response is invalid, the identity management platform 410 may deny the login request.

[0058]

[0063] Aspects of process flow 400 can be implemented to achieve one or more of the following advantages: The techniques described with respect to FIG. 4 may allow a developer or administrative user of identity management platform 410 to dynamically enable or disable passkey authentication for a client of identity management platform 410. For example, the described techniques may allow a developer of identity management platform 410 to control whether an end user is presented with an option to set and use a passkey when the end user attempts to access a protected resource associated with a client of identity management platform 410. Furthermore, identity management platform 410 may selectively display an option on devices enabled for passkey integration, which may reduce the likelihood of compatibility issues, errors, etc.

[0059]

[0064] 5 illustrates a block diagram 500 of an apparatus 505 that supports passkey integration techniques for identity management in accordance with one or more aspects of the present disclosure. The apparatus 505 may include an input module 510, an output module 515, and an authentication manager 520. The apparatus 505 may also include a processor. Each of these components may communicate with each other (e.g., via one or more buses).

[0060]

[0065] The input module 510 can manage input signals for the device 505. For example, the input module 510 can identify input signals based on interaction with a modem, keyboard, mouse, touchscreen, or similar device. These input signals can relate to user input or processing in other components or devices. In some cases, the input module 510 can process the input signals using an operating system such as iOS®, ANDROID®, MS-DOS®, MS-WINDOWS®, OS / 2®, UNIX®, LINUX®, or another known operating system. The input module 510 can send aspects of these input signals to other components of the device 505 for processing. For example, the input module 510 can transmit input signals to the authentication manager 520 to support passkey integration techniques for identity management. In some cases, the input module 510 can be a component of the input / output (I / O) controller 710, as described with respect to FIG. 7 .

[0061]

[0066] Output module 515 can manage output signals for device 505. For example, output module 515 can receive signals from other components of device 505, such as authentication manager 520, and can transmit those signals to other components or devices. In some examples, output module 515 can transmit the output signals for display in a user interface, for storage in a database or data store, for further processing on a server or server cluster, or for any other process in any number of devices or systems. As described with respect to FIG. 7, in some cases output module 515 can be a component of I / O controller 710.

[0062]

[0067] For example, authentication manager 520 may include a passkey enable component 525, an options display component 530, a selection receive component 535, a key retrieval component 540, a user authentication component 545, or any combination thereof. In some examples, authentication manager 520 or its various components may be configured to perform various operations (e.g., receive, monitor, transmit) using or in conjunction with input module 510, output module 515, or both. For example, authentication manager 520 may receive information from input module 510, send information to output module 515, or be integrated in combination with input module 510, output module 515, or both to receive information, transmit information, or perform various other operations described herein.

[0063]

[0068] The authentication manager 520 can support passkey authentication in the identity management platform according to examples disclosed herein. The passkey enable component 525 can be configured as or support a means for receiving, via a first user interface configured for the identity management platform, an instruction to enable passkey authentication for a client of the identity management platform from an administrator of the identity management platform. The option display component 530 can be configured as or support a means for displaying in a second user interface configured for the client of the identity management platform and for transmitting, based on enabling passkey authentication, an option to use passkey authentication for the login procedure. The selection receiving component 535 can be configured as or support a means for receiving, via the second user interface, from a user associated with the client, a selection of the option to use passkey authentication for the login procedure. The key acquisition component 540 can be configured as or support a means for obtaining the user's public key in response to the user selecting the option to use passkey authentication for the login procedure. The user authentication component 545 may be configured or support a means for performing a login procedure using at least a public key to authenticate a user's identity.

[0064]

[0069] FIG. 6 illustrates a block diagram 600 of an authentication manager 620 supporting a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure. The authentication manager 620 may be an example of an aspect of the authentication manager 520 as described with respect to FIG. 5. The authentication manager 620, or various components thereof, may be an example of a means for performing various aspects of a passkey integration technique for identity management as described herein. For example, the authentication manager 620 may include a passkey enablement component 625, an options display component 630, a selection reception component 635, a key acquisition component 640, a user authentication component 645, a challenge transmission component 650, a response reception component 655, a capability information reception component 660, a device compatibility component 665, or any combination thereof. Each of these components may communicate directly or indirectly with one another (e.g., via one or more buses).

