IP Library › Granted Patent US 12,470,547
Granted Patent B2
US 12,470,547 · App. 18/471,786 · Granted Nov 11, 2025

File format and platform for storage and verification of credentials

Inventor: Shaunt M. Sarkissian (Reno, NV)
Assignee: Cortex MCP, Inc.
H04L63/083G06Q20/3274G06Q20/3821G06Q30/0251H04L63/08H04L63/0861H04L2463/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,547
App. No.
18/471,786
Granted
Nov 11, 2025
Kind
B2
Abstract

In various embodiments, a computer-implemented method for generating and verifying officially verifiable electronic representations may be disclosed. The method may include storing information associated with a credential of a user for proving the user's identity or qualifications; receiving a file generation request to provide authentication of the user based on the information associated with the credential; generating a file comprising a virtual representation of the credential that has been verified by an issuing agency to be an official representation of the credential; transmitting the file; receiving a verifying request whether the file transmitted to the user authenticates the user; verifying that a NFC or Bluetooth protocol-based communication associated with the file corresponds with the credential of the user, in response to the verifying request; and transmitting an authentication message indicating whether the NFC or Bluetooth protocol-based communication corresponds to the information associated with the credential of the user.

Claims (46)

1 . A computer-implemented method of electronically authenticating a user, the method comprising:

receiving, via a processor of an officially verifiable electronic representation (OVER) engine, an OVER file generation request comprising a credential identifier from an OVER file storage client, wherein the credential identifier is associated with a physical credential of the user;

receiving, via the processor of the OVER engine, a verification of the credential identifier via an issuing agency associated with the physical credential of the user;

receiving, via the processor of the OVER engine, a status indicator providing a validity of the physical credential of the user from the issuing agency associated with the physical credential of the user;

generating, via the processor of the OVER engine, an OVER file comprising a virtual representation of a physical credential of the user based on the verification of the credential identifier and the status indicator providing the validity of the physical credential of the user;

generating, via the processor of the OVER engine, a device identifier associated with the OVER file, wherein the device identifier limits use of the OVER file to the OVER file storage client;

generating, via the processor of the OVER engine, a reference to a remotely stored credential, wherein the reference comprises a hash code, a pointer, or a network address, or combinations thereof;

transmitting, via the processor of the OVER engine, the OVER file to an OVER file storage client device of the user in response to an OVER file generation request; and

authenticating, via the processor of the OVER engine, the user by correlating the credential identifier to information provided via a request to authenticate the user.

2 . The computer-implemented method of claim 1 , wherein the remotely stored credential can be accessed via the reference stored in an OVER file datastore.

3 . The computer-implemented method of claim 1 , further comprising transmitting, via the processor of the OVER engine, an authentication message comprising an authentication of the user to an OVER file third-party client verifying device based on the correlation.

4 . The computer-implemented method of claim 1 , wherein the request to authenticate the user comprises an information code in a form of a networked or radio transmission.

5 . The computer-implemented method of claim 4 , wherein the networked or radio transmission comprises a Near Field Communication (NFC) or Bluetooth protocol.

6 . The computer-implemented method of claim 1 , wherein the request to authenticate the user comprises sensor information.

7 . The computer-implemented method of claim 6 , wherein the sensor information comprises a bump.

8 . The computer-implemented method of claim 1 , further comprising generating, via the processor of the OVER engine, a status indicator associated with the OVER file based on the status indicator.

9 . The computer-implemented method of claim 8 , further comprising checking, via the processor of the OVER engine, the status indicator associated with physical credential.

10 . The computer-implemented method of claim 1 , wherein the OVER file comprises a portion of the credential identifier associated with the physical credential.

11 . The computer-implemented method of claim 1 , further comprising:

receiving, via the processor of the OVER engine, additional credential information from the issuing agency of the physical credential, wherein the additional credential information comprises information not provided in or contradictory to the OVER file generation request.

12 . The computer-implemented method of claim 11 , wherein generation of the OVER file is further based on the additional credential information.

13 . The computer-implemented method of claim 11 , wherein the additional credential information comprises a legal name associated with the physical credential, an address associated with the physical credential, or a birth date associated with the physical credential, or combinations thereof.

14 . The computer-implemented method of claim 11 , wherein the additional credential information comprises an image associated with the physical credential.

15 . The computer-implemented method of claim 14 , further comprising:

embedding, via the processor of the OVER engine, the image associated with the physical credential into the OVER file.

16 . The computer-implemented method of claim 14 , wherein the image associated with the physical credential comprises an image of the physical credential, an image of the user, or a logo of the issuing agency of the physical credential, or combinations thereof.

