IP Library Granted Patent US 11,178,146
Granted Patent B2
US 11,178,146 · App. 16/197,797 · Granted Nov 16, 2021

Systems and methods for online third-party authentication of credentials

Inventors: Blake Hall (Washington, DC); Tanel Suurhans (McLean, VA)
Assignee: ID.me, Inc.
H04L63/0884G06F21/31H04L63/0838
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,178,146
App. No.
16/197,797
Granted
Nov 16, 2021
Kind
B2
Abstract

Systems and methods are disclosed for online authentication of online attributes. One method includes receiving an authentication request from a rely party, the authentication request including identity information to be authenticated and credential information to be authenticated; determining whether a user account is associated with the received identity information by accessing an internal database; accessing user data of the user account determined to be associated with received identity information; determining authentication data to obtained from a user associated with the user account based on the user data of the user account and the credential information to be authenticated; transmitting a request for authentication data; receiving authentication data associated with the user; transmitting authentication data associated with the user; and receiving an authentication result from the verification data source server for the user associated with authentication data.

Claims (52)

1. A computer-implemented method for online authentication of online attributes, the method including:

receiving, at a server over an electronic network, an authentication request from a relying party, the authentication request including identity information to be authenticated and credential information to be authenticated;

determining, by the server, whether a user account is associated with the received identity information by accessing an internal database;

transmitting, by the server over the electronic network to a user associated with the user account, a request for authentication data;

receiving, at the server over the electronic network, authentication data associated with the user, wherein the authentication data includes a status identifier identifying one of a pending, active, suspended, and revoked status, wherein the status identifier is placed in the suspended status after receiving a revocation request and the status identifier is placed in the revoked status after authenticating the revocation request by comparing an assurance level associated with the revocation request to a predetermined assurance level;

transmitting, by the server over the electronic network to a verification data source server, authentication data associated with the user; and

receiving, at the server over the electronic network, an authentication result from the verification data source server for the user associated with authentication data.

2. The method of claim 1 , further comprising:

storing, by the server, the authentication data in the user data of the user account associated with the user.

3. The method of claim 1 , further comprising:

encrypting, by the server, the authentication data in the user data of the user account associated with the user.

4. The method of claim 1 , further comprising:

transmitting, by the server, the authentication result of the authentication request to the relying party.

5. The method of claim 1 , further wherein the authentication data further includes a lifetime value, wherein the lifetime value identifies a length of time the authentication data is valid.

6. The method of claim 1 , further comprising:

transmitting, by the server, an assurance level request for a one-time-password (“OTP”) when an assurance level associated with the authentication request is greater than or equal to a predetermined threshold.

7. The method of claim 6 , wherein the OTP request is conducted by at least one of an interactive voice response (“IVR”) method and a short message service (“SMS”) method.

8. A system for online authentication of online attributes, the system including:

a data storage device that stores instructions system for online authentication of online attributes; and

a processor configured to execute the instructions to perform a method including:

receiving, over an electronic network, an authentication request from a relying party, the authentication request including identity information to be authenticated and credential information to be authenticated;

determining whether a user account is associated with the received identity information by accessing an internal database;

transmitting, over the electronic network to a user associated with the user account, a request for authentication data;

receiving, over the electronic network, authentication data associated with the user, wherein the authentication data includes a status identifier identifying one of a pending, active, suspended, and revoked status, wherein the status identifier is placed in the suspended status after receiving a revocation request and the status identifier is placed in the revoked status after authenticating the revocation request by comparing an assurance level associated with the revocation request to a predetermined assurance level;

transmitting, over the electronic network to a verification data source server, authentication data associated with the user; and

receiving, over the electronic network, an authentication result from the verification data source server for the user associated with authentication data.

9. The system according to claim 8 , wherein the processor is further configured to execute the instructions to perform the method including:

storing the authentication data in the user data of the user account associated with the user.

10. The system according to claim 8 , wherein the processor is further configured to execute the instructions to perform the method including:

encrypting the authentication data in the user data of the user account associated with the user.

11. The system according to claim 8 , wherein the processor is further configured to execute the instructions to perform the method including:

transmitting the authentication result of the authentication request to the relying party.

12. The system according to claim 8 , further wherein the authentication data further includes a lifetime value, wherein the lifetime value identifies a length of time the authentication data is valid.

13. The system according to claim 8 , wherein the processor is further configured to execute the instructions to perform the method including:

transmitting an assurance level request for a one-time-password (“OTP”) when an assurance level associated with the authentication request is greater than or equal to a predetermined threshold.

14. The system according to claim 13 , wherein the OTP request is conducted by at least one of an interactive voice response (“IVR”) method and a short message service (“SMS”) method.

15. A non-transitory computer-readable medium storing instructions that, when executed by a computer, cause the computer to perform a method for online authentication of online attributes, the method including:

receiving, at a server over an electronic network, an authentication request from a relying party, the authentication request including identity information to be authenticated and credential information to be authenticated;

determining, by the server, whether a user account is associated with the received identity information by accessing an internal database;

transmitting, by the server over the electronic network to a user associated with the user account, a request for authentication data;

receiving, at the server over the electronic network, authentication data associated with the user identifying one of a pending, active, suspended, and revoked status, wherein the status identifier is placed in the suspended status after receiving a revocation request and the status identifier is placed in the revoked status after authenticating the revocation request by comparing an assurance level associated with the revocation request to a predetermined assurance level;

transmitting, by the server over the electronic network to a verification data source server, authentication data associated with the user; and

receiving, at the server over the electronic network, an authentication result from the verification data source server for the user associated with authentication data.

16. The computer-readable medium according to claim 15 , further comprising:

storing, by the server, the authentication data in the user data of the user account associated with the user.

17. The computer-readable medium according to claim 15 , further comprising:

encrypting, by the server, the authentication data in the user data of the user account associated with the user.

18. The computer-readable medium according to claim 15 , further comprising:

transmitting, by the server, the authentication result of the authentication request to the relying party.

19. The computer-readable medium according to claim 15 , further wherein the authentication data further includes a lifetime value, wherein the lifetime value identifies a length of time the authentication data is valid.

20. The computer-readable medium according to claim 15 , further comprising:

transmitting, by the server, an assurance level request for a one-time-password (“OTP”) when an assurance level associated with the authentication request is greater than or equal to a predetermined threshold.

Assignments (5)
CHANGE OF NAME Recorded May 9, 2025
From: ID.ME, INC.
To: ID.ME, LLC
Reel/Frame 071248/0794 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 057435/FRAME 0807 Recorded Jan 22, 2025
From: FORTRESS CREDIT CORP.
To: ID.ME, INC.
Reel/Frame 069988/0023 →
PATENT SECURITY AGREEMENT Recorded Jan 22, 2025
From: ID.ME, INC.
To: ARES CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 069989/0493 →
PATENT SECURITY AGREEMENT Recorded Sep 7, 2021
From: ID.ME, INC.
To: FORTRESS CREDIT CORP., AS ADMINISTRATIVE AGENT
Reel/Frame 057435/0807 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2018
From: HALL, BLAKE; SUURHANS, TANEL
To: ID.ME, INC.
Reel/Frame 047606/0575 →
Continuity (3)
Continuation 14851235 · Sep 11, 2015
Provisional Application 62049796 · Sep 12, 2014
Related Publication 20190173879A1 · Jun 6, 2019