[0065]

[0070] The authentication manager 620 can support passkey authentication in the identity management platform according to examples disclosed herein. The passkey enable component 625 can be configured as or support a means for receiving, via a first user interface configured for the identity management platform, an instruction to enable passkey authentication for a client of the identity management platform from an administrator of the identity management platform. The option display component 630 can be configured as or support a means for transmitting, for display in a second user interface configured for the client of the identity management platform, an option to use passkey authentication for the login procedure based on enabling passkey authentication. The selection receiving component 635 can be configured as or support a means for receiving, via the second user interface, from a user associated with the client, a selection of the option to use passkey authentication for the login procedure. The key acquisition component 640 can be configured as or support a means for obtaining the user's public key in response to the user selecting the option to use passkey authentication for the login procedure. The user authentication component 645 may be configured or support a means for performing a login procedure using at least a public key to authenticate a user's identity.

[0066]

[0071] In some examples, to support the execution of a login procedure, the challenge transmission component 650 can be configured or support a means for transmitting an indication of a cryptographic challenge to a device associated with a user. In some examples, to support the execution of a login procedure, the response reception component 655 can be configured or support a means for receiving an indication of a cryptographic response from a device in response to the cryptographic challenge, the cryptographic response including a digital signature. In some examples, to support the execution of a login procedure, the user authentication component 645 can be configured or support a means for authenticating a user based on verifying a digital signature in the cryptographic response using a public key.

[0067]

[0072] In some examples, the user authentication component 645 may be configured with or support a means for determining that a device has access to a private key associated with a user based on a digital signature in a cryptographic response, and authenticating the user is based on determining that the device has access to the private key.

[0068]

[0073] In some examples, the private key is unlocked locally on the device after the user successfully performs a facial recognition procedure, a voice recognition procedure, a fingerprint recognition procedure, a personal identification number verification procedure, a security key verification procedure, or a combination thereof. In some examples, the private key is generated and stored on the device after the user selects the option to use passkey authentication for the login procedure.

[0069]

[0074] In some examples, the key acquisition component 640 may be configured with or support a means for receiving an indication that a user has registered a public key with a client of the identity management platform, and obtaining the user's public key is based on the indication.

[0070]

[0075] In some examples, to support receiving a selection of an option to use passkey authentication, the selection receiving component 635 may be configured as or support a means for receiving the selection via a web browser running on a device associated with the user, and the user's public key is stored in an identity management platform in association with the user, the web browser, the device, the device's operating system, or a combination thereof.

[0071]

[0076] In some examples, the capability information receiving component 660 can be configured or support a means for receiving an indication of capability information associated with a device via a web browser executing on a device associated with a user. In some examples, the device compatibility component 665 can be configured or support a means for determining, based on the capability information, that the device supports passkey authentication, and displaying an option for using passkey authentication in the login procedure is based on determining that the device supports passkey authentication. In some examples, the capability information is received via a web browser executing on the user's device.

[0072]

[0077] In some examples, the key retrieval component 640 may be configured with or support a means for storing a public key in the identity management platform in association with a user identifier, a user password, an account number associated with the user, or a combination thereof, where the public key is retrieved from the identity management platform after the user initiates a login procedure.

[0073]

[0078] In some examples, to support receiving instructions to enable passkey authentication, passkey enablement component 625 can be configured as or support a means for enabling passkey authentication for a client of the identity management platform in response to an identity management platform administrator selecting one or more user interface elements displayed within the first user interface. In some examples, the one or more user interface elements include a check box, a toggle switch, a drop-down list, a button, or a combination thereof.

[0074]

[0079] In some examples, the passkey enablement component 625 may be configured as or support a means for configuring a passkey for a user based on making one or more API calls to a web authentication service, where the passkey includes a public key and a corresponding private key associated with the user.

