US2021409221A1PendingUtilityA1

Portable Biometric Identity on a Distributed Data Storage Layer

Assignee: ACCENTURE GLOBAL SOLUTIONS LTDPriority: Jun 15, 2017Filed: Sep 13, 2021Published: Dec 30, 2021
Est. expiryJun 15, 2037(~10.9 yrs left)· nominal 20-yr term from priority
H04L 9/50H04L 9/3247H04L 67/10H04L 9/3231H04L 9/3239G06F 16/84H04L 63/102H04L 9/0861G06V 40/50H04L 9/3213H04L 2209/38G06K 9/00926
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A distributed data storage layer supports biometric identification systems. The biometric identity system includes hardware and software improvements for capturing, retrieving, and verifying identity based on securely stored biometric data in the distributed data storage layer. As a result, the biometric identity system provides increased individual security and reliable identification.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system comprising:
 a distributed ledger data storage layer comprising a first circuitry; and a service access node for accessing the distributed ledger data storage layer comprising a second circuitry,   wherein the first circuitry is configured to:
 provide a first permissioned access associated with a first higher access level to the service access node for storing an identifier of a digital identity in a linked chain of non-alterable data blocks in the distributed ledger data storages layer; and 
 provide a second permissioned access associated with a second lower access level to a served access node to authenticate the identifier of the digital identity with the linked chain of non-alterable data blocks in the distributed ledger data storages layer; and 
   wherein the second circuitry is configured to:
 provide the served access node an authentication of the digital identity associated with the authenticated identifier via communications offline with the distributed ledger data storage layer between a server associated with the service access node and a server associated with the served access node. 
   
     
     
         2 . The system of  claim 1 , wherein the second circuitry is configured to store the digital identity off the distributed ledger data storage layer in the server associated with the service access node. 
     
     
         3 . The system of  claim 2 , wherein the digital identity comprises a human biological identity. 
     
     
         4 . The system of  claim 3 , wherein the human biological identity comprises at least one of fingerprint, retina image, iris image, facial image, voice sample, DNA sequence, palm vein image, and palm print identity. 
     
     
         5 . The system of  claim 3 , wherein the human biological identity is captured by a service station associated with the service access node. 
     
     
         6 . The system of  claim 5 , wherein the second circuitry is configured to provide the served access node the authentication of the digital identity by comparing the human biological identity captured by the service station and another biological identity captured by the served access node. 
     
     
         7 . The system of  claim 1 , wherein the identifier of the digital identity comprises a token of an identification sequence generated using a one-way function from the digital identity and a public key associated with the digital identity. 
     
     
         8 . The system of  claim 7 , wherein the first circuitry is configured to provide the second permissioned access to the served access node to authenticate the identifier of the digital identity by:
 receiving the identifier from the served access node;   receiving a digital identity attestation digitally signed by the server associated with the service access node;   obtaining an index corresponding to the identifier received from the served access node;   requesting and receiving a second identifier from the distributed ledger data storage layer queried under the index; and   authenticate the identifier by verifying the digital identity attestation and based on a comparison of the identifier and the second identifier.   
     
     
         9 . The system of  claim 8 , wherein the served access node is configured to communicate with a mobile identity wallet presented by a holder to obtain the identifier and attestation. 
     
     
         10 . The system of  claim 9 , where the public key associated with the digital identity is generated by a mobile device hosting the mobile identity wallet. 
     
     
         11 . The system of  claim 10 , where the digital identity attestation generated and signed by the server associated with the service access node is further signed by the mobile device. 
     
     
         12 . A method comprising:
 providing a first permissioned access associated with a first higher access level to a service access node for storing an identifier of a digital identity in a linked chain of non-alterable data blocks in a distributed ledger data storages layer;   providing a second permissioned access associated with a second lower access level to a served access node to authenticate the identifier of the digital identity with the linked chain of non-alterable data blocks in the distributed ledger data storages layer; and   providing the served access node an authentication of the digital identity associated with the authenticated identifier via communications offline with the distributed ledger data storage layer between a server associated with the service access node and a server associated with the served access node.   
     
     
         13 . The method of  claim 12 , further comprising storing the digital identity off the distributed ledger data storage layer in the server associated with the service access node. 
     
     
         14 . The method of  claim 13 , wherein the digital identity comprises a human biological identity. 
     
     
         15 . The method of  claim 14 , wherein the human biological identity comprises at least one of fingerprint, retina image, iris image, facial image, voice sample, DNA sequence, palm vein image, and palm print identity. 
     
     
         16 . The method of  claim 14 , wherein the human biological identity is captured by a service station associated with the service access node. 
     
     
         17 . The method of  claim 16 , wherein providing the served access node the authentication of the digital identity comprises comparing the human biological identity captured by the service station and another biological identity captured by the served access node. 
     
     
         18 . The method of  claim 12 , wherein the identifier of the digital identity comprises a token of an identification sequence generated using a one-way function from the digital identity and a public key associated with the digital identity. 
     
     
         19 . The method of  claim 18 , wherein providing the second permissioned access to the served access node to authenticate the identifier of the digital identity comprises:
 receiving the identifier from the served access node;   receiving a digital identity attestation digitally signed by the server associated with the service access node;   obtaining an index corresponding to the identifier received from the served access node;   requesting and receiving a second identifier from the distributed ledger data storage layer queried under the index; and   authenticate the identifier by verifying the digital identity attestation and based on a comparison of the identifier and the second identifier.   
     
     
         20 . The method of  claim 19 , wherein the served access node is configured to communicate with a mobile identity wallet presented by a holder to obtain the identifier and attestation.

Join the waitlist — get patent alerts

Track US2021409221A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.