IP Library Granted Patent US 12682350
Granted Patent B2
US 12682350 · App. 18/547,450 · Granted Jul 14, 2026

Identity conveyance systems

Inventors: Shlomit Azgad-Tromer (Miami, FL); Matthew Green (Miami, FL); Eran Tromer (Miami, FL)
Assignee: Sealance Corp.
G06Q20/4014G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12682350
App. No.
18/547,450
Filed
Aug 22, 2023
Granted
Jul 14, 2026
Kind
B2
Art Unit
3699
USPC
705/75
Abstract

A system configured to facilitate verification of a customer's identity to a financial service provider by issuing an identity assertion to the service provider is provided. The system comprises an identity provider configured to store customer information and to verify the customer's identity, and to generate the identity assertion asserting at least some of the information based on a request from the service provider, the assertion comprising an encrypted portion; and a customer identity manager associated with the customer and configured to communicate with the service provider and the identity provider to facilitate providing the assertion to the service provider. The system further comprises an identity summarization engine configured to reason over a customer record and a policy in order to selectively determine which information in the customer record is to be provided in the assertion to the service provider, and in what form.

Claims (46)

1 . A computer-based system comprising:

a processor; and

a memory with computer code instructions stored thereon, the processor and the memory, with the computer code instructions, being configured to cause the computer-based system to:

store information associated with a computing node;

verify an identity of the computing node;

generate an identity assertion, the identity assertion configured to assert at least a portion of the information associated with the computing node based on a request from a digital asset server, the identity assertion including an encrypted portion;

transform, using a zero-knowledge proof, an identity object associated with the computing node into a digital object, the digital object including a non-interactive proof, the non-interactive proof capable of being verified by the digital asset server to validate that the identity assertion correctly represents authenticated data in the identity object;

communicate with the digital asset server and an identity server to facilitate transmitting the identity assertion to the digital asset server;

reason over a data record and a policy to selectively determine one or more data fields in the data record to be provided in the identity assertion to the digital asset server, and a form of the one or more data fields;

transform at least one data field of the selectively determined one or more data fields into at least one cryptographic object and at least one cryptographic value;

configure a given cryptographic object of the at least one cryptographic object to preempt access to contents of a corresponding data field of the at least one data field, the given cryptographic object capable of being verified by the digital asset server based on (i) the given cryptographic object, (ii) a corresponding cryptographic value of the at least one cryptographic value, and (iii) the contents;

generate a digital signature based on the at least one cryptographic object; and

transmit the identity object and the at least one cryptographic value to the digital asset server, the identity object including the at least one cryptographic object and the digital signature.

2 . The computer-based system of claim 1 , wherein the processor and the memory, with the computer code instructions, are further configured to cause the computer-based system to:

generate a hash tree based on the at least one cryptographic object, the hash tree including at least one leaf node corresponding to the at least one cryptographic object; and

transmit at least a portion of the hash tree to the digital asset server.

3 . The computer-based system of claim 1 , wherein the processor and the memory, with the computer code instructions, are further configured to cause the computer-based system to:

define a request language defining (i) a common format for identity requests from digital asset servers and (ii) a common format for identity assertions issued to the digital asset servers.

4 . The computer-based system of claim 1 , wherein the processor and the memory, with the computer code instructions, are further configured to cause the computer-based system to:

determine that at least some of the one or more data fields are to be included in the identity assertion in a generalized form.

5 . The computer-based system of claim 1 , wherein the processor and the memory, with the computer code instructions, are further configured to cause the computer-based system to:

determine that at least some of the one or more data fields are to be included in the identity assertion in a combined form with other data fields from the data record.

6 . The computer-based system of claim 1 , wherein the processor and the memory, with the computer code instructions, are further configured to cause the computer-based system to:

determine, based on an identity of the digital asset server, that at least some of the one or more data fields are to be withheld.

7 . The computer-based system of claim 1 , wherein the processor and the memory, with the computer code instructions, are further configured to cause the computer-based system to:

issue the identity assertion directly to the digital asset server.

8 . The computer-based system of claim 1 , wherein the identity assertion is a first identity assertion, wherein the digital asset server is a first digital asset server, and wherein the processor and the memory, with the computer code instructions, are further configured to cause the computer-based system to:

receive a request from a second digital asset server to provide a second identity assertion; and

provide the second digital asset server with information identifying one or more identity servers from which a suitable identity assertion may be obtained.

9 . The computer-based system of claim 8 , wherein the information identifying the one or more identity servers includes a zero-knowledge proof identifying the one or more identity servers.

10 . The computer-based system of claim 1 , wherein the processor and the memory, with the computer code instructions, are further configured to cause the computer-based system to:

provide additional information, available to the computing node, to the digital asset server.

11 . The computer-based system of claim 10 , wherein the processor and the memory, with the computer code instructions, are further configured to cause the computer-based system to:

provide the additional information summarized using a zero-knowledge proof.

12 . The computer-based system of claim 1 , wherein the processor and the memory, with the computer code instructions, are further configured to cause the computer-based system to:

receive information from the digital asset server about a user; and

update the identity assertion in view thereof.

13 . The computer-based system of claim 12 , where, in updating the identity assertion, the processor and the memory, with the computer code instructions, are configured to cause the computer-based system to:

revoke at least a portion of the at least a portion of the information associated with the computing node.

14 . The computer-based system of claim 12 , where, in updating the identity assertion, the processor and the memory, with the computer code instructions, are configured to cause the computer-based system to:

publish a message to the digital asset server, the message indicating that the updated identity assertion is available.

15 . The computer-based system of claim 1 , wherein the identity assertion includes information configured to facilitate the digital asset server to report information associated with the computing node to an external system.

16 . The computer-based system of claim 15 , wherein the information associated with the computing node includes at least one of: (i) one or more authentication tokens and (ii) information identifying one or more locations for reporting the information associated with the computing node.

17 . The computer-based system of claim 1 , wherein the encrypted portion of the identity assertion implements a zero-knowledge proof.

18 . The computer-based system of claim 1 , wherein the identity assertion includes a non-encrypted portion.

19 . The computer-based system of claim 18 , wherein the encrypted portion includes cryptographic authentication data computed over at least some of the non-encrypted portion.