[0075]

[0080] In some examples, to support displaying an option for using passkey authentication, the option display component 630 can be configured or support a means for conveying, for display in the second user interface, a first option for using passkey authentication in the login procedure and a second option for using other credentials in the login procedure, where the first option is selected by the user.

[0076]

[0081] 7 illustrates a diagram of a system 700 including a device 705 that supports passkey integration techniques for identity management in accordance with one or more aspects of the present disclosure. The device 705 may be an example of or include components of the device 505 described herein with respect to FIG. 5. The device 705 may include various components for data communication, including components for sending and receiving communications, such as an authentication manager 720, an I / O controller 710, a database controller 715, a memory 725, a processor 730, and a database 735. These components may be in electronic communication or may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more buses (e.g., bus 740).

[0077]

[0082] The I / O controller 710 can manage input signals 745 and output signals 750 of the device 705. The I / O controller 710 can also manage peripheral devices not integrated into the device 705. In some cases, the I / O controller 710 may represent a physical connection or port to an external peripheral device. In some cases, the I / O controller 710 can utilize an operating system such as iOS®, ANDROID®, MS-DOS®, MS-WINDOWS®, OS / 2®, UNIX®, LINUX®, or another known operating system. In other cases, the I / O controller 710 can represent or interact with a modem, keyboard, mouse, touchscreen, or similar device. In some cases, the I / O controller 710 can be implemented as part of the processor 730. In some examples, a user can interact with the device 705 through the I / O controller 710 or through hardware components controlled by the I / O controller 710.

[0078]

[0083] The database controller 715 can manage the storage and processing of data in the database 735. In some cases, a user can interact with the database controller 715. In other cases, the database controller 715 can operate automatically without user interaction. The database 735 can be an example of a single database, a distributed database, multiple distributed databases, a data store, a data lake, or an emergency backup database.

[0079]

[0084] Memory 725 may include random access memory (RAM) and read-only memory (ROM). Memory 725 may store computer-readable, computer-executable software containing instructions that, when executed, cause processor 730 to perform various functions described herein. In some cases, memory 725 may include a basic I / O system (BIOS), which may control basic hardware or software operations, such as interaction with peripheral components or devices, among other things.

[0080]

[0085] The processor 730 may include an intelligent hardware device (e.g., a general-purpose processor, a digital signal processor (DSP), a central processing unit (CPU), a graphics processing unit (GPU), a microcontroller, an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), a programmable logic device, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some cases, the processor 730 may be configured to operate a memory array using a memory controller. In other cases, the memory controller may be integrated into the processor 730. The processor 730 may be configured to execute computer-readable instructions stored in the memory 725 to perform various functions (e.g., functions or tasks supporting passkey integration techniques for identity management).

[0081]

[0086] Authentication manager 720 can support passkey authentication in an identity management platform according to examples disclosed herein. For example, authentication manager 720 can be configured as or support a means for receiving an instruction to enable passkey authentication for a client of the identity management platform from an administrator of the identity management platform via a first user interface configured for the identity management platform. Authentication manager 720 can be configured as or support a means for transmitting an option to use passkey authentication for a login procedure for display in a second user interface configured for the client of the identity management platform and based on enabling passkey authentication. Authentication manager 720 can be configured as or support a means for receiving a selection of the option to use passkey authentication for the login procedure from a user associated with the client via the second user interface. Authentication manager 720 can be configured as or support a means for obtaining a user's public key in response to the user selecting the option to use passkey authentication for the login procedure. Authentication manager 720 can be configured as or support a means for performing a login procedure using at least the public key to authenticate the user's identity.

[0082]

[0087] By including or configuring authentication manager 720 according to examples described herein, device 705 can support techniques for dynamically enabling or disabling passkey authentication for clients of the identity management platform. For example, a developer of the identity management platform can use device 705 to control whether an end user is presented with an option to set and use a passkey when the end user attempts to access a protected resource associated with the client of the identity management platform. Additionally, the identity management platform can selectively display the option on devices enabled for passkey integration, which may reduce the likelihood of compatibility issues, errors, etc.

