U.S. Patent 12,388,646 B2

A patented security layer for passkey identity

Amwal's patented protocols extend OpenID security to support secure passkey registration and authentication across web browsers and native mobile applications.

View the published patent

Patent number

US 12,388,646 B2

Issued

August 12, 2025

Assignee

Amwal Tech Inc.

Inventor

Sameh Galal

The invention, briefly

Extending OpenID for secure passkey flows

The patent describes systems and methods that decide between secure passkey registration and authentication, verify that requests are genuine, adapt the flow to the client device, and issue an authentication token for a secure network session.

OpenID extension

Adds secure registration semantics to an OpenID authorization flow, including a create mode used to initiate passkey registration.

Web and native mobile

Detects the client platform and supports browser-based experiences as well as native mobile operating-system SDKs.

Passkey authentication

Uses public-private key credentials and signed challenges so a user can authenticate without sending a reusable password.

Simplified protocol

How the secure flow works

The public patent describes a device-aware registration and authentication sequence. This diagram simplifies the core logic for a general audience.

01

Secure the request

The authorization request is signed so the backend can verify it came from an authentic OpenID client.

02

Detect the device

The protocol identifies whether the request comes from a web browser or a supported native mobile client.

03

Register or invoke a passkey

A create request provisions a passkey; an existing user instead receives a security challenge for authentication.

04

Verify and open a session

The signed challenge is checked with the stored public key before an authentication token initiates a secure session.

Security principles

Designed around identity, device and proof

The patented approach combines standard protocols with device-native authentication capabilities to reduce reliance on reusable credentials.

Passwordless by design

Passkeys rely on asymmetric cryptography rather than a password that must be repeatedly transmitted or remembered.

Device-aware routing

The flow distinguishes web and native mobile clients so each can use the appropriate passkey registration and login mechanism.

Forge-resistant requests

Signed request parameters and challenge verification help the server establish that requests and responses are genuine.

Security infrastructure Amwal owns and advances

The granted patent reflects Amwal's investment in proprietary authentication technology that can strengthen device and user identity flows within secure financial experiences.

Read U.S. Patent 12,388,646 B2

This page is a simplified, non-legal overview. The issued patent and its claims are the authoritative source for the invention's legal scope.

Patented Passkey Authentication Security | Amwal Tech