17 . An application gateway comprising a processor and a memory configured to store officially verifiable electronic representation (OVER) engine that, when executed by the processor, causes the application gateway to:

generate an OVER file comprising a virtual representation of a physical credential of a user, wherein the physical credential proves an identity of the user, a qualification of the user, or combinations thereof;

receive an agency authentication of the physical credential of the user and credential information associated with the physical credential from an issuing agency of the physical credential, wherein the agency authentication and credential information validate the generated OVER file as an authorized representation of the physical credential;

receive an OVER file generation request comprising a credential identifier, and wherein generating the OVER file generation request further comprises correlating the credential identifier to one of a plurality of physical credentials stored by the OVER engine;

generate a device identifier associated with the physical credential, wherein the device identifier limits use of the physical credential to an OVER file storage client device;

generate a reference to a remotely stored credential, wherein the reference comprises a hash code, a pointer, or a network address, or combinations thereof;

transmit the OVER file to an OVER file storage client device of the user in response to an OVER file generation request; and

authenticate the user by correlating the credential identifier to information provided via a request to authenticate the user.

18 . The application gateway of claim 17 , wherein, when executed by the processor, the OVER engine further causes the application gateway to transmit an authentication message comprising an authentication of the user to an OVER file third-party client verifying device based on the correlation.

19 . A system for authenticating a virtual representation of a physical credential, the system comprising:

an officially verifiable electronic representation (OVER) database configured to store a plurality of OVER files; and

an application gateway comprising a processor and a memory configured to store OVER engine that, when executed by the processor, causes the application gateway to:

generate an OVER file comprising a virtual representation of a physical credential of a user, wherein the physical credential proves an identity of the user, a qualification of the user, or combinations thereof;

receive an agency authentication of the physical credential of the user and credential information associated with the physical credential from an issuing agency of the physical credential, wherein the agency authentication and credential information valid ate the generated OVER file as an authorized representation of the physical credential;

receive an OVER file generation request comprising a credential identifier, and wherein generating the OVER file generation request further comprises correlating the credential identifier to one of a plurality of physical credentials stored by the OVER engine; and

generate a device identifier associated with the physical credential, wherein the device identifier limits use of the physical credential to an OVER file storage client device;

generate a reference to a remotely stored credential, wherein the reference comprises a hash code, a pointer, or a network address, or combinations thereof:

transmit the OVER file to an OVER file storage client device of the user in response to an OVER file generation request; and

authenticate the user by correlating the credential identifier to information provided via a request to authenticate the user.