[0083]

[0088] 8 shows a flowchart illustrating a method 800 for supporting a passkey integration technique for identity management according to one or more aspects of the present disclosure. The operations of method 800 may be implemented by an identity management platform or components thereof. For example, the operations of method 800 may be performed by the identity management platform 210 described with respect to FIG. 2. In some examples, the identity management platform may execute a set of instructions to control functional elements of the identity management platform to perform the operations of method 800. Additionally or alternatively, the identity management platform may perform aspects of the operations of method 800 using dedicated hardware.

[0084]

[0089] At 805, the identity management platform may receive instructions to enable passkey authentication for a client of the identity management platform from an administrator of the identity management platform via a first user interface configured for the identity management platform. The operations of 805 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 805 may be performed by the passkey enablement component 625 described with respect to FIG. 6.

[0085]

[0090] At 810, the identity management platform may transmit an option for using passkey authentication for the login procedure for display in a second user interface configured for a client of the identity management platform and based on enabling passkey authentication. The operations of 810 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 810 may be performed by option display component 630 described with respect to FIG. 6.

[0086]

[0091] At 815, the identity management platform may receive, via the second user interface, from a user associated with the client, a selection of an option to use passkey authentication for the login procedure. The operations of 815 may be performed according to examples disclosed herein. In some examples, the operations of 815 may be performed by the selection receiving component 635 described with respect to FIG. 6.

[0087]

[0092] At 820, the identity management platform may obtain the user's public key in response to the user selecting an option to use passkey authentication for the login procedure. The operations of 820 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 820 may be performed by the key derivation component 640 described with respect to FIG. 6.

[0088]

[0093] At 825, the identity management platform may perform a login procedure using at least the public key to authenticate the user's identity. The operations of 825 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 825 may be performed by the user authentication component 645 described with respect to FIG. 6.

[0089]

[0094] 9 shows a flowchart illustrating a method 900 for supporting a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure. The operations of method 900 may be implemented by an identity management platform or components thereof. For example, the operations of method 900 may be performed by the identity management platform 310 described with respect to FIG. 3. In some examples, the identity management platform may execute a set of instructions to control functional elements of the identity management platform to perform the operations of method 900. Additionally or alternatively, the identity management platform may perform aspects of the operations of method 900 using dedicated hardware.

[0090]

[0095] At 905, the identity management platform may receive instructions to enable passkey authentication for a client of the identity management platform from an administrator of the identity management platform via a first user interface configured for the identity management platform. The operations of 905 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 905 may be performed by the passkey enablement component 625 described with respect to FIG. 6.

[0091]

[0096] At 910, the identity management platform may transmit an option for display in a second user interface configured for a client of the identity management platform and, based on enabling passkey authentication, for using passkey authentication in the login procedure. The operations of 910 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 910 may be performed by option display component 630 described with respect to FIG. 6.

[0092]

[0097] At 915, the identity management platform may receive, via the second user interface, from a user associated with the client, a selection of an option to use passkey authentication for the login procedure. The operations of 915 may be performed according to examples disclosed herein. In some examples, the operations of 915 may be performed by the selection receiving component 635 described with respect to FIG. 6.

[0093]

[0098] At 920, the identity management platform may obtain the user's public key in response to the user selecting an option to use passkey authentication for the login procedure. The operations of 920 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 920 may be performed by the key derivation component 640 described with respect to FIG. 6.

[0094]

[0099] At 925, the identity management platform may transmit an indication of the cryptographic challenge to a device associated with the user. The operations of 925 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 925 may be performed by the challenge transmission component 650 described with respect to FIG. 6.

[0095]

[0100] At 930, the identity management platform can receive from the device an indication of a cryptographic response in response to the cryptographic challenge, the cryptographic response including a digital signature. The operations of 930 can be performed in accordance with examples disclosed herein. In some examples, aspects of the operations of 930 can be performed by the response receiving component 655 described with respect to FIG. 6.

[0096]

[0101] At 935, the identity management platform can authenticate the user based on verifying the digital signature in the cryptographic response using the public key. The operations of 935 can be performed according to examples disclosed herein. In some examples, aspects of the operations of 935 can be performed by the user authentication component 645 described with respect to FIG. 6.

