IP Library Granted Patent US 12,301,572
Granted Patent B2
US 12,301,572 · App. 18/231,541 · Granted May 13, 2025

Computer-implemented systems for distributed authorization and federated privacy exchange

Inventors: Mike Cook (Toronto, CA); Alec Laws (Toronto, CA); James Carter (Toronto, CA)
Assignee: IDENTOS Inc.
H04L63/0884H04L63/0807H04L63/0815H04L63/0892H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,572
App. No.
18/231,541
Granted
May 13, 2025
Kind
B2
Abstract

Computer-implemented systems and methods for authorization are provided. A system for distributed authorization includes a resource server which stores a protected resource of a resource owner and a service provider client device which provides a service which uses the protected resource. The system also includes a federated privacy exchange system configured to provide an authorization service for allowing the service provider client device to access the protected resource according to permissions data. The federated privacy exchange system includes a privacy-respecting authorization server configured to store a resource definition for the protected resource, and an agent device configured to provide an agent interface for managing credentials and controlling permissions and policies at the authorization server and store protected data including any one or more of account identifier data, authenticator data, resource server relationship data, and permissions data.

Claims (46)

1. A computer-implemented system for distributed authorization, the system comprising:

a resource server which stores a protected resource of a resource owner;

a service provider client device configured to provide a service which uses the protected resource and request an access token authorizing access to the protected resource and a resource location for the protected resource;

an authorization hardware server configured to provide an authorization service for allowing the service provider client device to access the protected resource without the service provider client device knowing the resource server and the resource location in advance, the authorization hardware server configured to:

register the protected resource against a generic resource definition according to an interface schema of the generic resource definition, wherein the generic resource definition does not identify the resource owner and can be mapped by the resource server to the protected resource when responding to the service provider client device upon successful authorization of access to the protected resource;

receive the request from the service provider client device and issue a generic request to an agent device based on the generic resource definition; and

issue the access token and the resource location to the service provider client device based on a response from the agent device;

the agent device, configured to:

provide a user interface for the resource owner to manage interactions with the authorization hardware server; and

issue the response to the generic request to the authorization hardware server, wherein the response meets requirements of the generic resource definition and specifies the resource location.

2. The system of claim 1 , wherein the interactions include managing credentials and controlling permissions and policies at the authorization hardware server.

3. The system of claim 1 , wherein the agent device interacts with the authorization hardware server on behalf of the resource owner.

4. The system of claim 1 , wherein the agent device is user-controlled, and wherein the user is the resource owner.

5. A computer-implemented system for distributed authorization, the system comprising:

an authorization hardware server for providing an authorization service for allowing a service provider client device to access a protected resource of a resource owner stored at a resource server without the service provider client device knowing the resource server and a resource location for the protected resource in advance, the authorization hardware server configured to:

register the protected resource against a generic resource definition according to an interface schema of the generic resource definition, wherein the generic resource definition does not identify the resource owner and can be mapped by the resource server to the protected resource when responding to the service provider client device upon successful authorization of access to the protected resource;

receive a request from the service provider client device for an access token authorizing access to the protected resource and the resource location for the protected resource and issue a generic request to an agent device based on the generic resource definition; and

issue the access token and the resource location to the service provider client device based on a response from the agent device;

an agent device communicatively connected to the authorization hardware server, the agent device configured to:

provide a user interface for the resource owner to manage interactions with the authorization hardware server; and

issue the response to the generic request to the authorization hardware server, wherein the response meets requirements of the generic resource definition and specifies the resource location.

6. The system of claim 5 , wherein the authorization hardware server is further configured to store a privacy-respecting ledger of resource owner data including account data and permissions data.

7. The system of claim 5 , wherein the authorization hardware server is further configured to control any one or more of a governance registry and a registry of approved clients, resources servers, and agents.

8. The system of claim 5 , wherein the user interface is configured to perform any one or more of registering a new account, authenticating to an account, interacting with an authenticator, managing permissions, and handling client resource requests.

9. The system of claim 5 , wherein the authorization hardware server is further configured to delegate permission gathering and authentication to the agent device upon receiving a request from the service provider client device.

10. The system of claim 5 , wherein a client capability is registered generically against the generic resource definition.

11. The system of claim 5 , wherein the protected resource is registered generically against the generic resource definition.

12. The system of claim 5 , wherein the interactions include managing credentials and controlling permissions and policies at the authorization hardware server.

13. The system of claim 5 , wherein the agent device interacts with the authorization hardware server on behalf of the resource owner.

14. The system of claim 5 , wherein the agent device is user-controlled, and wherein the user is the resource owner.

15. A method of distributed authorization the method comprising:

at an authorization hardware server for providing an authorization service for allowing a service provider client device to access a protected resource of a resource owner stored at a resource server without the service provider client knowing the resource server and a resource server location for the protected resource in advance, registering the protected resource generically against a generic resource definition according to an interface schema of the generic resource definition, wherein the generic resource definition does not identify the resource owner and can be mapped by the resource server to the protected resource when responding to the service provider client upon successful authorization of access to the protected resource;

receiving, at the authorization hardware server, a request from the service provider client device for an access token authorizing access to the protected resource and the resource location;

providing, by the user device, a user interface for the resource owner to manage interactions with the authorization server;

issuing, by the authorization hardware server, a generic request to an agent device based on the generic resource definition;

issuing, by the agent device, a response to the generic request from the authorization hardware server, wherein the response meets requirements of the generic resource definition and specifies the resource location; and

issuing, by the authorization hardware server, the access token and the resource location to the service provider client device based on the response from the agent device.

16. The method of claim 15 , further comprising:

defining policy conditions comprising authorization grant rules at the authorization hardware server against the interface schema.

17. The method of claim 15 , further comprising:

fulfilling the interface schema for a specific service provider client by a specific resource server that receives a generic request from the specific service provider client and resolves the generic request.

18. The method of claim 15 , further comprising:

receiving, at the authorization hardware server, user consent allowing a specific resource server to fulfil the interface schema for a specific service provider client.

19. The method of claim 15 , further comprising:

defining, via the generic resource definition, contents of a successful response from the resource server to the service provider client upon successful authorization of access to the protected resource.

20. The method of claim 15 , further comprising providing, by the agent device, a user interface for the resource owner to manage credentials and control permissions and policies at the authorization hardware server.

Assignments (3)
SECURITY INTEREST Recorded Aug 21, 2025
From: IDENTOS INC.
To: THE BANK OF NOVA SCOTIA
Reel/Frame 072083/0632 →
SECURITY INTEREST Recorded Nov 11, 2024
From: IDENTOS INC.
To: BDC CAPITAL INC.
Reel/Frame 069197/0888 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2023
From: COOK, MIKE; LAWS, ALEC; CARTER, JAMES
To: IDENTOS INC.
Reel/Frame 064604/0816 →
Continuity (3)
Continuation 17150683 · Jan 15, 2021
Provisional Application 62961280 · Jan 15, 2020
Related Publication 20230388305A1 · Nov 30, 2023
References Cited (5)
US 20170099148A1 · Ochmanski · 2017 [cited by examiner]
US 20170324719A1 · Mason · 2017 [cited by examiner]
US 20180183802A1 · Choyi · 2018 [cited by examiner]
US 20190251241A1 · Bykampadi · 2019 [cited by examiner]
US 20190325129A1 · Wang · 2019 [cited by examiner]