Managing a generation and delivery of digital identity documents
Abstract
An approach is provided for generating a digital identity document. The digital identity document, including private information, is generated for display by a predetermined device under a predetermined form in a context of encrypting specifically to the predetermined device. The generation of the digital identity document is performed by computers so that a first sub-set of the computers has access to the private information of the digital identity document and a second sub-set of the computers does not have access to the private information and the second sub-set of the computers includes a cloud service for scalability. The first sub-set of the computers is owned and controlled by an issuer party. The second sub-set of the computers is owned and controlled by a servicing party.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of generating a first digital identity document, the method comprising the step of:
generating, by a plurality of computers, the first digital identity document, including private information, for display by a first predetermined device under a predetermined form in a context of encrypting specifically to the first predetermined device, with the generation being performed in a manner such that:
a first sub-set of the plurality of computers, which is owned and controlled by an issuer party, has access to the private information of the first digital identity document, and
a second sub-set of the plurality of computers, which is owned and controlled by a servicing party, does not have access to the private information of the first digital identity document and includes a cloud service for scalability.
2 . The method of claim 1 , wherein the step of generating, by the plurality of computers, the first digital identity document includes the steps of:
receiving, by a first computer included in the first sub-set of the plurality of computers, a request to generate an initial digital identity document for the first predetermined device; generating, by the first computer, the initial digital identity document; encrypting, by the first computer, the initial digital identity document; storing, by the first computer, the encrypted initial digital identity document on a second computer included in the second sub-set of the plurality of computers; and storing, by the first computer, instructions for the initial digital identity document in a data repository coupled to the first computer.
3 . The method of claim 2 , further comprising the steps of:
receiving, by the first computer, a request to generate a second digital identity document for a second predetermined device which is different from the first predetermined device, the second digital identity document being a copy of the initial digital identity document; loading, by the first computer, the instructions for the initial digital identity document from the data repository; based on the loaded instructions, generating, by the first computer, the second digital identity document; encrypting, by the first computer, the second digital identity document; and storing, by the first computer, the second digital identity document on the second computer.
4 . The method of claim 3 , wherein the step of encrypting the second digital identity document includes encrypting the second digital identity document specifically to the second predetermined device but not to the first predetermined device.
5 . The method of claim 3 , further comprising the steps of based on the second predetermined device being different from the first predetermined device and the second digital identity document being the copy of the initial digital identity document, searching, by the first computer, the data repository for the instructions for the initial digital identity document, and in response to the step of searching, finding, by the first computer, the instructions for the initial digital identity document in the data repository, wherein the step of loading the instructions for the initial digital identity document is performed in response to the step of finding the instructions.
6 . The method of claim 1 , wherein the second sub-set of the plurality of computers stores and distributes an encrypted version of the first digital identity document to the predetermined device without unencrypting the encrypted version.
7 . The method of claim 1 , further comprising the step of receiving, by the second sub-set of the plurality of computers, a request from the predetermined device for the first digital identity document to be sent to the predetermined device, the request including information specifying the predetermined device, wherein an encryption of the first digital identity document by the first sub-set of the plurality of computers is based in part on the information specifying the predetermined device.
8 . The method of claim 1 , further comprising the step of:
providing at least one support service for at least one of creating, integrating, hosting, maintaining, and deploying computer-readable program code in the first computer, the program code being executed by a processor of the first computer to implement the step of generating the first digital identity document.
9 . A computer program product for generating a first digital identity document, the computer program product comprising a computer readable storage medium having computer readable program code stored on the computer readable storage medium, wherein the computer readable storage medium is not a transitory signal per se, the computer readable program code being executed by a central processing unit (CPU) of a computer system to cause the computer system to perform a method comprising the step of:
generating, by the computer system, the first digital identity document, including private information, for display by a first predetermined device under a predetermined form in a context of encrypting specifically to the first predetermined device, with the generation being performed in a manner such that:
a first sub-set of a plurality of computers in the computer system has access to the private information of the first digital identity document, the first sub-set being owned and controlled by an issuer party, and
a second sub-set of the plurality of computers does not have access to the private information of the first digital identity document and includes a cloud service for scalability, the second sub-set being owned and controlled by a servicing party.
