Systems and methods for managing user identities in networks
Abstract
Systems and methods are provided for managing user identities in networks. One example method includes receiving, at a communication device, a request from a relying party for an assertion of an identity of a user where the communication device includes a software development kit (SDK). The method also includes, after receiving the request for the assertion, authenticating, by the communication device, the user and, based on a successful authentication of the user, compiling, via the SDK, an assertion packet including an attestation regarding authentication of the user where the assertion packet is signed with a private key of a private-public key pair stored in a memory of the communication device. The method then includes transmitting the assertion packet to the relying party.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method for use in managing user identities, the method comprising:
receiving, at a communication device, a request from a relying party for an assertion of an identity of a user, the communication device including a software development kit (SDK), the user associated with the communication device; after receiving the request for the assertion, authenticating, by the communication device, the user; based on a successful authentication of the user, compiling, by the communication device, via the SDK, an assertion packet including an attestation regarding authentication of the user, wherein the assertion packet is signed with a private key of a private-public key pair stored in a memory of the communication device; and transmitting the assertion packet to the relying party, whereby the assertion packet permits the relying party of verify the identity of the user.
2 . The computer-implemented method of claim 1 , wherein the request includes an application programing interface (API) call request.
3 . The computer-implemented method of claim 1 , wherein the request includes a phone number associated with the communication device; and
wherein the assertion packet further includes identity data indicative of the identity of the user.
4 . The computer-implemented method of claim 3 , wherein the identity data includes at least a name and an address associated with the user; and
wherein the request for the assertion includes an identifier of the user.
5 . The computer-implemented method of claim 1 , wherein authenticating the user includes:
soliciting, by the communication device, a biometric from the user; capturing, by the communication device, the biometric of the user; and matching, by the communication device, the captured biometric to a reference biometric associated with the user; and wherein the successful authentication includes the captured biometric matching the reference biometric.
6 . The computer-implemented method of claim 5 , wherein the biometric includes one of a fingerprint of the user and a voiceprint of the user.
7 . The computer-implemented method of claim 1 , further comprising, prior to receiving the request from the relying party: generating, by the communication device, via the SDK, the private-public key pair;
compiling, by the communication device, via the SDK, a credential packet including a public key of the private-public key pair and identity data associated with the user; and transmitting the credential packet to the relying party, whereby the relying party is registered to the SDK to request assertions from the SDK of the identity of the user.
8 . The computer-implemented method of claim 7 , further comprising storing the private key in a trusted execution environment (TEE) of the communication device; and
singing the assertion packet with the private key from the TEE of the communication device.
9 . The computer-implemented method of claim 1 , wherein the communication device includes an application, which incorporates the SDK.
10 . The computer-implemented method of claim 9 , wherein the application includes a banking application associated with a banking institution;
wherein the user is associated with an account issued by the banking institution, whereby the application is usable to access information about the account; and wherein the relying party is different than the banking institution.
11 . A non-transitory computer-readable storage medium including executable instructions for a software development kit (SDK) for managing a digital identity of a user, which when executed by at least one processor of a communication device, cause the at least one processor to:
receive a request from a relying party for an assertion of an identity of the user, the communication device including the SDK, the user associated with the communication device; after receiving the request for the assertion, authenticate the user; based on a successful authentication of the user, compile an assertion packet including attestation regarding authentication of the user, wherein the assertion packet is signed with a private key of a private-public key pair stored in a memory of the communication device; and transmitting the assertion packet to the relying party, whereby the assertion packet permits the relying party of verify the identity of the user.
12 . The non-transitory computer-readable storage medium of claim 11 , wherein the request includes an application programing interface (API) call request.
13 . The non-transitory computer-readable storage medium of claim 11 , wherein the request includes a phone number associated with the communication device; and
wherein the assertion packet further includes identity data indicative of the identity associated with the user.
14 . The non-transitory computer-readable storage medium of claim 13 , wherein the identity data includes at least a name and an address associated with the user; and
wherein the request for the assertion includes an identifier of the user.
15 . The non-transitory computer-readable storage medium of claim 11 , wherein the executable instructions, when executed by the at least one processor of the communication device, cause the at least one processor, in authenticating the user, to:
solicit a biometric from the user; and verify a biometric for the user, captured by the communication device, against a reference biometric associated with the user.
16 . The non-transitory computer-readable storage medium of claim 15 , wherein the biometric includes one of a fingerprint of the user and a voiceprint of the user.
17 . The non-transitory computer-readable storage medium of claim 11 , wherein the executable instructions, when executed by the at least one processor of the communication device, cause the at least one processor to, prior to receiving the request from the relying party:
generate the private-public key pair; compile a credential packet including a public key of the private-public key pair and identity data associated with the user; and transmit the credential packet to the relying party, whereby the relying party is registered to the SDK to request assertions from the SDK of the identity of the user.
18 . The non-transitory computer-readable storage medium of claim 11 , wherein the SDK is part of an application.
19 . The non-transitory computer-readable storage medium of claim 18 , wherein the application includes a banking application associated with a banking institution;
wherein the user is associated with an account issued by the banking institution, whereby the application is usable to access information about the account; and wherein the relying party is different than the banking institution.Join the waitlist — get patent alerts
Track US2023246840A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.