IP Library Patent Application 17198079
Patent Application
App. No. 17/198,079

ELECTRONIC PATIENT CREDENTIALS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/198,079
Abstract

An issuer client of a service provider establishes a trusted, private, and cryptographically secured connection with a wallet application of a user through a cloud-based agent and provides credential information to the wallet application via the private connection. The credential information is encrypted using a public key of the wallet application dedicated for the private connection with the cloud-based agent. Upon receiving the encrypted credential information, the wallet application decrypts it using a private key to obtain the credential information. The cloud-based agent digitally signs the credential information using a private key of the issuer client, which can be verified by a public key of the issuer client stored in a public identity ledger.

Claims (85)

1 . A method, comprising:

by a first client deployed on a terminal device of a first service provider:

receiving a request for secure connection from a wallet client deployed on a terminal device of a user, the request for secure connection including a first digital identifier of the wallet client, a first public key of the wallet client, and first personal identification information of the user;

in response to the request for secure connection:

verifying that the first personal identification information of the user is authentic;

in response to verifying that the first personal identification information of the user is authentic, sending the digital identifier of the wallet client and the first public key of the wallet client to a first cloud-based agent to enable the first cloud-based agent to store the digital identifier of the wallet client together with the first public key of the wallet client;

receiving a request to issue a credential that identifies a credential template; and

in response to receiving the request to issue a credential:

accessing the identified credential template;

retrieving information of the user from a first electronic health record system coupled to the first client;

populating the accessed credential template using the information of the user retrieved from the first electronic health record system to generate first credential information; and

sending the first credential information with the wallet client's digital identifier to the first cloud-based agent to enable the first cloud-based agent to:

encrypt the first credential information with the first public key of the wallet client; and

forward the encrypted first credential information to the wallet client using the wallet client's digital identifier.

2 . The method of claim 1 wherein the retrieving information of the user from the first electronic health record system is performed in accordance with a standard health care application programming interface.

3 . The method of claim 1 , wherein the receiving the request for secure connection from the wallet client includes receiving the request for secure connection through the wallet client capturing a two-dimensional barcode displayed by a portal application of the first client, and receiving a phone number of the user.

4 . The method of claim 1 , further comprising:

by the first client:

invoking the first cloud-based agent to register the first service provider, to enable the first cloud-based agent to:

create a second key pair for the first service provider comprising a second private key and second public key;

store the second private key; and

cause publication of the second public key in a distributed ledger, and wherein the sending the first credential information with the wallet client's digital identifier further enables the first cloud-based agent to:

sign the first credential information with the second private key of the first service provider, and wherein it is the first credential information signed with the second private key of the first service provider that is encrypted with the first public key of the wallet client.

5 . The method of claim 1 , comprising:

receiving an identifier of one or more of the user or the terminal device of the user;

providing programs configured to deploy the wallet client to the terminal device of the user based on the received identifier; and

causing the wallet client to be deployed at the terminal device of the user, the wallet client including the digital identifier of the wallet client, the first public key and a first private key configured to decrypt a data encrypted using the first public key.

6 . The method of claim 5 , wherein the providing the programs configured to deploy the wallet client to the terminal device of the user includes sending a message to the terminal device, the message including a link configured to deploy the wallet client based on a selection by the user.

7 . The method of claim 5 , wherein the receiving the identifier of the one or more of the user or the terminal device of the user includes receiving the identifier through one or more of a portal application of the first client by human input or a service application of the first client from a first application of the first service provider that is different from the first client.

8 . The method of claim 1 , wherein the information of the user obtained from the first electronic health record system is vaccination information of the user.

9 . The method of claim 1 , wherein the wallet client is configured to identify the first client ad corresponding to the first service provider among a list of service providers.

10 . The method of claim 1 , wherein the information of the user includes personal identification information of the user.

11 . The method of claim 1 , comprising:

by the wallet client:

receiving, from a second service provider, a request for the first credential information;

sending a second digital identifier and a second public key of the wallet client to a second client of the second service provider;

identifying, by the wallet client, a second cloud-based agent as coupled to the second client of the second service provider;

encrypting signed first credential information with a second private key of the wallet client to generate signed and re-encrypted first credential information, the second private key of the wallet client corresponding to the second public key of the wallet client; and

sending, through the second cloud-based agent, the signed and re-encrypted first credential information to the second client.

12 . The method of claim 11 , wherein the second cloud-based agent decrypts the signed and re-encrypted first credential information using the second public key of the wallet client to obtain the signed first credential information and sends the signed first credential information to the second client.

13 . The method of claim 12 , further comprising:

by the second client:

obtaining, through the second cloud-based agent, a third public key of the first client from a distributed ledger; and

verifying authenticity of the signed first credential information using the third public key.

14 . The method of claim 13 , wherein the verifying authenticity of the signed first credential information is conducted by the second cloud-based agent.