[0097]

[0102] 10 shows a flowchart illustrating a method 1000 for supporting a passkey integration technique for identity management in accordance with one or more aspects of the present disclosure. The operations of method 1000 may be implemented by an identity management platform or components thereof. For example, the operations of method 1000 may be performed by the identity management platform 410 described with respect to FIG. 4. In some examples, the identity management platform may execute a set of instructions to control functional elements of the identity management platform to perform the operations of method 1000. Additionally or alternatively, the identity management platform may perform aspects of the operations of method 1000 using dedicated hardware.

[0098]

[0103] At 1005, the identity management platform may receive instructions to enable passkey authentication for a client of the identity management platform from an administrator of the identity management platform via a first user interface configured for the identity management platform. The operations of 1005 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 1005 may be performed by the passkey enablement component 625 described with respect to FIG. 6.

[0099]

[0104] At 1010, the identity management platform may receive an indication of capability information associated with the device via a web browser executing on a device associated with a user. The operations of 1010 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 1010 may be performed by the capability information receiving component 660 described with respect to FIG. 6.

[0100]

[0105] At 1015, the identity management platform may determine, based on the capabilities information, that the device supports passkey authentication. The operations of 1015 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 1015 may be performed by the device compatibility component 665 described with respect to FIG. 6.

[0101]

[0106] At 1020, the identity management platform may transmit an option for using passkey authentication for the login procedure for display in a second user interface configured for a client of the identity management platform and based on determining that the device supports passkey authentication. The operations of 1020 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 1020 may be performed by option display component 630 described with respect to FIG. 6.

[0102]

[0107] At 1025, the identity management platform may receive, via the second user interface, from a user associated with the client, a selection of an option to use passkey authentication for the login procedure. The operations of 1025 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 1025 may be performed by the selection receiving component 635 described with respect to FIG. 6.

[0103]

[0108] At 1030, the identity management platform may obtain the user's public key in response to the user selecting an option to use passkey authentication for the login procedure. The operations of 1030 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 1030 may be performed by the key derivation component 640 described with respect to FIG. 6.

[0104]

[0109] At 1035, the identity management platform may perform a login procedure using at least the public key to authenticate the user's identity. The operations of 1035 may be performed according to examples disclosed herein. In some examples, aspects of the operations of 1035 may be performed by the user authentication component 645 described with respect to FIG. 6.

[0105]

[0110] It should be noted that the methods described above describe possible implementations, and that operations and steps may be rearranged or modified, and other implementations are possible. Furthermore, aspects from two or more of the methods may be combined.

[0106]

[0111] The description set forth herein with reference to the accompanying drawings illustrates example configurations and does not represent every example that may be implemented or fall within the scope of the claims. As used herein, the term "exemplary" means "serving as an example, instance, or illustration" and does not mean "preferred" or "advantageous over other examples." The detailed description includes specific details for the purpose of providing an understanding of the described techniques. However, these techniques may be practiced without these specific details. In some instances, well-known structures and devices are shown in block diagram form in order to avoid obscuring the concepts of the described examples.

[0107]

[0112] In the accompanying drawings, similar components or features may have the same reference label. Additionally, various components of the same type may be distinguished by following the reference label with a dash and a second label that distinguishes among the similar components. When only a first reference label is used in this specification, the description is applicable to any similar component having the same first reference label regardless of the second reference label.

[0108]

[0113] The information and signals described herein may be represented using any of a variety of different technologies and techniques. For example, the data, instructions, commands, information, signals, bits, symbols, and chips that may be referred to throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0109]

[0114] The various example blocks and modules described in connection with the disclosure herein may be implemented or performed using a general purpose processor, a DSP, an ASIC, an FPGA or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor may be a microprocessor, but may alternatively be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in combination with a DSP core, or any other such configuration).

