IP Library › Granted Patent US 9,954,854
Granted Patent B2
US 9,954,854 · App. 14/982,981 · Granted Apr 24, 2018

File format and platform for storage and verification of credentials

Inventor: Shaunt M. Sarkissian (Cambridge, MA)
Assignee: Cortex MCP Inc.
H04L63/083G06Q20/3274G06Q20/3821G06Q30/0251H04L63/08H04L63/0861H04L2463/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,954,854
App. No.
14/982,981
Granted
Apr 24, 2018
Kind
B2
Abstract

In various embodiments, a computer-implemented method for generating and verifying officially verifiable electronic representations may be disclosed. The method may comprise receiving, by a credential database, a request for a credential action. The credential database may be configured to store one or more credentials comprising a status indicator. The method may further comprise determining, by the credential database, a response to the credential action based on the one or more user credentials stored in the credential database and transmitting, by the credential database, the response to a client device.

Claims (58)

1. A computer-implemented method comprising:

accessing, by an officially verifiable electronic representation (OVER) file verifying device, a first OVER file stored on a first OVER file client device, the first OVER file comprising:

a first virtual representation of an original credential of a user that has been verified by an issuing agency to be a first official representation of the original credential of the user for proving the user's identity or qualifications, based on information associated with the original credential of the user, wherein the first OVER file is itself a first new credential of the user;

the first OVER file generated by an OVER engine configured to:

store the information associated with the original credential of the user; and

transmit the first generated OVER file to the first OVER file client device;

transmitting, by the OVER file verifying device, to the OVER engine, a first verifying request to verify that the first OVER file accessed from the first OVER file client device authenticates the user;

receiving, by the OVER file verifying device, a first authentication message comprising a first indication of whether a first scan associated with the first OVER file on the first OVER file client device of the user corresponds to the information associated with the original credential of the user that is stored in the OVER engine;

outputting a first status indicator expressing whether the first OVER file authenticates the user;

accessing, by the OVER file verifying device, a second OVER file stored on a second OVER file client device of the user, the second OVER file comprising a second virtual representation of the original credential that has been verified by the issuing agency to be a second official representation of the original credential that is invalid for use in the first OVER file client device for authenticating the user, wherein the second OVER file is itself a second new credential over the first OVER file and the original credential;

transmitting, by the OVER file verifying device, to the OVER engine, a second verifying request to verify that the second OVER file scanned at the second client device authenticates the user;

receiving, by the OVER file verifying device, a second authentication message comprising a second indication of whether the second scan associated with the second OVER file on the device of the user corresponds to the information associated with the original credential of the user that is stored in the OVER engine; and

outputting a second status indicator expressing whether the second OVER file authenticates the user.

2. The computer-implemented method of claim 1 , wherein the first OVER file further comprises a device identifier for the original credential configured to limit the first OVER file, for use in authenticating the user using the information of the original credential, to the first OVER file client device.

3. The computer-implemented method of claim 1 , wherein the first OVER file further comprises user-specific information.

4. The computer-implemented method of claim 3 , wherein the user specific-information comprises at least one of:

biometric information, location information, a password, or a device identifier.

5. The computer-implemented method of claim 1 , wherein the first OVER file comprises a portion of the original credential stored by the OVER engine.

6. The computer-implemented method of claim 1 , wherein the first authentication message comprises an indication that the first OVER file is expired.

7. The computer-implemented method of claim 1 , further comprising accessing, by the verifying device, from the first OVER file client device, additional credential information associated with the first OVER file indicating whether a secondary condition for authorizing the user has been satisfied.

8. An officially verifiable electronic representation (OVER) file verifying device comprising:

a hardware processor;

a memory unit operatively coupled to the hardware processor, the memory unit configured to store information associated with an original credential of a user and a plurality of instructions, wherein the instructions are configured to cause the hardware processor to perform operations comprising:

accessing a first OVER file stored on a first OVER file client device, the first OVER file comprising:

a first virtual representation of the original credential that has been verified by an issuing agency to be a first official representation of the original credential of the user for proving the user's identity or qualifications, based on information associated with the original credential of the user, wherein the first OVER file is itself a first new credential of the user;

the first OVER file generated by an OVER engine configured to:

