IP Library › Patent Application 14421005
Patent Application
App. No. 14/421,005

SYSTEM AND METHOD FOR ELECTRONIC CREDENTIALS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/421,005
Abstract

The present disclosure describes systems and methods directed towards a highly secure and intelligent, end to end provisioning, authentication, and transaction system which creates and/or consolidates user data for a unified profile for the user (e.g., a person, place, organization, object, etc.) to allow for the safe, secure, and verifiable exchange of information.

Claims (84)

1 . A method of provisioning an authentication system, the method comprising:

wirelessly conveying first data from at least one data device of a first party to an authentication server, the first data including a first party identifier, a confidential data item of a second party, and a request to process the confidential data item;

at the authentication server, processing the first data to determine that a security protocol is associated with the confidential data item and determine that the request is a storage request;

at the authentication server, generating second data, wherein the second data is a result of operating on the confidential data item with a one-way function; and

based on the determined security protocol and the determined storage request, storing the confidential data item and the second data at a database.

2 . The method of claim 1 , wherein the confidential data item is generated at one of the data devices of the first party.

3 . The method of claim 1 , further comprising:

determining, based on the first data, that a digital certificate is to be issued;

requesting issuance of a digital certificate based on at least the confidential data item;

receiving the digital certificate; and

storing the digital certificate at the database.

4 . The method of claim 3 , wherein the digital certificate is generated by operating on issuer data, the confidential data item, a timestamp, and an indication of whether the first party or the second party requested the issuance of the digital certificate with a one-way function.

5 . The method of claim 1 , further comprising:

determining, based on the first data, that a digital certificate is to be created;

creating a digital certificate based on at least the confidential data item; and

storing the digital certificate at the database.

6 . The method of claim 5 , further comprising:

transmitting a second party identifier from the at least one data device of the first party to the authentication server; and

based on receipt of the second party identifier, sending an acknowledgement message from the authentication server to a data device of the second party, wherein the acknowledgement message provides a notification that the authentication system has been provisioned for secure storage of the confidential data item.

7 . The method of claim 1 , wherein said processing the first data includes comparing the confidential data item against a predetermined list of data items.

8 . The method of claim 1 , wherein the confidential data item and the second data are stored in a second party profile at the database.

9 . The method of claim 8 , further comprising:

transmitting a second party identifier from the at least one data device of the first party to the authentication server;

at the authentication server, generating third data, wherein the third data is a result of operating on the confidential data item and the second party identifier with a one-way function; and

storing the third data in the second party profile at the database.

10 . The method of claim 9 , wherein second party profile includes a data table indexed by the second party identifier.

11 . The method of claim 1 , wherein the confidential data item and the second data are stored in a first party profile at the database.

12 . The method of claim 11 , wherein the first party profile includes a data table indexed by the first party identifier.

13 . The method of claim 1 , further comprising sending a first acknowledgement message from the authentication server to one of the data devices of the first party, wherein the first acknowledgement message provides a notification that the authentication system has been provisioned for secure storage of the confidential data item.

14 . The method of claim 13 , further comprising:

transmitting a second party identifier from the at least one data device of the first party to the authentication server; and

based on receipt of the second party identifier, sending a second acknowledgement message from the authentication server to a data device of the second party, wherein the second acknowledgement message provides a notification that the authentication system has been provisioned for secure storage of the confidential data item.

15 . The method of claim 1 , further comprising:

transmitting a provisioning request to the authentication server from a data device of the second party;

retrieving a confidential data item from the authentication server based on the provisioning request; and

transmitting the confidential data item from the authentication server to a third party database based on the provisioning request.

16 . The method of claim 1 , further comprising:

transmitting a provisioning request to the authentication server from a data device of the second party;

retrieving a confidential data item from the authentication server based on the provisioning request;

transmitting an authentication request to the data device of the second party, wherein the authentication request prompts the second party to send an authentication message from the data device of the second party to the authentication server; and

upon receipt of the authentication message from the data device of the second party, transmitting the confidential data item from the authentication server to a third party database based on the provisioning request.