[0110]

[0115] The functions described herein may be implemented in hardware, software executed by a processor, firmware, or any combination thereof. When implemented in software executed by a processor, the functions may be stored on or transmitted as one or more instructions or code on a computer-readable medium. Other examples and implementations are within the scope of this disclosure and the appended claims. For example, due to the nature of software, the functions described above may be implemented using software executed by a processor, hardware, firmware, hardwiring, or any combination thereof. Features implementing a function may be physically located in various locations, including being distributed so that portions of the function are implemented in different physical locations. Furthermore, as used herein, including the claims, "or" used in a list of items (e.g., a list of items followed by a phrase such as "at least one of" or "one or more of") indicates an inclusive list, such as a list of at least one of A, B, or C, meaning A, or B, or C, or AB, or AC, or BC, or ABC (i.e., A and B and C). Furthermore, as used herein, the phrase "based on" should not be construed as referring to a closed set of conditions. For example, an example step described as "based on condition A" can be based on both condition A and condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase "based on" is intended to be interpreted similarly to the phrase "based at least in part on."

[0111]

[0116] Computer-readable media includes both non-transitory computer storage media and communication media, including any medium that facilitates transfer of a computer program from one place to another. Non-transitory storage media may be any available medium that can be accessed by a general-purpose or special-purpose computer. By way of example, and not limitation, non-transitory computer-readable media may include RAM, ROM, Electrically Erasable Programmable Read Only Memory (EEPROM), Compact Disc (CD) ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to carry or store desired program code means in the form of instructions or data structures and that can be accessed by a general-purpose or special-purpose computer or processor. Furthermore, any connection is properly referred to as a computer-readable medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. As used herein, disk and disc include CDs, laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, where disks typically replicate data magnetically and discs replicate data optically with a laser. Combinations of the above are also included within the scope of computer-readable media.

[0112]

[0117] The description herein is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to the disclosure will readily occur to those skilled in the art, and the general principles defined herein may be applied to other alternative forms without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. 1. A method for passkey authentication in an identity management platform, comprising: receiving instructions from an administrator of the identity management platform via a first user interface configured for the identity management platform to enable passkey authentication for a client of the identity management platform; transmitting, for display in a second user interface configured for a client of the identity management platform, and based at least in part on enabling the passkey authentication, an option to use the passkey authentication in a login procedure; receiving, via the second user interface, from a user associated with the client, a selection of the option to use the passkey authentication in a login procedure; obtaining a public key of the user in response to the user selecting the option to use the passkey authentication for the login procedure; and performing the login procedure using at least the public key to authenticate the identity of the user; A method comprising:

2. Executing the login procedure, transmitting an indication of the cryptographic challenge to a device associated with said user; receiving from the device an indication of a cryptographic response in response to the cryptographic challenge, the cryptographic response including a digital signature; and authenticating the user based at least in part on verifying the digital signature in the cryptographic response using the public key; The method of claim 1 , comprising:

3. determining, based at least in part on the digital signature in the cryptographic response, that the device has access to a private key associated with the user, wherein authenticating the user is based at least in part on determining that the device has access to the private key. The method of claim 2 further comprising:

4. 4. The method of claim 3, wherein the private key is unlocked locally on the device after the user successfully performs a facial recognition procedure, a voice recognition procedure, a fingerprint recognition procedure, a personal identification number verification procedure, a security key verification procedure, or a combination thereof.

5. The method of claim 3 , wherein the private key is generated and stored on the device after the user selects the option to use the passkey authentication for the login procedure.

6. receiving an indication that the user has registered the public key with the client of the identity management platform, wherein obtaining the public key of the user is based at least in part on the indication. The method of claim 1 further comprising:

7. receiving the selection of the option to use the passkey authentication; receiving the selection via a web browser executing on a device associated with the user, wherein the public key of the user is stored in the identity management platform in association with the user, the web browser, the device, an operating system of the device, or a combination thereof; The method of claim 1 , comprising:

8. receiving, via a web browser executing on a device associated with the user, an indication of capability information associated with the device; and determining, based at least in part on the capabilities information, that the device supports passkey authentication, and wherein displaying the option to use passkey authentication in the login procedure is based at least in part on determining that the device supports passkey authentication. The method of claim 1 further comprising:

9. The method of claim 8 , wherein the capability information is received via a web browser running on the device of the user.