15 . A method, comprising:

by a first client deployed on a terminal device of a first service provider:

receiving, from a wallet client, a digital identifier of the wallet client;

sending the digital identifier of the wallet client to a first cloud-based agent and causing the first client to establish a secured connection with the wallet client, the establishing the secured connection with the wallet client including identifying a first public key stored at the first cloud-based agent as corresponding to a first private key of the wallet client; and

receiving, through the first cloud-based agent and from the wallet client, signed first credential information of a user that is issued by a second service provider,

wherein the first cloud-based agent:

receives from the wallet client signed and encrypted first credential information of the user,

decrypts the signed and encrypted first credential information of the user using the first public key to obtain signed first credential information,

obtains a second public key of the second service provider from a distributed ledger,

verifies authenticity of the signed first credential information using the second public key; and

sends the signed first credential information to the first client after the authenticity verification.

16 . The method of claim 15 , wherein the first client is coupled to a first electronic health record system, and the method comprises communicating, by the first client, the signed first credential information of the user to the first electronic health record system.

17 . The method of claim 15 , comprising:

receiving an identifier of one or more of the user or the terminal device of the user;

providing programs configured to deploy the wallet client to the terminal device of the user based on the received identifier; and

causing the wallet client be deployed at the terminal device of the user, the wallet client including the digital identifier of the wallet client, the first public key and the first private key configured to decrypt data encrypted using the first public key.

18 . The method of claim 15 , comprising:

by the first client:

invoking the first cloud-based agent to register the first service provider and to enable the wallet client to create a first key pair of the first private key and the first public key dedicated for communication with the first service provider.

19 . A storage medium having executable instructions stored thereon, which when executed by a processor, configure the processor to implement acts comprising:

at a first client deployed on a terminal device of a first service provider:

receiving a request for secure connection from a wallet client deployed on a terminal device of a user, the request for secure connection including a first digital identifier of the wallet client, a first public key of the wallet client, and first personal identification information of the user;

in response to the request for secure connection:

verifying that the first personal identification information of the user is authentic; and

in response to verifying that the first personal identification information of the user is authentic, sending the digital identifier of the wallet client and the first public key of the wallet client to a first cloud-based agent to enable the first cloud-based agent to store the digital identifier of the wallet client together with the first public key of the wallet client;

receiving a request to issue a credential that identifies a credential template; and

in response to receiving the request to issue a credential:

accessing the identified credential template;

retrieving information of the user from a first electronic health record system coupled to the first client;

populating the accessed credential template using the information of the user retrieved from the first electronic health record system to generate first credential information; and

sending the first credential information with the wallet client's digital identifier to the first cloud-based agent to enable the first cloud-based agent to:

encrypt the first credential information with the first public key of the wallet client; and

forward the encrypted first credential information to the wallet client using the wallet client's digital identifier.

20 . The storage medium of claim 19 , wherein the acts further comprise:

at the first client:

invoking the first cloud-based agent to register the first service provider, to enable the first cloud-based agent to:

create a second key pair for the first service provider comprising a second private key and second public key;

store the second private key; and

cause publication of the second public key in a distributed ledger, and wherein the sending the first credential information with the wallet client's digital identifier further enables the first cloud-based agent to:

sign the first credential information with the second private key of the first service provider, and wherein it is the first credential information signed with the second private key of the first service provider that is encrypted with the first public key of the wallet client.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2025
From: ADVATA INC.
To: R1 RCM INC.
Reel/Frame 071515/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2025
From: ANDERSON, BRIAN; INGRAO, CHRISTIAN M.; NASH, MICHAEL W.; PARKISON, BENJAMIN K.
To: LUMEDIC ACQUISITION CO, INC.
Reel/Frame 071472/0013 →
SECURITY AGREEMENT Recorded Nov 20, 2024
From: R1 RCM INC.; IVINCI PARTNERS, LLC; ADVATA INC.; PAR8O, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS TRUSTEE AND COLLATERAL AGENT
Reel/Frame 069402/0739 →
RELEASE OF SECURITY INTERESTS Recorded Nov 20, 2024
From: BANK OF AMERICA, N.A., AS AGENT
To: INTERMEDIX OFFICE BASED, LLC; INTERMEDIX CORPORATION; R1 RCM INC.; SCHEDULING.COM, INC.; IVINCI PARTNERS, LLC; PAR8O, LLC; ADVATA INC.
Reel/Frame 069402/0845 →
NOTICE AND CONFIRMATION OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Nov 19, 2024
From: INVINCI PARTNERS, LLC; ADVATA INC.; PAR8O, LLC; R1 RCM INC.
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS COLLATERAL AGENT
Reel/Frame 069390/0490 →
SECURITY AGREEMENT (SUPPLEMENT) Recorded Mar 15, 2024
From: ADVATA INC.
To: BANK OF AMERICA, N.A., AS AGENT
Reel/Frame 066944/0699 →
CHANGE OF NAME Recorded Dec 4, 2023
From: LUMEDIC ACQUISITION CO., INC.
To: LUMEDIC, INC.
Reel/Frame 065757/0411 →
MERGER Recorded Dec 4, 2023
From: LUMEDIC, INC.
To: ADVATA INC.
Reel/Frame 065746/0043 →