10 . The computer program product of claim 9 , wherein the step of generating, by the computer system, the first digital identity document includes the steps of:
receiving, by a first computer included in the first sub-set of the plurality of computers, a request to generate an initial digital identity document for the first predetermined device; generating, by the first computer, the initial digital identity document; encrypting, by the first computer, the initial digital identity document; storing, by the first computer, the encrypted initial digital identity document on a second computer included in the second sub-set of the plurality of computers; and storing, by the first computer, instructions for the initial digital identity document in a data repository coupled to the first computer.
11 . The computer program product of claim 10 , wherein the method further comprises the steps of:
receiving, by the first computer, a request to generate a second digital identity document for a second predetermined device which is different from the first predetermined device, the second digital identity document being a copy of the initial digital identity document; loading, by the first computer, the instructions for the initial digital identity document from the data repository; based on the loaded instructions, generating, by the first computer, the second digital identity document; encrypting, by the first computer, the second digital identity document; and storing, by the first computer, the second digital identity document on the second computer.
12 . The computer program product of claim 11 , wherein the step of encrypting the second digital identity document includes encrypting the second digital identity document specifically to the second predetermined device but not to the first predetermined device.
13 . The computer program product of claim 11 , wherein the method further comprises the steps of based on the second predetermined device being different from the first predetermined device and the second digital identity document being the copy of the initial digital identity document, searching, by the first computer, the data repository for the instructions for the initial digital identity document, and in response to the step of searching, finding, by the first computer, the instructions for the initial digital identity document in the data repository, wherein the step of loading the instructions for the initial digital identity document is performed in response to the step of finding the instructions.
14 . The computer program product of claim 9 , wherein the second sub-set of the plurality of computers stores and distributes an encrypted version of the first digital identity document to the predetermined device without unencrypting the encrypted version.
15 . The computer program product of claim 9 , wherein the method further comprises the step of receiving, by the second sub-set of the plurality of computers, a request from the predetermined device for the first digital identity document to be sent to the predetermined device, the request including information specifying the predetermined device, wherein an encryption of the first digital identity document by the first sub-set of the plurality of computers is based in part on the information specifying the predetermined device.
16 . A computer system comprising:
a central processing unit (CPU); a memory coupled to the CPU; and a computer readable storage medium coupled to the CPU, the computer readable storage medium containing instructions that are executed by the CPU via the memory to implement a method of generating a first digital identity document, the method comprising the steps of:
generating, by the computer system, the first digital identity document, including private information, for display by a first predetermined device under a predetermined form in a context of encrypting specifically to the first predetermined device, with the generation being performed in a manner such that:
a first sub-set of a plurality of computers in the computer system, which is owned and controlled by an issuer party, has access to the private information of the first digital identity document, and
a second sub-set of the plurality of computers, which is owned and controlled by a servicing party, does not have access to the private information of the first digital identity document and includes a cloud service for scalability.
17 . The computer system of claim 16 , wherein the step of generating, by the computer system, the first digital identity document includes the steps of:
receiving, by a first computer included in the first sub-set of the plurality of computers, a request to generate an initial digital identity document for the first predetermined device; generating, by the first computer, the initial digital identity document; encrypting, by the first computer, the initial digital identity document; storing, by the first computer, the encrypted initial digital identity document on a second computer included in the second sub-set of the plurality of computers; and storing, by the first computer, instructions for the initial digital identity document in a data repository coupled to the first computer.
18 . The computer system of claim 17 , wherein the method further comprises the steps of:
receiving, by the first computer, a request to generate a second digital identity document for a second predetermined device which is different from the first predetermined device, the second digital identity document being a copy of the initial digital identity document; loading, by the first computer, the instructions for the initial digital identity document from the data repository; based on the loaded instructions, generating, by the first computer, the second digital identity document; encrypting, by the first computer, the second digital identity document; and storing, by the first computer, the second digital identity document on the second computer.
19 . The computer system of claim 18 , wherein the step of encrypting the second digital identity document includes encrypting the second digital identity document specifically to the second predetermined device but not to the first predetermined device.
20 . The computer system of claim 18 , wherein the method further comprises the steps of based on the second predetermined device being different from the first predetermined device and the second digital identity document being the copy of the initial digital identity document, searching, by the first computer, the data repository for the instructions for the initial digital identity document, and in response to the step of searching, finding, by the first computer, the instructions for the initial digital identity document in the data repository, wherein the step of loading the instructions for the initial digital identity document is performed in response to the step of finding the instructions.Join the waitlist — get patent alerts
Track US2019075018A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.