IP Library › Granted Patent US 11,153,086
Granted Patent B2
US 11,153,086 · App. 16/428,831 · Granted Oct 19, 2021

Methods and systems for a digital trust architecture

Inventor: Clayton C Bonnell (Fairfax, VA)
Assignee: United States Postal Service
H04L9/32G06F21/6245H04L9/006H04L9/0861H04L9/3239H04L9/3247H04L9/3268H04L63/0442H04L63/123H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,086
App. No.
16/428,831
Granted
Oct 19, 2021
Kind
B2
Abstract

In some aspects, methods and systems for a digital trust architecture are provided. In some aspects, the architecture includes a user account provisioning process. The provisioning process may make use of in person verifications of some personal information to ensure authenticity of the user information. Once the authenticity of user information is established, an account may be created. The user account may include a user email account, with integrated access to digital certificates linked to the user account. Account creation may also automatically publish the new user's public key in a publicly accessible directory, enabling encrypted email information to be easily sent to the new user.

Claims (28)

1. A system for authenticating access to personal information, comprising:

user data stored in a non-volatile electronic memory, the user data associated with a user;

one or more electronic hardware processors, the one or more electronic hardware processors configured to implement:

a digital trust architecture; configured to:

receive the user data and a private key associated with the user; and

generate a digital certificate based on the private key and a digital token of the digital trust architecture;

a data broker, the data broker configured to conditionally provide a network application access to the user data upon request based on receipt of the digital certificate from the network application; and

wherein the data broker is further configured to revoke network application access to the user data based on reception of a revoke message, and to deny further requests for access to the user data based on the reception of the revoke message.

2. The system of claim 1 , further comprising a user computer, configured to provide the digital certificate to the network application, wherein the data broker is configured to receive requests for access to the user data from the network application.

3. The system of claim 2 wherein the data broker is further configured to generate a response to a request for access indicating access to the user data is denied and cause the network application to delete local copies of the user data in response to receiving the response to a request for access indicating access to the user data is denied.

4. The system of claim 3 , wherein the user computer is further configured to provide the user data to the network application.

5. The system of claim 1 , wherein the digital certificate comprises a valid date range, and wherein the data broker is configured to conditionally provide network application access to the user data only within the valid date range.

6. A method of authenticating access to personal information, comprising:

storing user data associated with a user in a non-volatile electronic memory;

receiving, in a digital trust architecture, the user data and a private key associated with the user;

generating a digital certificate based on the received private key and a digital token associated with the digital trust architecture;

conditionally providing a network application access to the stored user data upon request based on the receiving the digital certificate from the network application;

receiving, in the digital trust architecture, a revoke message;

revoking access to the stored user data based on the received revoke message; and

denying further requests for access to the stored user data based on the received revoke message.

7. The method of claim 6 , further comprising:

providing the digital certificate to the network application; and

receiving requests for access to the stored user data from the network application.

8. The method of claim 7 , further comprising:

generating a response to a request for access, the response indicating access to the user data is denied; and

causing the network application to delete local copies of the stored user data in response to receiving the response to a request for access.

9. The method of claim 8 , further comprising providing the stored user data to the network application.

10. The method of claim 6 , wherein the digital certificate comprises a valid date range, and wherein conditionally providing network application access to the stored user data upon request comprises confirming the request is received within the valid date range.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2021
From: BONNELL, CLAYTON C.
To: UNITED STATES POSTAL SERVICE
Reel/Frame 056915/0865 →
Continuity (3)
Division 15709266 · Sep 19, 2017
Provisional Application 62397282 · Sep 20, 2016
Related Publication 20190288843A1 · Sep 19, 2019