US2021226941A1PendingUtilityA1
System and method for electronic credentials
Assignee: CORT BUSINESS SERVICES CORPPriority: Aug 16, 2012Filed: Apr 5, 2021Published: Jul 22, 2021
Est. expiryAug 16, 2032(~6 yrs left)· nominal 20-yr term from priority
Inventors:Himalesh Cherukuvada Kumar
H04L 63/0823G06F 21/33H04W 12/068H04W 12/069H04L 9/3226H04L 63/0884G06Q 20/425G06Q 20/4012G06Q 20/4014G06Q 20/3821G06Q 20/322G06Q 20/20G06F 2221/2115G06Q 20/12G06F 21/31H04L 63/08G06F 21/44H04L 63/105H04L 63/083
50
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
The present disclosure describes systems and methods directed towards a highly secure and intelligent, end to end provisioning, authentication, and transaction system which creates and/or consolidates user data for a unified profile for the user (e.g., a person, place, organization, object, etc.) to allow for the safe, secure, and verifiable exchange of information.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method of provisioning a credential authentication system, the method comprising:
wirelessly conveying first data from a data device of a user to an authentication server via a third party device, the first data comprising a user identifier, a confidential data item of the user, and a request to process the confidential data item, wherein the third party device automatically connects to the data device of the user using Bluetooth when the user enters one of predetermined physical locations, and collects and forwards the first data using Bluetooth; at the authentication server, initiating a session with the data device of the user and processing the first data that comprises the confidential data item to determine that a security protocol is associated with the confidential data item and determine that the request is a storage request; at the authentication server, generating second data, wherein the second data is a result of operating on the confidential data item with a one-way function; based on the determined security protocol and the determined storage request, storing the confidential data item and the second data in a user profile at a database, wherein the user profile is associated with a universal electronic identifier and comprises heterogeneous types of confidential data of the user; and terminating the initiated session in accordance with an expiration factor associated with the confidential data item and the second data, wherein the expiration factor is selected from the group consisting of: a clock time, a number of requests to access either the confidential data or the second data, and combinations thereof.
2 . The method of claim 1 , further comprising:
at the authentication server, generating third data, wherein the third data is a result of operating on the confidential data item and the user identifier with a one-way function; and storing the third data in the user profile at the database.
3 . The method of claim 1 , further comprising:
based on receipt of the user identifier at the authentication server, transmitting an acknowledgement message from the authentication server to the data device of the user via the third party device, wherein the acknowledgement message provides a notification that the authentication system has been provisioned for secure storage of the confidential data item.
4 . The method of claim 1 , wherein the first data further includes a unique transaction identifier corresponding to the request to process the confidential data item.
5 . The method of claim 1 , further comprising:
transmitting an authentication request to the data device of the user, wherein the authentication request prompts the user to send an authentication message from the data device of the user to the authentication server.
6 . The method of claim 5 , further comprising:
upon receipt of the authentication message from the data device of the user, transmitting, the confidential data item from the authentication server to a third party database that is separate from the authentication server.
7 . The method of claim 6 , wherein:
the first data further comprises a provisioning request; and the confidential data item is transmitted from the authentication server to the third party database based on the provisioning request.
8 . The method of claim 1 , further comprising:
transmitting a provisioning request to the authentication server from a second party data device, wherein the provisioning request includes the user identifier and the second party data device identification; and verifying at the authentication server the user identifier and the second party data device identification.
9 . The method of claim 8 , further comprising:
retrieving a confidential data item from the authentication server based on the verification of the user identifier, the verification of the second party data device identification, and the provisioning request; and transmitting the retrieved confidential data item from the authentication server to a third party database based on the provisioning request.
10 . The method of claim 8 , further comprising:
transmitting an authentication request to the data device of the user, wherein the authentication request prompts the user to send an authentication message from the data device of the user to the authentication server; retrieving a confidential data item from the authentication server based on the verification of the user identifier, the verification of the second party data device identification, the receipt of the authentication message, and the provisioning request; and transmitting the retrieved confidential data item from the authentication server to a third party database based on the provisioning request.