store the information associated with the original credential of the user; and

transmit the first generated OVER file to the first OVER file client device;

transmitting to the OVER engine a first verifying request to verify that the first OVER file accessed from the first OVER file client device authenticates the user;

receiving a first authentication message comprising a first indication of whether a first scan associated with the first OVER file on the first OVER file client device of the user corresponds to the information associated with the original credential of the user that is stored in the OVER engine;

outputting a first status indicator expressing whether the first OVER file authenticates the user;

accessing a second OVER file stored on a second OVER file client device of the user, the second OVER file comprising a second virtual representation of the original credential that has been verified by the issuing agency to be a second official representation of the original credential that is invalid for use in the first OVER file client device for authenticating the user, wherein the second OVER file is itself a second new credential over the first OVER file and the original credential;

transmitting to the OVER engine a second verifying request to verify that the second OVER file scanned at the second client device authenticates the user;

receiving a second authentication message comprising a second indication of whether the second scan associated with the second OVER file on the device of the user corresponds to the information associated with the original credential of the user that is stored in the OVER engine; and

outputting a second status indicator expressing whether the second OVER file authenticates the user.

9. The device of claim 8 , wherein the first OVER file further comprises a device identifier for the original credential configured to limit the first OVER file, for use in authenticating the user using the information of the original credential, to the first OVER file client device.

10. The device of claim 8 , wherein the first OVER file further comprises user-specific information.

11. The device of claim 10 , wherein the user specific-information comprises at least one of:

biometric information, location information, a password, or a device identifier.

12. The device of claim 8 , wherein the first OVER file comprises a portion of the original credential stored by the OVER engine.

13. The device of claim 8 , wherein the first authentication message comprises an indication that the first OVER file is expired.

14. The device of claim 8 , wherein the operations further comprise accessing, from the first OVER file client device, additional credential information associated with the first OVER file indicating whether a secondary condition for authorizing the user has been satisfied.

15. A non-transitory computer-readable medium comprising instructions that, when executed by a processor, cause the processor to perform operations comprising:

accessing a first OVER file stored on a first OVER file client device, the first OVER file comprising:

a first virtual representation of an original credential that has been verified by an issuing agency to be a first official representation of the original credential of a user for proving the user's identity or qualifications, based on information associated with the original credential of the user, wherein the first OVER file is itself a first credential of the user;

the first OVER file generated by an OVER engine configured to:

store the information associated with the original credential of the user; and

transmit the first generated OVER file to the first OVER file client device;

transmitting to the OVER engine a first verifying request to verify that the first OVER file accessed from the first OVER file client device authenticates the user;

receiving a first authentication message comprising a first indication of whether a first scan associated with the first OVER file on the first OVER file client device of the user corresponds to the information associated with the original credential of the user that is stored in the OVER engine;

outputting a first status indicator expressing whether the first OVER file authenticates the user;

accessing a second OVER file stored on a second OVER file client device of the user, the second OVER file comprising a second virtual representation of the original credential that has been verified by the issuing agency to be a second official representation of the original credential that is invalid for use in the first OVER file client device for authenticating the user, wherein the second OVER file is itself a second new credential over the first OVER file and the original credential;

transmitting to the OVER engine a second verifying request to verify that the second OVER file scanned at the second client device authenticates the user;

receiving a second authentication message comprising a second indication of whether the second scan associated with the second OVER file on the device of the user corresponds to the information associated with the original credential of the user that is stored in the OVER engine; and

outputting a second status indicator expressing whether the second OVER file authenticates the user.

16. The computer readable medium of claim 15 , wherein the OVER file further comprises a device identifier for the original credential configured to limit the first OVER file, for use in authenticating the user using the information of the original credential, to the OVER file client device.

17. The computer readable medium of claim 15 , wherein the first OVER file further comprises user-specific information comprising at least one of:

biometric information, location information, a password, or a device identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2017
From: SARKISSIAN, SHAUNT M.
To: CORTEX MCP INC.
Reel/Frame 044454/0413 →
Continuity (3)
Continuation 13794878 · Mar 12, 2013
Provisional Application 61740731 · Dec 21, 2012
Related Publication 20160149896A1 · May 26, 2016