OpenID extension
Adds secure registration semantics to an OpenID authorization flow, including a create mode used to initiate passkey registration.
Amwal's patented protocols extend OpenID security to support secure passkey registration and authentication across web browsers and native mobile applications.
View the published patentPatent number
US 12,388,646 B2
Issued
August 12, 2025
Assignee
Amwal Tech Inc.
Inventor
Sameh Galal
The invention, briefly
The patent describes systems and methods that decide between secure passkey registration and authentication, verify that requests are genuine, adapt the flow to the client device, and issue an authentication token for a secure network session.
Adds secure registration semantics to an OpenID authorization flow, including a create mode used to initiate passkey registration.
Detects the client platform and supports browser-based experiences as well as native mobile operating-system SDKs.
Uses public-private key credentials and signed challenges so a user can authenticate without sending a reusable password.
Simplified protocol
The public patent describes a device-aware registration and authentication sequence. This diagram simplifies the core logic for a general audience.
The authorization request is signed so the backend can verify it came from an authentic OpenID client.
The protocol identifies whether the request comes from a web browser or a supported native mobile client.
A create request provisions a passkey; an existing user instead receives a security challenge for authentication.
The signed challenge is checked with the stored public key before an authentication token initiates a secure session.
Security principles
The patented approach combines standard protocols with device-native authentication capabilities to reduce reliance on reusable credentials.
Passkeys rely on asymmetric cryptography rather than a password that must be repeatedly transmitted or remembered.
The flow distinguishes web and native mobile clients so each can use the appropriate passkey registration and login mechanism.
Signed request parameters and challenge verification help the server establish that requests and responses are genuine.
The granted patent reflects Amwal's investment in proprietary authentication technology that can strengthen device and user identity flows within secure financial experiences.
Read U.S. Patent 12,388,646 B2This page is a simplified, non-legal overview. The issued patent and its claims are the authoritative source for the invention's legal scope.