Identity Vault Service
Abstract
Concepts and technologies are disclosed for an identity vault service. According to one aspect disclosed herein, an identity vault service system can collect self-attested and operator-attested user information. The operator-attested user information can be associated with a user and a mobile telecommunications service provided to the user by a mobile network operator. The system can create a trusted digital identity of the user based upon the self-attested and operator-attested user information. The system can receive an identity access request from a third party. The request can be for access to at least a portion of the trusted digital identity for use by the third party in performance of an act. The system can send a consent request to a user device and can receive a consent response that indicates whether the user permits access to at least the portion of the trusted digital identity of the user.
Claims
exact text as granted — not AI-modified1 . A method comprising:
collecting, by an identity vault service system comprising a processor, self-attested user information provided by a user, wherein the identify vault service system is associated with a mobile network operator; collecting, by the identity vault service system, operator-attested user information provided by the mobile network operator, wherein the operator-attested user information is associated with the user; creating, by the identity vault service system, a trusted digital identity of the user based upon the self-attested user information and the operator-attested user information; receiving, by the identity vault service system, an identity access request from a third party, wherein the identity access request is for access to at least a first portion of the trusted digital identity for use by the third party in performance of an act; in response to the identity access request, determining, by the identity vault service system, whether to allow access to at least the first portion of the trusted digital identity of the user; determining, by the identity vault service system, an anomaly associated with a second portion of the trusted digital identity of the user; and in response to determining the anomaly, denying, by the identity vault service system, access to the second portion of the trusted digital identity of the user determined to be associated with the anomaly.
2 . The method of claim 1 , wherein the self-attested user information is provided by the user for the mobile network operator to provide an identity vault service to the user.
3 . The method of claim 1 , wherein the operator-attested user information comprises a location of a user device associated with the user within a mobile telecommunications network.
4 . The method of claim 3 , wherein the location is part of a movement behavior model of the user as the user moves through the mobile telecommunications network over time.
5 . The method of claim 1 , wherein the operator-attested user information comprises a device type or a change from the device type to a new device type.
6 . The method of claim 1 , wherein determining, by the identity vault service system, whether to allow access to at least the first portion of the trusted digital identity of the user comprises:
generating, by the identity vault service system, a consent request directed to the user; sending, by the identity vault service system, the consent request to a user device associated with the user; and receiving, by the identity vault service system, a consent response from the user device associated with the user, wherein the consent response indicates whether the user permits access to at least the first portion of the trusted digital identity of the user.
7 . The method of claim 1 , wherein the act comprises a commerce act, an authorization act, an authentication act, or an identification act.
8 . The method of claim 1 , further comprising adding an entry into a distributed ledger protected by a blockchain, wherein the entry identifies the third party to the user, when the third party made the identity access request, and for what reason the third party made the identity access request.
9 . A computer-readable storage medium comprising computer-executable instructions that, when executed by a processor of an identity vault service system, cause the processor to perform operations comprising:
collecting self-attested user information provided by a user, wherein the identify vault service system is associated with a mobile network operator; collecting operator-attested user information provided by the mobile network operator, wherein the operator-attested user information is associated with the user; creating a trusted digital identity of the user based upon the self-attested user information and the operator-attested user information; receiving an identity access request from a third party, wherein the identity access request is for access to at least a first portion of the trusted digital identity for use by the third party in performance of an act; in response to the identity access request, determining whether to allow access to at least the first portion of the trusted digital identity of the user; determining an anomaly associated with a second portion of the trusted digital identity of the user; and in response to determining the anomaly, denying access to the second portion of the trusted digital identity of the user determined to be associated with the anomaly.
10 . The computer-readable storage medium of claim 9 , wherein the self-attested user information is provided by the user for the mobile network operator to provide an identity vault service to the user.
11 . The computer-readable storage medium of claim 9 , wherein the operator-attested user information comprises a location of a user device associated with the user within a mobile telecommunications network.
12 . The computer-readable storage medium of claim 11 , wherein the location is part of a movement behavior model of the user as the user moves through the mobile telecommunications network over time.
13 . The computer-readable storage medium of claim 9 , wherein the operator-attested user information comprises a device type or a change from the device type to a new device type.
14 . The computer-readable storage medium of claim 9 , wherein determining whether to allow access to at least the first portion of the trusted digital identity of the user comprises:
generating a consent request directed to the user; sending the consent request to a user device associated with the user; and receiving a consent response from the user device associated with the user, wherein the consent response indicates whether the user permits access to at least the first portion of the trusted digital identity of the user.
15 . The computer-readable storage medium of claim 9 , wherein the act comprises a commerce act, an authorization act, an authentication act, or an identification act.
16 . The computer-readable storage medium of claim 9 , wherein the operations further comprise adding an entry into a distributed ledger protected by a blockchain, wherein the entry identifies the third party to the user, when the third party made the identity access request, and for what reason the third party made the identity access request.
17 . An identity vault service system comprising:
a processor; and a memory comprising computer-executable instructions that, when executed by the processor, cause the processor to perform operations comprising
collecting self-attested user information provided by a user, wherein the identify vault service system is associated with a mobile network operator,
collecting operator-attested user information provided by the mobile network operator, wherein the operator-attested user information is associated with the user,
creating a trusted digital identity of the user based upon the self-attested user information and the operator-attested user information,
receiving an identity access request from a third party, wherein the identity access request is for access to at least a first portion of the trusted digital identity for use by the third party in performance of an act,
in response to the identity access request, determining whether to allow access to at least the first portion of the trusted digital identity of the user,
determining an anomaly associated with a second portion of the trusted digital identity of the user, and
in response to determining the anomaly, denying access to the second portion of the trusted digital identity of the user determined to be associated with the anomaly.
18 . The identity vault service system of claim 17 , wherein the operator-attested user information comprises a location of a user device associated with the user within a mobile telecommunications network, and wherein the location is part of a movement behavior model of the user as the user moves through the mobile telecommunications network over time.
19 . The identity vault service system of claim 17 , wherein the operator-attested user information comprises a device type or a change from the device type to a new device type.
20 . The identity vault service system of claim 17 , wherein determining whether to allow access to at least the first portion of the trusted digital identity of the user comprises:
generating a consent request directed to the user; sending the consent request to a user device associated with the user; and receiving a consent response from the user device associated with the user, wherein the consent response indicates whether the user permits access to at least the first portion of the trusted digital identity of the user.Join the waitlist — get patent alerts
Track US2022294785A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.