IP Library Granted Patent US 10,587,413
Granted Patent B1
US 10,587,413 · App. 15/660,335 · Granted Mar 10, 2020

Decentralized identities for cross-enterprise authentication and/or authorization

Inventors: Stephen Todd (Shrewsbury, MA); Mark A. O'Connell (Westborough, MA)
Assignee: EMC IP Holding Company LLC
H04L9/3234G06Q10/10H04L9/3247H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,587,413
App. No.
15/660,335
Filed
Jul 26, 2017
Granted
Mar 10, 2020
Kind
B1
Art Unit
2436
USPC
713/185
Abstract

At least one identity for a given entity of a first enterprise is established in accordance with a decentralized identity management system maintained in accordance with a distributed ledger. The identity of the given entity of the first enterprise and a set of attributes relating to the identity are defined by at least one cryptographically signed token file. The cryptographically signed token file is referenced in the distributed ledger enabling a second enterprise to authenticate and/or authorize the given entity in accordance with at least one of the set of attributes.

Claims (37)

1. A method comprising:

establishing at least one identity for a given entity of a first enterprise in accordance with a decentralized identity management system maintained in accordance with a distributed ledger, wherein the identity of the given entity of the first enterprise and a set of attributes relating to the identity are defined by at least one cryptographically signed token file;

referencing the cryptographically signed token file in the distributed ledger enabling a second enterprise to at least one of authenticate and authorize the given entity in accordance with at least one of the set of attributes; and

utilizing the cryptographically signed token file to make an automated decision whether or not to grant the given entity of the first enterprise access to an environment controlled by the second enterprise;

wherein a given level of access to the environment of the second enterprise is granted to the given entity of the first enterprise when the identity is authorized by the first enterprise;

wherein the method is implemented via one or more processing devices each comprising a processor coupled to a memory.

2. The method of claim 1 , wherein a given level of access to the environment of the second enterprise is granted to the given entity of the first enterprise when the identity is authorized by the first enterprise and the set of attributes of the cryptographically signed token file comprises a request from the second enterprise.

3. The method of claim 1 , wherein a given level of access to the environment of the second enterprise is granted to the given entity of the first enterprise when the identity is authorized by the first enterprise and the set of attributes of the cryptographically signed token file comprises a request from the second enterprise containing a name associated with the given identity and a specific environment to which the given entity is to be given access.

4. The method of claim 1 , wherein a given level of access to the environment of the second enterprise is granted to the given entity of the first enterprise when the identity is authorized by the first enterprise and the set of attributes of the cryptographically signed token file comprises a request from one or more authorizing entities of the second enterprise containing a name associated with the given identity and a specific environment to which the given entity is to be given access.

5. The method of claim 1 , wherein the automated decision whether or not to grant the given entity of the first enterprise access to the environment controlled by the second enterprise is based on at least one revocation attribute contained in the set of attributes of the cryptographically signed token file.

6. The method of claim 5 , wherein the revocation attribute is an expiration time associated with the identity of the given entity of the first enterprise.

7. The method of claim 5 , wherein the revocation attribute is a check that automatically determines if the identity of the given entity of the first enterprise has been revoked.

8. The method of claim 1 , wherein the set of attributes of the cryptographically signed token file comprises a revocable request from the second enterprise, and wherein the request itself is cryptographically signed by the second enterprise.

9. The method of claim 1 , wherein the first enterprise is a vendor and the second enterprise is a customer of the vendor, and wherein the given entity is an individual associated with the vendor tasked with performing a service that necessitates access by the individual to the environment controlled by the customer.

10. The method of claim 9 , wherein the environment controlled by the customer comprises at least one of a customer facility and a customer communication system.

11. The method of claim 10 , wherein the individual associated with the vendor is tasked with performing a service on a product provided by the vendor to the customer, and wherein the product is located within the customer facility.

12. The method of claim 1 , further comprising:

storing the cryptographically signed token file on a portable device;

the given entity of the first enterprise presenting the portable device with the cryptographically signed token file to the second enterprise; and

the second enterprise utilizing the cryptographically signed token file to make an automated decision whether or not to grant the given entity of the first enterprise access to an environment controlled by the second enterprise.

13. The method of claim 1 , wherein the decentralized identity and the set of attributes contained in the cryptographically signed token file for the given entity enables the second enterprise to not have to maintain a dedicated set of access credentials for giving access to the given entity.

14. The method of claim 1 , wherein the token file is cryptographically signed using a private key assigned to the first enterprise such that the token file can be verified using a public key corresponding to the private key.

15. The method of claim 1 , wherein the decentralized identity management system is adapted from a blockstack-based system.

16. The method of claim 1 , wherein the distributed ledger is a blockchain distributed ledger.

17. A system comprising:

at least one processor, coupled to a memory, and configured to:

establish at least one identity for a given entity of a first enterprise in accordance with a decentralized identity management system maintained in accordance with a distributed ledger, wherein the identity of the given entity of the first enterprise and a set of attributes relating to the identity are defined by at least one cryptographically signed token file;

reference the cryptographically signed token file in the distributed ledger enabling a second enterprise to at least one of authenticate and authorize the given entity in accordance with at least one of the set of attributes; and

utilize the cryptographically signed token file to make an automated decision whether or not to grant the given entity of the first enterprise access to an environment controlled by the second enterprise;

wherein a given level of access to the environment of the second enterprise is granted to the given entity of the first enterprise when the identity is authorized by the first enterprise.

18. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes said at least one processing device to:

establish at least one identity for a given entity of a first enterprise in accordance with a decentralized identity management system maintained in accordance with a distributed ledger, wherein the identity of the given entity of the first enterprise and a set of attributes relating to the identity are defined by at least one cryptographically signed token file; and

reference the cryptographically signed token file in the distributed ledger enabling a second enterprise to at least one of authenticate and authorize the given entity in accordance with at least one of the set of attributes; and

utilize the cryptographically signed token file to make an automated decision whether or not to grant the given entity of the first enterprise access to an environment controlled by the second enterprise;

wherein a given level of access to the environment of the second enterprise is granted to the given entity of the first enterprise when the identity is authorized by the first enterprise.

19. The system of claim 17 , wherein the decentralized identity and the set of attributes contained in the cryptographically signed token file for the given entity enables the second enterprise to not have to maintain a dedicated set of access credentials for giving access to the given entity.

20. The computer program product of claim 18 , wherein the decentralized identity and the set of attributes contained in the cryptographically signed token file for the given entity enables the second enterprise to not have to maintain a dedicated set of access credentials for giving access to the given entity.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (043775/0082) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060958/0468 →
RELEASE OF SECURITY INTEREST AT REEL 043772 FRAME 0750 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0606 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: TODD, STEPHEN; O'CONNELL, MARK A.
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 043576/0043 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043772/0750 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 043775/0082 →
Cited By (2)
US 12,256,010 US 12,585,736