US2016352717A1PendingUtilityA1

Remote access of digital identities

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Jan 26, 2007Filed: Aug 10, 2016Published: Dec 1, 2016
Est. expiryJan 26, 2027(~0.5 yrs left)· nominal 20-yr term from priority
G06F 21/41H04L 63/08G06F 21/33H04L 63/0853
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for controlling distribution and use of digital identity representations (“DIRs”) increases security, usability, and oversight of DIR use. A DIR stored on a first device may be obtained by a second device for use in satisfying the security policy of a relying party. Release of the DIR to the second device requires permission from a device or entity that may be different from the device or entity attempting to access the relying party. Further, the use of the DIR to obtain an identity token may separately require permission of even a different person or entity and may be conditioned upon receiving satisfactory information relating to the intended use of the DIR (e.g., the name of the relying party, type of operation being attempted, etc.). By controlling the distribution and use of DIRs, security of the principal's identity and supervisory control over a principal's activities are enhanced.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A method for controlling distribution of a digital identity representation, comprising the steps of:
 receiving at a first device a request from a second device for the digital identity representation;   prompting a user of the first device to accept or deny the request;   providing, if the request is accepted by the user, the digital identity representation.   
     
     
         2 . The method of  claim 1 , wherein the digital identity representation is provided by a third device. 
     
     
         3 . The method of  claim 1 , wherein the digital identity representation includes metadata describing at least a first claim about a principal. 
     
     
         4 . The method of  claim 3 , wherein the digital identity representation further includes backing data comprising the first claim. 
     
     
         5 . The method of  claim 3 , wherein the principal is the user of the first device. 
     
     
         6 . The method of  claim 1 , wherein the first device includes a use limitation in the digital identity representation. 
     
     
         7 . The method of  claim 6 , wherein the use limitation comprises an expiration time for the digital identity representation. 
     
     
         8 . The method of  claim 7 , wherein the expiration time is based on a timestamp provided in the request by the second device. 
     
     
         9 . The method of  claim 1 , wherein, prior to the request, the digital identity representation is stored at the first device and includes internal address information pointing to an identity provider included in the first device, further comprising the step of:
 changing the internal address information to an externally accessible address of the first device.   
     
     
         10 . The method of  claim 1 , further comprising the steps of:
 receiving a second request to use the digital identity representation;   prompting the user of the first device to accept or deny the second request;   providing, if the second request is accepted by the user, permission to use the digital identity representation.   
     
     
         11 . A computer program product for use in a computer system, the computer program product comprising one or more computer readable media having computer-executable instructions for implementing a method for controlling use of a digital identity representation, the method comprising the steps of:
 receiving at a first device a request from a second device to use the digital identity representation;   prompting a user of the first device to accept or deny the request;   providing, if the request is accepted by the user, permission to use the digital identity representation.   
     
     
         12 . The computer program product of  claim 11 , wherein the digital identity representation includes metadata describing at least a first claim about a principal and the principal is not the user of the first machine. 
     
     
         13 . The computer program product of  claim 11 , wherein the digital identity representation includes a use restriction that is changeable by the user of the first device. 
     
     
         14 . The computer program product of  claim 13 , wherein the use restriction includes an address of a third device from which the permission to use the digital identity representation must be obtained. 
     
     
         15 . The computer program product of  claim 11 , wherein the method further comprises the steps of:
 requesting from the second device information related to the use of the digital identity representation.   
     
     
         16 . The computer program product of  claim 15 , wherein the second device requests use of the digital identity representation to obtain an identity token and the information includes identification of a relying party to whom the identity token is to be provided. 
     
     
         17 . A method of using a digital identity representation, comprising the steps of:
 receiving a request for an identity token from a relying party;   sending to a first device a request from a second device to obtain the digital identity representation;   receiving at the second device the digital identity representation, wherein the digital identity representation includes metadata describing at least a first claim about a principal;   sending from the second device a request to use the digital identity representation;   receiving at the second device permission to use the digital identity representation;   using the digital identity representation to request the identity token;   receiving the identity token; and   providing the identity token to the relying party.   
     
     
         18 . The method of  claim 17 , wherein the request to use the digital identity representation is sent to a third device that is different from the first and second devices. 
     
     
         19 . The method of  claim 17 , wherein the request to use the digital identity representation is sent to a device that is controlled by a person other than the principal. 
     
     
         20 . The method of  claim 17 , wherein the request to use the digital identity information includes information identifying the relying party.

Join the waitlist — get patent alerts

Track US2016352717A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.