IP Library › Granted Patent US 11,734,676
Granted Patent B2
US 11,734,676 · App. 16/684,323 · Granted Aug 22, 2023

Using a contactless card to securely share personal data stored in a blockchain

Inventors: Jeffrey Rule (Chevy Chase, MD); Rajko Ilincic (Annandale, VA); Kaitlin Newman (Washington, DC)
G06Q20/3674G06Q20/352G06Q20/389G06Q20/3825G06Q20/4014H04L9/0637H04L9/3247H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,734,676
App. No.
16/684,323
Granted
Aug 22, 2023
Kind
B2
Abstract

Systems, methods, and articles of manufacture to securely share data stored in a blockchain. A contactless card may receive a request to provide a data element from a device. An applet of the contactless card may encrypt the data element and a wallet address. The applet may generate a signature for the request, and transmit, to a mobile device, the signature and the encrypted data. The mobile device may transmit, to a verification service, the signature and encrypted data. The verification service may verify the signature based on a public key. A node in a blockchain may generate a block in the blockchain, the block comprising indications of the verification of the signature, the requested data element, and the wallet address. An encrypted data element corresponding to the data element may be decrypted using a public key. The device may receive the decrypted data element from the wallet address.

Claims (41)

1. A method, comprising:

receiving, by a verification service executing on a server from a mobile device, a digital signature, an encrypted request to provide a user data element to a merchant wallet address, and a user wallet address, wherein an applet of a contactless card generates the digital signature based on a private key of the contactless card, wherein the applet generates the encrypted request based on a first request received from a merchant device as part of a transaction;

verifying, by the verification service, the digital signature based on a public key associated with the private key of the contactless card;

decrypting, by the verification service, the encrypted request;

receiving, by the verification service, the user data element;

encrypting, by the verification service, the received user data element using the private key to produce an encrypted user data element;

generating, by a node of a blockchain responsive to a second request received from the verification service, a block in the blockchain corresponding to the first request, the block comprising an indication of the verification of the digital signature, the encrypted user data element, the public key, the merchant wallet address as a recipient address of the block, and the user wallet address; and retrieving, by the merchant device, the block, decrypting the encrypted user data element, and authorizing the transaction based on the decrypted user data element.

2. The method of claim 1 , wherein the block in the blockchain further comprises an indication of a request token associated with the first request, wherein the user data element is one of a plurality of user data elements, each user data element corresponding to one or more personally identifiable attributes describing a user, the personally identifiable attributes comprising: (i) an age, (ii) a name, (iii) an address, (iv) an identification number, (v) one or more biometric identifiers, (vi) one or more account numbers, and (vii) an email address.

3. The method of claim 1 , further comprising: identifying, by the verification service, a plurality of blocks of the blockchain associated with a plurality of prior requests, the plurality of prior requests validated and fulfilled to provide user data elements of a user.

4. The method of claim 1 , further comprising: transmitting the second request by the verification service to the node of the blockchain, wherein the second request comprises the encrypted user data element, the indication of the verification of the digital signature, the public key, the merchant wallet address, and the user wallet address.

5. The method of claim 4 , further comprising: responsive to generation of the block, reading, by the merchant device, the block in the blockchain; decrypting, by the merchant device based on the public key, the encrypted user data element; and authorizing, by the merchant device, the transaction based on the decrypted user data element.

6. The method of claim 1 , wherein the user wallet address is encrypted when received with the request, further comprising:

decrypting, by the verification service based on the public key, the user wallet address to validate an identity of a user.

7. The method of claim 1 , wherein verifying the digital signature comprises decrypting the digital signature by the verification service based on the public key, wherein the digital signature comprises a hash value.

8. A system, comprising:

a server executing a verification service, the verification service programmed to:

receive, from a mobile device, a digital signature, an encrypted request to provide a user data element to a merchant wallet address, and a user wallet address, wherein an applet of a contactless card generates the digital signature based on a private key of the contactless card, wherein the applet generates the encrypted request based on a first request received from a merchant device as part of a transaction;

verify the digital signature based on a public key associated with the private key of the contactless card;

decrypt the encrypted request; receive the user data element;

encrypt the received user data element using the private key to produce an encrypted user data element; and

transmit a second request to a node of a blockchain;

the node of the blockchain configured to: generate, responsive to the second request received from the verification service, a block in the blockchain corresponding to the first request, the block comprising an indication of the verification of the digital signature, the encrypted user data element, the public key, the merchant wallet address as a recipient address of the block, and the user wallet address; and

the merchant device configured to retrieve the block, decrypt the encrypted user data element, and authorize the transaction based on the decrypted user data element.

