IP Library Granted Patent US 11,615,403
Granted Patent B1
US 11,615,403 · App. 16/868,415 · Granted Mar 28, 2023

System and method for dynamically retrieving an attribute value of an identity claim from an issuing party using a digitally signed access token

Inventors: Kamalanathan Thandapani (Livermore, CA); Lionello G. Lunesu (Peng Chau, HK); Aneesh Sandeep Verenkar (San Jose, CA); Keith Kowal (Pleasanton, CA); Prakash Sundaresan (Redmond, WA)
Assignee: Workday, Inc.
G06Q20/3674G06Q20/363G06Q20/3821G06Q20/3829H04L9/3213H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,615,403
App. No.
16/868,415
Granted
Mar 28, 2023
Kind
B1
Abstract

A processor-implemented system and method for dynamically retrieving an attribute value of an identity claim for a user using a digitally signed access token that is digitally signed by a user device, at a relying party device associated with a relying party. The method includes (i) making an API call to retrieve at least one identity claim for the user, (ii) processing each identity claim of the user, with the relying party device, to identify if at least one by-reference identity claim that includes a URL of an endpoint, (iii) obtaining the digitally signed access token that is digitally signed by the user device, (iv) invoking the URL of the endpoint with the at least one by-reference identity claim and the digitally signed access token, and (v) dynamically retrieving the attribute value from the URL of the endpoint from an issuing party device associated with an issuing party.

Claims (34)

1. A processor-implemented method for generating at least one identity claim as at least one by-reference identity claim at an issuing party device associated with an issuing party and dynamically returning an attribute value associated with the at least one by-reference identity claim to a relying party device associated with a relying party, the method comprising:

generating, with the issuing party device, the at least one identity claim as the at least one by-reference identity claim that includes a URL of an endpoint;

issuing, with the issuing party device, the at least one by-reference identity claim to a user device associated with a user;

listening, with the issuing party device, to the URL of the endpoint that is invoked by the relying party device to obtain the at least one by-reference identity claim and receiving a digitally signed access token;

validating, with the issuing party device, the digitally signed access token; and

dynamically returning, with the issuing party device, the attribute value associated with the at least one by-reference identity claim to the relying party device associated with the relying party if the digitally signed access token is valid.

2. The processor-implemented method of claim 1 , wherein the at least one by-reference identity claim is generated by embedding a user public key of the user in the at least one identity claim and specifying the URL of the endpoint in the at least one by-reference identity claim.

3. The processor-implemented method of claim 2 , wherein the issuing party device validates the digitally signed access token by verifying that the user public key associated with the at least one identity claim corresponds to a user private key that was used to digitally sign the digitally signed access token.

4. The processor-implemented method of claim 3 , wherein if the relying party device invokes the URL of the endpoint with a digitally signed access token that has an expiration time, the issuing party device does not share the attribute value of the identity claim with the relying party device if the expiration time has occurred or has passed.

5. The processor-implemented method of claim 1 , wherein the attribute value is a derived attribute value which is derived from an actual attribute value, wherein the derived attribute value is dynamically retrieved by the relying party device, and wherein the derived attribute values is generated by the issuing party device.

6. The processor-implemented method of claim 1 , wherein the user device

obtains the at least one identity claim as the at least one by-reference identity claim from the issuing party device, wherein the at least one by-reference identity includes the URL of the endpoint of the attribute value;

digitally signs the access token to obtain the digitally signed access token;

receives an API call from the relying party device; and

sends the at least one by-reference identity claim and the digitally signed access token that corresponds to the at least one identity claim to the relying party device based on the API call.

7. The processor-implemented method of claim 1 , wherein the relying party device

makes the API call to retrieve the at least one identity claim for the user; and

processes each identity claim of the user, to identify the at least one by-reference identity claim that includes the URL of the endpoint.

8. The processor-implemented method of claim 7 , wherein the relying party device further

obtains the digitally signed access token that is digitally signed by the user device;

invokes the URL of the endpoint with the at least one by-reference identity claim and the digitally signed access token; and

dynamically retrieves the attribute value from the URL of the endpoint from the issuing party device.

9. One or more non-transitory computer readable storage mediums storing one or more sequences of instructions, which when executed by one or more processors, further causes a method for generating at least one identity claim as at least one by-reference identity claim at an issuing party device associated with an issuing party and dynamically returning an attribute value associated with the at least one by-reference identity claim to a relying party device associated with a relying party, the method comprising:

generating, with the issuing party device, the at least one identity claim as the at least one by-reference identity claim that includes a URL of an endpoint;

issuing, with the issuing party device, the at least one by-reference claim to a user device associated with a user;

listening, with the issuing party device, to the URL of the endpoint that is invoked by the relying party device to receive the at least one by-reference identity claim and a digitally signed access token;

validating, with the issuing party device, the digitally signed access token; and

dynamically returning, with the issuing party device, the attribute value associated with the at least one by-reference identity claim to the relying party device associated with the relying party if the digitally signed access token is valid.

10. The one or more non-transitory computer readable storage mediums storing the one or more sequences of instructions of claim 9 , wherein the at least one by-reference identity claim is generated by embedding a user public key of the user in the at least one identity claim and specifying the URL of the endpoint in the at least one by-reference identity claim.

11. The one or more non-transitory computer readable storage mediums storing the one or more sequences of instructions of claim 9 , wherein the relying party device makes an API call to retrieve the at least one identity claim for the user;

processes each identity claim of the user, to identify the at least one by-reference identity claim that includes the URL of the endpoint;

obtains the digitally signed access token that is digitally signed by the user device;

invokes the URL of the endpoint with the at least one by-reference identity claim and the digitally signed access token; and

dynamically retrieves the attribute value from the URL of the endpoint from the issuing party device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2020
From: THANDAPANI, KAMALANATHAN; LUNESU, LIONELLO G.; VERENKAR, ANEESH SANDEEP; KOWAL, KEITH; SUNDARESAN, PRAKASH
To: WORKDAY, INC.
Reel/Frame 052989/0861 →
Continuity (1)
Provisional Application 62852764 · May 24, 2019
Cited By (2)
US 12,316,632 US 12,346,894