IP Library › Granted Patent US 11,528,138
Granted Patent B2
US 11,528,138 · App. 17/308,857 · Granted Dec 13, 2022

Methods and systems for a digital trust architecture

Inventor: Clayton C. Bonnell (Fairfax, VA)
Assignee: United States Postal Service
H04L9/32G06F21/6245H04L9/006H04L9/0861H04L9/3239H04L9/3247H04L9/3268H04L63/0442H04L9/50H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,528,138
App. No.
17/308,857
Granted
Dec 13, 2022
Kind
B2
Abstract

In some aspects, methods and systems for a digital trust architecture are provided. In some aspects, the architecture includes a user account provisioning process. The provisioning process may make use of in person verifications of some personal information to ensure authenticity of the user information. Once the authenticity of user information is established, an account may be created. The user account may include a user email account, with integrated access to digital certificates linked to the user account. Account creation may also automatically publish the new user's public key in a publicly accessible directory, enabling encrypted email information to be easily sent to the new user.

Claims (49)

1. A digital trust architecture system comprising:

a hardware processor configured to:

receive, from a network, a request to create an account for a user;

verify the user account for the user based on user identity information, the user identity information comprising a first item of user information received when the user is at a first location and a second item of user information received when the user is at a second location where the second item of user information is verified in-person, wherein the first location is different from the second location;

associate the user account with an electronic key;

identify electronic data regarding the user, wherein the electronic data is to be communicated electronically with respect to a transaction involving the user;

sign the electronic data based on the electronic key;

convey the electronic data over the network to a recipient associated with a recipient device;

receive input identifying the recipient associated with the recipient device and input indicating the electronic data,

search for a public key associated with the recipient, wherein the electronic key comprises, at least in part, the public key, and

encrypt the electronic data with the public key;

receive input indicating that the encrypted electronic data is to be stored in a blockchain; and

store the encrypted electronic data in the blockchain in response to the input; and

a memory configured to store the user identity information, the user account, and the electronic key.

2. The system of claim 1 , wherein the hardware processor is further configured to receive the first item of user information from a user device and the second item of user information from an in-person verification device via the network.

3. The system of claim 1 , wherein the hardware processor is further configured to:

generate a prompt to an in-person verification system for the second item of user identity information, and

receive the second item of user identity information in response to the generated prompt.

4. The system of claim 1 , wherein the hardware processor is further configured to:

receive a visibility input indicating whether the information stored in the blockchain is publicly accessible, and

set access privileges of the blockchain in response to the visibility input.

5. The system of claim 1 , wherein the hardware processor is further configured to selectively publish a public key associated with the user to a publicly accessible directory database.

6. The system of claim 1 , wherein the hardware processor is further configured to:

generate a digital signature for the electronic data, and

invalidate the digital signature based on revoking access to the electronic data.

7. A method implementing a digital trust architecture, the method comprising:

receiving, by a processor, from a network, a request to create an account for a user;

verifying by a processor, the user account for the user based on user identity information, the user identity information comprising a first item of user information received when the user is at a first location and a second item of user information received when the user is at a second location where the second item of user information is verified in-person, wherein the first location is different from the second location;

associating, by a processor, the user account with an electronic key;

identifying, by a processor, electronic data regarding the user, wherein the electronic data is to be communicated electronically with respect to a transaction involving the user;

signing, by a processor, the electronic data based on the electronic key;

conveying, by a processor, the electronic data over the network to a recipient associated with a recipient device;

receiving input identifying the recipient associated with the recipient device and input indicating the electronic data;

searching for a public key associated with the recipient, wherein the electronic key comprises, at least in part, the public key; and

encrypting the electronic data with the public key

receiving input indicating that the encrypted electronic data is to be stored in a blockchain;

storing the encrypted electronic data in the blockchain in response to the input; and

storing, in a memory the user identity information, the user account, and the electronic key.

8. The method of claim 7 , further comprising, receiving the first item of user information from a user device and the second item of user information from an in-person verification device via the network.

9. The method of claim 7 , further comprising:

generating a prompt to an in-person verification system for the second item of user identity information, and

receiving the second item of user identity information in response to the generated prompt.

10. The method of claim 7 , further comprising:

receiving a visibility input indicating whether the information stored in the blockchain is publicly accessible, and

setting access privileges of the blockchain in response to the visibility input.

11. The method of claim 7 , further comprising selectively publishing a public key associated with the user to a publicly accessible directory database.

12. The method of claim 7 , further comprising:

generating a digital signature for the electronic data; and

invalidating the digital signature based on revoking access to the electronic data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2022
From: BONNELL, CLAYTON C.
To: UNITED STATES POSTAL SERVICE
Reel/Frame 061637/0130 →
Continuity (4)
Continuation 16428831 · May 31, 2019
Division 15709266 · Sep 19, 2017
Provisional Application 62397282 · Sep 20, 2016
Related Publication 20210258161A1 · Aug 19, 2021