IP Library Granted Patent US 11,954,212
Granted Patent B2
US 11,954,212 · App. 17/344,275 · Granted Apr 9, 2024

Method, apparatus, and computer-readable medium for confederated rights and hierarchical key management

Inventor: George Daniel Doney (Annapolis, MD)
Assignee: SECURRENCY, INC.
G06F21/604G06F16/27G06Q20/3674G06Q20/38215G06Q20/3825G06Q20/3829G06Q20/389G06Q20/4016H04L9/0894H04L9/3247G06F2221/2141H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,954,212
App. No.
17/344,275
Granted
Apr 9, 2024
Kind
B2
Abstract

A method and apparatus for secured, peer-to-peer transfer of data rights over a computer network, the method being accomplished by a distributed computing system including a distributed ledger platform. Root rights are defined and delegated to wallets in a multilevel manner to thereby isolate wallets associated with the root right from cyber risk.

Claims (39)

1. A method for secure authorization of data transactions represented as state changes in a decentralized computing network including a distributed ledger platform, the method comprising:

creating a root right expressed in a smart contract code executed on the decentralized computing network, the root right permitting execution of specified functions to thereby create an immutable right;

delegating a right to permit execution of at least one of the specified functions from the root right to a wallet on the decentralized computing network to create a delegated right allowing the wallet to sign transactions corresponding to the at least one of the specified functions, wherein the delegated right is configured to be revoked or reassigned by the root right;

recording a data structure in a delegation registry that represents the delegated right; and

authorizing a transaction on the decentralized computing network by signing the transaction with the wallet to thereby exercise the delegated right.

2. The method of claim 1 , wherein the smart contract code provides a party with signing authority on an assigning wallet assigned to the root right permission to delegate a second delegated right to a second wallet, thereby creating an extended right, and further comprising recording a second data structure in the delegation registry in response to a delegation of the second delegated right, thereby resulting in the second data structure in the delegation registry referencing at least one smart contract wherein the second delegated right applies, the second delegated right, the assigning wallet, and the second wallet to which the second delegated right was delegated.

3. The method of claim 2 , wherein the right, the delegated right, and the extended right are derived directly or indirectly from the root right, to thereby provide a chain of authority configured to be traced back to the root right.

4. The method of claim 1 , wherein a smart contract interface specification is used for communication between the smart contract code and the delegation registry.

5. The method of claim 1 , wherein a root wallet assigned to the root right is configured to revoke the delegated right by removing the data structure from the delegation registry that represents the delegated right, or replacing delegation of the delegated right by delegating the delegated right to another wallet by changing the data structure in the delegation registry that represents the delegated right.

6. The method of claim 1 , further comprising the wallet delegating the delegated right to another wallet to thereby further isolate a root wallet assigned to the root right from cyber risk associated with signing transactions.

7. The method of claim 1 , wherein a rights management data structure model is applied whereby new rights are formed from existing rights, wherein the new rights include at least one management right permitting creation, management, and enforcement of the delegated right, the rights management data structure model expressing the at least one management right by deploying a rights management smart contract code that enables a rights management structure, the rights management data structure model being defined by a root wallet.

8. The method of claim 7 , wherein the rights management data structure model includes an attribute management registry containing at least one attribute, wherein the at least one attribute is an attribute data structure containing a name, a storage location and data type, and an indication of an authorized party authorized to create, read, update, or delete data and wherein an attestation registry stores attestation attribute values associated with objects assigned by the authorized party, the attestation attribute values representing roles which are configured to be used to capture the delegated right assigned to the wallet, to thereby facilitate the creation and management of a role right configured to be used to govern the delegated right.

9. The method of claim 1 , wherein a policy management data structure includes a set of encoded instructions that evaluates one or more rules consisting of logic to use attributes of effected objects in a state change proposed by the wallet to determine a the delegated right of the wallet allowing the wallet to authorize the state change.

10. A computer system for secure authorization of data transactions represented as state changes in a decentralized computing network including a distributed ledger platform, the system comprising:

at least one computer hardware processor; and

at least one memory device having computer readable instructions stored thereon which,

when executed by the at least one computer hardware processor cause the at least

one computer hardware processor to carry out the following method:

creating a root right expressed in a smart contract code for execution on the decentralized computing network, the root right permitting execution of specified functions to thereby create an immutable right;

delegating a right to permit execution of at least one of the specified functions from the root right to a wallet on the decentralized network to create a delegated right allowing the wallet to sign transactions corresponding to the at least one of the specified functions, wherein the delegated right is configured to be revoked or reassigned by the root right;

recording a data structure in a delegation registry that represents the delegated right; and

authorizing a transaction on the decentralized computing network by signing the transaction with the wallet to thereby exercise the delegated right.

