US2023246840A1PendingUtilityA1

Systems and methods for managing user identities in networks

Assignee: MASTERCARD INTERNATIONAL INCPriority: Jul 10, 2019Filed: Apr 5, 2023Published: Aug 3, 2023
Est. expiryJul 10, 2039(~12.9 yrs left)· nominal 20-yr term from priority
H04L 9/3231H04L 63/0861H04L 9/3073G06F 9/54H04L 9/0861H04L 9/0894H04L 9/3247H04L 63/126H04L 2463/102H04W 12/06H04W 12/108
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided for managing user identities in networks. One example method includes receiving, at a communication device, a request from a relying party for an assertion of an identity of a user where the communication device includes a software development kit (SDK). The method also includes, after receiving the request for the assertion, authenticating, by the communication device, the user and, based on a successful authentication of the user, compiling, via the SDK, an assertion packet including an attestation regarding authentication of the user where the assertion packet is signed with a private key of a private-public key pair stored in a memory of the communication device. The method then includes transmitting the assertion packet to the relying party.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method for use in managing user identities, the method comprising:
 receiving, at a communication device, a request from a relying party for an assertion of an identity of a user, the communication device including a software development kit (SDK), the user associated with the communication device;   after receiving the request for the assertion, authenticating, by the communication device, the user;   based on a successful authentication of the user, compiling, by the communication device, via the SDK, an assertion packet including an attestation regarding authentication of the user, wherein the assertion packet is signed with a private key of a private-public key pair stored in a memory of the communication device; and   transmitting the assertion packet to the relying party, whereby the assertion packet permits the relying party of verify the identity of the user.   
     
     
         2 . The computer-implemented method of  claim 1 , wherein the request includes an application programing interface (API) call request. 
     
     
         3 . The computer-implemented method of  claim 1 , wherein the request includes a phone number associated with the communication device; and
 wherein the assertion packet further includes identity data indicative of the identity of the user.   
     
     
         4 . The computer-implemented method of  claim 3 , wherein the identity data includes at least a name and an address associated with the user; and
 wherein the request for the assertion includes an identifier of the user.   
     
     
         5 . The computer-implemented method of  claim 1 , wherein authenticating the user includes:
 soliciting, by the communication device, a biometric from the user;   capturing, by the communication device, the biometric of the user; and   matching, by the communication device, the captured biometric to a reference biometric associated with the user; and   wherein the successful authentication includes the captured biometric matching the reference biometric.   
     
     
         6 . The computer-implemented method of  claim 5 , wherein the biometric includes one of a fingerprint of the user and a voiceprint of the user. 
     
     
         7 . The computer-implemented method of  claim 1 , further comprising, prior to receiving the request from the relying party: generating, by the communication device, via the SDK, the private-public key pair;
 compiling, by the communication device, via the SDK, a credential packet including a public key of the private-public key pair and identity data associated with the user; and   transmitting the credential packet to the relying party, whereby the relying party is registered to the SDK to request assertions from the SDK of the identity of the user.   
     
     
         8 . The computer-implemented method of  claim 7 , further comprising storing the private key in a trusted execution environment (TEE) of the communication device; and
 singing the assertion packet with the private key from the TEE of the communication device.   
     
     
         9 . The computer-implemented method of  claim 1 , wherein the communication device includes an application, which incorporates the SDK. 
     
     
         10 . The computer-implemented method of  claim 9 , wherein the application includes a banking application associated with a banking institution;
 wherein the user is associated with an account issued by the banking institution, whereby the application is usable to access information about the account; and   wherein the relying party is different than the banking institution.   
     
     
         11 . A non-transitory computer-readable storage medium including executable instructions for a software development kit (SDK) for managing a digital identity of a user, which when executed by at least one processor of a communication device, cause the at least one processor to:
 receive a request from a relying party for an assertion of an identity of the user, the communication device including the SDK, the user associated with the communication device;   after receiving the request for the assertion, authenticate the user;   based on a successful authentication of the user, compile an assertion packet including attestation regarding authentication of the user, wherein the assertion packet is signed with a private key of a private-public key pair stored in a memory of the communication device; and   transmitting the assertion packet to the relying party, whereby the assertion packet permits the relying party of verify the identity of the user.   
     
     
         12 . The non-transitory computer-readable storage medium of  claim 11 , wherein the request includes an application programing interface (API) call request. 
     
     
         13 . The non-transitory computer-readable storage medium of  claim 11 , wherein the request includes a phone number associated with the communication device; and
 wherein the assertion packet further includes identity data indicative of the identity associated with the user.   
     
     
         14 . The non-transitory computer-readable storage medium of  claim 13 , wherein the identity data includes at least a name and an address associated with the user; and
 wherein the request for the assertion includes an identifier of the user.   
     
     
         15 . The non-transitory computer-readable storage medium of  claim 11 , wherein the executable instructions, when executed by the at least one processor of the communication device, cause the at least one processor, in authenticating the user, to:
 solicit a biometric from the user; and   verify a biometric for the user, captured by the communication device, against a reference biometric associated with the user.   
     
     
         16 . The non-transitory computer-readable storage medium of  claim 15 , wherein the biometric includes one of a fingerprint of the user and a voiceprint of the user. 
     
     
         17 . The non-transitory computer-readable storage medium of  claim 11 , wherein the executable instructions, when executed by the at least one processor of the communication device, cause the at least one processor to, prior to receiving the request from the relying party:
 generate the private-public key pair;   compile a credential packet including a public key of the private-public key pair and identity data associated with the user; and   transmit the credential packet to the relying party, whereby the relying party is registered to the SDK to request assertions from the SDK of the identity of the user.   
     
     
         18 . The non-transitory computer-readable storage medium of  claim 11 , wherein the SDK is part of an application. 
     
     
         19 . The non-transitory computer-readable storage medium of  claim 18 , wherein the application includes a banking application associated with a banking institution;
 wherein the user is associated with an account issued by the banking institution, whereby the application is usable to access information about the account; and   wherein the relying party is different than the banking institution.

Join the waitlist — get patent alerts

Track US2023246840A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.