9. The system of claim 8 , wherein the block in the blockchain further comprises an indication of a request token associated with the first request, wherein the user data element is one of a plurality of user data elements, each user data element corresponding to one or more personally identifiable attributes describing a user, the personally identifiable attributes comprising: (i) an age, (ii) a name, (iii) an address, (iv) an identification number, (v) one or more biometric identifiers, (vi) one or more account numbers, and (vii) an email address.

10. The system of claim 8 , wherein the second request comprises the encrypted user data element, the indication of the verification of the digital signature, the public key, the merchant wallet address, and the user wallet address.

11. The system of claim 8 , further comprising the merchant device, the merchant device programmed to: responsive to generation of the block, read the block in the blockchain; decrypt, based on the public key, the encrypted user data element; and authorize the transaction based on the decrypted user data element.

12. The system of claim 8 , the verification service programmed to: identify a plurality of blocks of the blockchain associated with a plurality of prior requests, the plurality of prior requests validated and fulfilled to provide user data elements of a user.

13. The system of claim 8 , wherein the user wallet address is encrypted when received with the request, wherein the verification service is programmed to: decrypt, based on the public key, the user wallet address to validate an identity of a user.

14. A non-transitory computer-readable storage medium storing computer-readable program code executable by a plurality of processors causes the plurality of processors to:

receive, by a verification service from a mobile device, a digital signature, an encrypted request to provide a user data element to a merchant wallet address, and a user wallet address, wherein an applet of a contactless card generates the digital signature based on a private key of the contactless card, wherein the applet generates the encrypted request based on a first request received from a merchant device as part of a transaction;

verify, by the verification service, the digital signature based on a public key associated with the private key of the contactless card;

decrypt, by the verification service, the encrypted request; receive the user data element;

encrypt, by the verification service, the received user data element using the private key to produce an encrypted user data element; and

generate, by a node of a blockchain, a block in the blockchain corresponding to the first request, the block comprising an indication of the verification of the digital signature, the encrypted user data element, the public key, the merchant wallet address as a recipient address of the block, and the user wallet address; and

retrieve, by the merchant device, the block, decrypt the encrypted user data element, and authorize the transaction based on the decrypted user data element.

15. The non-transitory computer-readable storage medium of claim 14 , wherein the block in the blockchain is generated responsive to a second request, wherein the second request comprises the encrypted user data element, the indication of the verification of the digital signature, the public key, the merchant wallet address, and the user wallet address.

16. The non-transitory computer-readable storage medium of claim 14 , wherein the block in the blockchain further comprises an indication of a request token associated with the first request, wherein the user data element is one of a plurality of user data elements, each user data element corresponding to one or more personally identifiable attributes describing a user, the personally identifiable attributes comprising: (i) an age, (ii) a name, (iii) an address, (iv) an identification number, (v) one or more biometric identifiers, (vi) one or more account numbers, and (vii) an email address.

17. The non-transitory computer-readable storage medium of claim 14 , storing computer-readable program code executable by the processor to cause the processor to: receive, from the merchant device, an indication that the transaction was authorized.

18. The non-transitory computer-readable storage medium of claim 14 , storing computer-readable program code executable by the processor to cause the processor to: decrypt the digital signature based on the public key to verify the digital signature, wherein the digital signature comprises a hash value.

19. The non-transitory computer-readable storage medium of claim 14 , wherein the user wallet address is encrypted when received with the request, the medium storing computer-readable program code executable by the processor to cause the processor to: decrypt, based on the public key, the user wallet address to validate an identity of a user.

20. The non-transitory computer-readable storage medium of claim 14 , wherein the code to verify the digital signature comprises code to decrypt the digital signature based on the public key, wherein the digital signature comprises a hash value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2019
From: RULE, JEFFREY; ILINCIC, RAJKO; NEWMAN, KAITLIN
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 051013/0701 →
Continuity (2)
Continuation 16359980 · Mar 20, 2019
Related Publication 20200302432A1 · Sep 24, 2020