11 . A method of provisioning a credential authentication system, the method comprising:
providing first data to an authentication server, the first data comprising a user identifier associated with a user, a confidential data item of the user, a device identifier associated with a first device, and a request to process the confidential data item; at the authentication server, initiating a session with the first device and processing the first data that comprises the confidential data item to determine that a security protocol is associated with the confidential data item and determine that the request is a storage request; at the authentication server, generating second data and third data, wherein the second data is a result of operating on the confidential data item with a one-way function, and the third data is a result of operating on the confidential data item and the user identifier with a one-way function; verifying that the device identifier is associated with an account of the user, wherein the account is stored in a database at the authentication server; based on the determined security protocol, the determined storage request, and the verified device identifier, storing the confidential data item, the second data, and the third data in a user profile at the database, wherein the user profile is associated with a universal electronic identifier and comprises heterogeneous types of confidential data of the user; and terminating the initiated session in accordance with an expiration factor associated with at least one of the confidential data item, the second data, and the third data, wherein the expiration factor is selected from the group consisting of: a clock time, a number of requests to access either the confidential data, the second data, or the third data, and combinations thereof.
12 . The method of claim 11 , wherein said providing the first data to the authentication server comprises wirelessly conveying the first data from the first device to the authentication server.
13 . The method of claim 11 , wherein said providing the first data to the authentication server includes:
receiving the confidential data item via manual input from the user at the first device; and transmitting the confidential data item from the first device to the authentication server.
14 . The method of claim 11 , further comprising:
based on receipt of the user identifier at the authentication server, displaying a notification that the authentication system has been provisioned for secure storage of the confidential data item.
15 . The method of claim 11 , further comprising:
transmitting an authentication request to the first device associated with the user, wherein the authentication request prompts the user to send an authentication message from the first device to the authentication server.
16 . The method of claim 15 , further comprising:
upon receipt of the authentication message from the first device, transmitting, the confidential data item from the authentication server to a third party database that is separate from the authentication server.
17 . The method of claim 16 , wherein:
the first data further comprises a provisioning request; and the confidential data item is transmitted from the authentication server to the third party database based on the provisioning request.
18 . The method of claim 11 , further comprising:
transmitting a provisioning request to the authentication server from a second party data device, wherein the provisioning request includes the user identifier and the second party data device identification; and verifying at the authentication server the user identifier and the second party data device identification.
19 . The method of claim 18 , further comprising:
retrieving a confidential data item from the authentication server based on the verification of the user identifier, the verification of the second party data device identification, and the provisioning request; and transmitting the retrieved confidential data item from the authentication server to a third party database based on the provisioning request.
20 . The method of claim 18 , further comprising:
transmitting an authentication request to the first device of the user, wherein the authentication request prompts the user to send an authentication message from the first device of the user to the authentication server; retrieving a confidential data item from the authentication server based on the verification of the user identifier, the verification of the second party data device identification, the receipt of the authentication message, and the provisioning request; and transmitting the retrieved confidential data item from the authentication server to a third party database based on the provisioning request.
21 . A method of provisioning a credential authentication system, the method comprising:
receiving an activation code at a first device via manual entry by a user; transmitting first data from the first device to an authentication server, the first data comprising the activation code, a user identifier associated with the user, a confidential data item of the user, a device identifier associated with the first device, and a request to process the confidential data item; at the authentication server, initiating a session with the first device and processing the first data that comprises the confidential data item to determine that a security protocol is associated with the confidential data item and determine that the request is a storage request; at the authentication server, generating second data and third data, wherein the second data is a result of operating on the confidential data item with a one-way function, and the third data is a result of operating on the confidential data item and the user identifier with a one-way function; verifying that the activation code was previously issued for the user by an entity; based on the determined security protocol, the determined storage request, and the verified activation code, storing the confidential data item, the second data, and the third data in a user profile at the database, wherein the user profile is associated with a universal electronic identifier and comprises heterogeneous types of confidential data of the user; and terminating the initiated session in accordance with an expiration factor associated with at least one of the confidential data item, the second data, and the third data, wherein the expiration factor is selected from the group consisting of: a clock time, a number of requests to access either the confidential data, the second data, or the third data, and combinations thereof.
22 . The method of claim 21 , further comprising:
sending a success message to the first device to indicate successful provisioning of the confidential data item.
23 . The method of claim 21 , wherein the heterogeneous types of confidential data of the user comprise information from:
at least one physical identifier of the user; at least one non-physical identifier of the user; at least one financial credential of the user; and at least one digital key utilized by the user to grant access.
24 . The method of claim 21 , further comprising:
transmitting an authentication request to the first device, wherein the authentication request prompts the user to send an authentication message from the first device to the authentication server; and upon receipt of the authentication message from the first device, transmitting, the confidential data item from the authentication server to a third party database that is separate from the authentication server.
25 . The method of claim 24 , wherein:
the first data further comprises a provisioning request; and the confidential data item is transmitted from the authentication server to the third party database based on the provisioning request.Join the waitlist — get patent alerts
Track US2021226941A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.