17 . The method of claim 1 , further comprising:

transmitting a provisioning request to the authentication server from a third party's data device, wherein the provisioning request includes a second party identifier and a third party data device identification;

verifying at the authentication server the second party identifier and the third party data device identification;

retrieving a confidential data item from the authentication server based on the verification of the second party identifier, the verification of the third party data device identification, and the provisioning request; and

transmitting the confidential data item from the authentication server to a third party database based on the provisioning request.

18 . The method of claim 1 , further comprising:

transmitting a provisioning request to the authentication server from a data device of a third party, wherein the provisioning request includes a second party identifier and a third party data device identification;

verifying at the authentication server the second party identifier and the third party data device identification;

transmitting an authentication request to a data device of the second party, wherein the authentication request prompts the second party to send an authentication message from the data device of the second party to the authentication server;

retrieving a confidential data item from the authentication server based on the verification of the second party identifier, the verification of the third party data device identification, the receipt of the authentication message, and the provisioning request; and

transmitting the confidential data item from the authentication server to a third party database based on the provisioning request.

19 . A method of provisioning an authentication system, the method comprising:

wirelessly conveying first data from a data device of a user to an authentication server, the first data including a user identifier, a confidential data item of the user, and a request to process the confidential data item;

at the authentication server, processing the first data to determine that a security protocol is associated with the confidential data item and determine that the request is a storage request;

at the authentication server, generating second data, wherein the second data is a result of operating on the confidential data item with a one-way function; and

based on the determined security protocol and the determined storage request, storing the confidential data item and the second data in a user profile at a database.

20 . The method of claim 19 , further comprising:

at the authentication server, generating third data, wherein the third data is a result of operating on the confidential data item and the user identifier with a one-way function; and

storing the third data in the user profile at the database.

21 . The method of claim 19 , further comprising:

based on receipt of the user identifier at the authentication server, transmitting an acknowledgement message from the authentication server to the data device of the user, wherein the acknowledgement message provides a notification that the authentication system has been provisioned for secure storage of the confidential data item.

22 . The method of claim 19 , wherein the first data further includes a unique transaction identifier corresponding to the request to process the confidential data item.

23 . A method of provisioning an authentication system, the method comprising:

providing first data to an authentication server, the first data including a user identifier associated with a user, a confidential data item of the user, a device identifier associated with a first device, and a request to process the confidential data item;

at the authentication server, processing the first data to determine that a security protocol is associated with the confidential data item and determine that the request is a storage request;

at the authentication server, generating second data and third data, wherein the second data is a result of operating on the confidential data item with a one-way function, and the third data is a result of operating on the confidential data item and the user identifier with a one-way function;

verifying that the device identifier is associated with an account of the user, wherein the account is stored in a database at the authentication server; and

based on the determined security protocol, the determined storage request, and the verified device identifier, storing the confidential data item, the second data, and the third data in a user profile at the database.

24 . The method of claim 23 , wherein said providing the first data to the authentication server comprises wirelessly conveying the first data from the first device to the authentication server.

25 . The method of claim 23 , wherein said providing the first data to the authentication server includes:

receiving the confidential data item via manual input from the user at the first device; and

transmitting the confidential data item from the second device to the authentication server.

26 . The method of claim 23 , further comprising:

based on receipt of the user identifier at the authentication server, displaying a notification that the authentication system has been provisioned for secure storage of the confidential data item.

27 . A method of provisioning an authentication system, the method comprising:

receiving an activation code at a first device via manual entry by a user;

transmitting first data from the first device to an authentication server, the first data including the activation code, a user identifier associated with the user, a confidential data item of the user, a device identifier associated with the first device, and a request to process the confidential data item;

at the authentication server, processing the first data to determine that a security protocol is associated with the confidential data item and determine that the request is a storage request;

at the authentication server, generating second data and third data, wherein the second data is a result of operating on the confidential data item with a one-way function, and the third data is a result of operating on the confidential data item and the user identifier with a one-way function;

verifying that the activation code was previously issued for the user by an entity; and

based on the determined security protocol, the determined storage request, and the verified activation code, storing the confidential data item, the second data, and the third data in a user profile at the database.

28 . The method of claim 27 , further comprising:

sending a success message to the first device to indicate successful provisioning of the confidential data item.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2020
From: KUMAR, HIMALESH CHERUKUVADA
To: CORT
Reel/Frame 052088/0135 →