10. storing the public key in the identity management platform in association with an identifier of the user, a password of the user, an account number associated with the user, or a combination thereof, the public key being obtained from the identity management platform after the user initiates the login procedure. The method of claim 1 further comprising:

11. Receiving the instruction to enable the passkey authentication includes: enabling the passkey authentication for the client of the identity management platform in response to the administrator of the identity management platform selecting one or more user interface elements displayed within the first user interface. The method of claim 1 , comprising:

12. The method of claim 11 , wherein the one or more user interface elements include a checkbox, a toggle switch, a drop-down list, a button, or a combination thereof.

13. constructing a passkey for the user based at least in part on executing one or more application programming interface calls to a web authentication service, the passkey including the public key and a corresponding private key associated with the user. The method of claim 1 further comprising:

14. Displaying the option to use the passkey authentication includes: transmitting, for display in the second user interface, a first option for using the passkey authentication in the login procedure and a second option for using other credentials in the login procedure, the first option being selected by the user. The method of claim 1 , comprising:

15. A device for passkey authentication in an identity management platform, comprising: a processor; a memory coupled to the processor; instructions stored in the memory, receiving instructions from an administrator of the identity management platform via a first user interface configured for the identity management platform to enable passkey authentication for a client of the identity management platform; transmitting, for display in a second user interface configured for a client of the identity management platform, and based at least in part on enabling the passkey authentication, an option to use the passkey authentication in a login procedure; receiving, via the second user interface, from a user associated with the client, a selection of the option to use the passkey authentication in a login procedure; obtaining a public key of the user in response to the user selecting the option to use the passkey authentication for the login procedure; and performing the login procedure using at least the public key to authenticate the identity of the user; instructions executable by the processor to cause the device to Including, equipment.

16. The instructions for performing the login procedure include: transmitting an indication of the cryptographic challenge to a device associated with said user; receiving from the device an indication of a cryptographic response in response to the cryptographic challenge, the cryptographic response including a digital signature; and authenticating the user based at least in part on verifying the digital signature in the cryptographic response using the public key; 16. The device of claim 15, wherein the step of:

17. The instruction: receiving, via a web browser executing on a device associated with the user, an indication of capability information associated with the device; and determining, based at least in part on the capabilities information, that the device supports passkey authentication, and wherein displaying the option to use passkey authentication in the login procedure is based at least in part on determining that the device supports passkey authentication.

16. The device of claim 15, further executable by the processor to cause the device to:

18. The instruction: storing the public key in the identity management platform in association with an identifier of the user, a password of the user, an account number associated with the user, or a combination thereof, the public key being obtained from the identity management platform after the user initiates the login procedure.

16. The device of claim 15, further executable by the processor to cause the device to:

19. 1. A non-transitory computer-readable medium storing a code for passkey authentication in an identity management platform, the code comprising: receiving instructions from an administrator of the identity management platform via a first user interface configured for the identity management platform to enable passkey authentication for a client of the identity management platform; transmitting, for display in a second user interface configured for a client of the identity management platform, and based at least in part on enabling the passkey authentication, an option to use the passkey authentication in a login procedure; receiving, via the second user interface, from a user associated with the client, a selection of the option to use the passkey authentication in a login procedure; obtaining a public key of the user in response to the user selecting the option to use the passkey authentication for the login procedure; and performing the login procedure using at least the public key to authenticate the identity of the user; A non-transitory computer-readable medium comprising instructions executable by a processor to perform the steps of:

20. The instructions for performing the login procedure include: transmitting an indication of the cryptographic challenge to a device associated with said user; receiving from the device an indication of a cryptographic response in response to the cryptographic challenge, the cryptographic response including a digital signature; and authenticating the user based at least in part on verifying the digital signature in the cryptographic response using the public key; 20. The non-transitory computer-readable medium of claim 19, executable by the processor to:

Citation Information

Patent Citations

  • Authentication system, authentication key management device, authentication key management method and authentication key management program

    JP2016139910A

  • Authentication server, authentication system and authentication method

    JP2019046044A

  • Computer system, log-in screen display method, and program

    JP2021043902A