11. The system of claim 10 , wherein the smart contract code provides a party with signing authority on an assigning wallet assigned to the root right permission to delegate a second delegated right to a second wallet, thereby creating an extended right, and further comprising recording a second data structure in the delegation registry being accomplished in response to a delegation of the second delegated right resulting in the second data structure in the delegation registry referencing at least one smart contract wherein the second delegated right applies, the second delegated right, the assigning wallet, and the second wallet to which the second delegated right was delegated.

12. The system of claim 11 , wherein the right, the delegated right, and the extended right are derived directly or indirectly from the root right, to thereby provide a chain of authority configured to be traced back to the root right.

13. The system of claim 10 , wherein a smart contract interface specification is used for communication between the smart contract code and the delegation registry.

14. The system of claim 10 , wherein a root wallet assigned to the root right is configured to revoke the delegated right by removing the data structure from the delegation registry that represents the delegated right, or replacing the delegation of the delegated right by delegating the delegated right to another wallet by changing the data structure in the delegation registry that represents the delegated right.

15. The system of claim 10 , further comprising the wallet delegating the delegated right to another wallet to thereby further isolate a root wallet assigned to the root right from cyber risk associated with signing transactions.

16. The system of claim 10 , wherein a rights management data structure model is applied whereby new rights are formed from existing rights, wherein the new rights include at least one management right permitting creation, management, and enforcement of the delegated right, the rights management data structure model expressing the at least one management right to authorize a state change by deploying a rights management smart contract code that enables a rights management structure, the rights management data structure model being defined by a party possessing the root wallet.

17. The system of claim 16 , wherein the rights management data structure model includes an attribute management registry containing at least one attribute, wherein the at least one attribute is an attribute data structure containing a name, a storage location and data type, and an indication of an authorized party authorized to create, read, update, or delete data and wherein an attestation registry stores attestation attribute values associated with objects assigned by the authorized party, the attestation attribute values representing roles which are configured to be used to capture the delegated right assigned to the wallet, to thereby facilitate the creation and management of a role right configured to be used to govern the delegated right.

18. The system of claim 10 , wherein a policy management data structure includes a set of encoded instructions that evaluates one or more rules consisting of logic to use attributes of effected objects in a state change proposed by the wallet to determine a delegated right of the wallet allowing the wallet to authorize the state change.

19. A computer system for secure authorization of data transactions represented as state changes in a decentralized computing network including a distributed ledger platform, the system comprising:

at least one computer hardware processor;

a root right expressed in a smart contract code; and

at least one memory device having computer readable instructions stored thereon which are configured to be executed by the at least one computer hardware processor;

wherein the root right expressed in the smart contract code is executed on the decentralized computing network, wherein the root right permits execution of specified functions to thereby create an immutable right;

wherein a right to permit execution of at least one of the specified functions is configured to be delegated from the root right to a wallet on the decentralized network to create a delegated right, wherein the wallet is configured to sign transactions corresponding to the at least one of the specified functions, wherein the delegated right is configured to be revoked or reassigned by the root right;

wherein a data structure is recorded in a delegation registry that represents the delegated right; and

wherein the wallet is configured to authorize a transaction on the decentralized computing network by signing the transaction with the wallet.

20. The system of claim 19 , wherein the smart contract code provides a party with signing authority on an assigning wallet assigned to the root right permission to delegate a second delegated right to a second wallet, thereby creating an extended right, and further comprising recording a second data structure in the delegation registry being accomplished in response to a delegation of the second delegated right resulting in the second data structure in the delegation registry referencing at least one smart contract wherein the second delegated right applies, the second delegated right, the assigning wallet, and the second wallet to which the second delegated right was delegated.

Assignments (4)
MERGER AND CHANGE OF NAME Recorded Apr 19, 2024
From: SECURRENCY, INC.; SNAPDRAGON MERGER SUB INC.; DTCC DIGITAL (US) INC.
To: DTCC DIGITAL (US) INC.
Reel/Frame 067159/0338 →
RELEASE OF PATENT SECURITY INTEREST RECORDED AT REEL 064015, FRAME 0699 Recorded Dec 11, 2023
From: WISDOMTREE, INC.
To: SECURRENCY, INC.
Reel/Frame 065844/0315 →
SECURITY INTEREST Recorded Jun 21, 2023
From: SECURRENCY, INC.
To: WISDOMTREE, INC., AS COLLATERAL AGENT
Reel/Frame 064015/0699 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2022
From: DONEY, GEORGE DANIEL
To: SECURRENCY INC.
Reel/Frame 060039/0986 →
Continuity (2)
Provisional Application 63037034 · Jun 10, 2020
Related Publication 20210390191A1 · Dec 16, 2021