20 . The system of claim 19 , wherein, when executed by the processor, the OVER engine further causes the application gateway to transmit an authentication message comprising an authentication of the user to an OVER file third-party client verifying device based on the correlation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2023
From: SARKISSIAN, SHAUNT M.
To: CORTEX MCP, INC.
Reel/Frame 065767/0632 →
Continuity (8)
Continuation 17715610 · Apr 7, 2022
Continuation 16893023 · Jun 4, 2020
Continuation 16422715 · May 24, 2019
Continuation 15887873 · Feb 2, 2018
Continuation 14982981 · Dec 29, 2015
Continuation 13794878 · Mar 12, 2013
Provisional Application 61740731 · Dec 21, 2012
Related Publication 20240089251A1 · Mar 14, 2024
References Cited (95)
US 7014107B2 · Singer et al. · 2006 [cited by applicant]
US 7290146B2 · Ekers et al. · 2007 [cited by applicant]
US 8132237B2 · Kang · 2012 [cited by applicant]
US 8458487B1 · Palgon et al. · 2013 [cited by applicant]
US 8923827B2 · Wentker et al. · 2014 [cited by applicant]
US 9251531B2 · Sarkissian · 2016 [cited by applicant]
US 9954854B2 · Sarkissian · 2018 [cited by applicant]
US 10749859B2 · Sarkissian · 2020 [cited by applicant]
US 11329973B2 · Sarkissian · 2022 [cited by applicant]
US 20070208665A1 · Ohara · 2007 [cited by applicant]
US 20080270166A1 · Morin et al. · 2008 [cited by applicant]
US 20090070268A1 · Sarkissian et al. · 2009 [cited by applicant]
US 20090113543A1 · Adams et al. · 2009 [cited by applicant]
US 20090249082A1 · Mattsson · 2009 [cited by applicant]
US 20090271321A1 · Stafford · 2009 [cited by applicant]
US 20090307756A1 · Kang · 2009 [cited by applicant]
US 20100070754A1 · Leach · 2010 [cited by applicant]
US 20100106596A1 · Grimes · 2010 [cited by applicant]
US 20100250389A1 · Augustin et al. · 2010 [cited by applicant]
US 20110184857A1 · Shakkarwar · 2011 [cited by applicant]
US 20110251892A1 · Laracey · 2011 [cited by applicant]
US 20110258122A1 · Shader et al. · 2011 [cited by applicant]
US 20110320316A1 · Randazza et al. · 2011 [cited by applicant]
US 20120016731A1 · Smith et al. · 2012 [cited by applicant]
US 20120150669A1 · Langley et al. · 2012 [cited by applicant]
US 20120151206A1 · Paris et al. · 2012 [cited by applicant]
US 20120173311A1 · Chang et al. · 2012 [cited by applicant]
US 20120197740A1 · Grigg et al. · 2012 [cited by applicant]
US 20120209749A1 · Hammad et al. · 2012 [cited by applicant]
US 20120240204A1 · Bhatnagar et al. · 2012 [cited by applicant]
US 20120310838A1 · Harris et al. · 2012 [cited by applicant]
US 20120316992A1 · Oborne · 2012 [cited by examiner]
US 20130054454A1 · Purves et al. · 2013 [cited by applicant]
US 20130212248A1 · Neafsey · 2013 [cited by examiner]
US 20130262315A1 · Hruska · 2013 [cited by applicant]
US 20140180787A1 · Sarkissian · 2014 [cited by applicant]
US 20140181927A1 · Sarkissian · 2014 [cited by applicant]
US 20140279475A1 · Castrechini et al. · 2014 [cited by applicant]
US 20150032627A1 · Dill et al. · 2015 [cited by applicant]
US 20150112790A1 · Wolinsky et al. · 2015 [cited by applicant]
US 20150269569A1 · Sarkissian et al. · 2015 [cited by applicant]
US 20150310419A1 · Kadaster et al. · 2015 [cited by applicant]
US 20150363808A1 · Maggio · 2015 [cited by applicant]
US 20160055322A1 · Thomas · 2016 [cited by applicant]
US 20160149896A1 · Sarkissian · 2016 [cited by applicant]
US 20190044936A1 · Sarkissian · 2019 [cited by applicant]
US 20190281043A1 · Sarkissian · 2019 [cited by applicant]
US 20210119987A1 · Sarkissian · 2021 [cited by applicant]
AU 2014236710A1 · 2015 [cited by applicant]
CA 2942643A1 · 2014 [cited by applicant]
CA 2934873C · 2019 [cited by applicant]
CA 3050656C · 2021 [cited by applicant]
EP 2936370A4 · 2016 [cited by applicant]
JP 2010516000A · 2010 [cited by applicant]
KR 1020040035223A · 2004 [cited by applicant]
KR 1020080104398A · 2008 [cited by applicant]
KR 101091410B1 · 2011 [cited by applicant]
KR 1020130060002A · 2013 [cited by applicant]
KR 1020130063593A · 2013 [cited by applicant]
WO 2008005018A2 · 2008 [cited by applicant]
WO 2008018744A1 · 2008 [cited by applicant]
WO 2014100628 · 2014 [cited by applicant]
WO 2014151944A1 · 2014 [cited by applicant]
U.S. Appl. No. 13/834,763, filed Mar. 15, 2013. [cited by applicant]
U.S. Appl. No. 14/031,757, filed Sep. 19, 2013. [cited by applicant]
International Search Report and Written Opinion of the International Searching Authority for International PCT Application No. PCT/US2013/077010 dated Apr. 17, 2014. [cited by applicant]
Supplemental EP Search Report for 13864820.9 dated May 31, 2016. [cited by applicant]
International Search Report and Written Opinion of the International Searching Authority for PCT Application No. PCT/US2014/026709 dated Jul. 28, 2014. [cited by applicant]
Examiner's Report for CA Patent Application No. 2942643 dated Apr. 9, 2022. [cited by applicant]
Examination Report No. 1 for AU Patent Application No. 2014236710 dated Apr. 18, 2020. [cited by applicant]
U.S. Appl. No. 61/598,219, filed Feb. 13, 2012. [cited by applicant]
Steiner et al., “Kerberos: An Authentication Service for Open Network Systems.” Usenix Winter (1988). [cited by applicant]
Cross River, “Tokenization in Card Networks” (May 2023). [cited by applicant]
Heather Mark, “Shift4: Secure Payment Processing” (2006). [cited by applicant]
Tom Arnold, “Credit Card Information Surrogate: A Method and System for using surrogates to integrate PCI-level security for legacy information systems.” (2007). [cited by applicant]
Brown et al. “Microsoft Code Name ‘Geneva’ Framework Whitepaper for Developers” (2008). [cited by applicant]
Thakar et al. PCI Compliance for Dummies (2009), in 2 documents. [cited by applicant]
Ben Jackson, “Token Gestures.” Digital Transactions (2009). [cited by applicant]
First Data, “Data Encryption and Tokenization: An Innovative One-Two Punch to Increase Data Security and Reduce the Challenges of PCI DSS Compliance.” (2009). [cited by applicant]
ProPay Press Release, “ProPay Adds Automated Clearing House (ACH) Data Encryption and Tokenization to Its Suite of ProtectPay Services.” (May 10, 2010). [cited by applicant]
Richard J. Sullivan, “The Changing Nature of U.S. Card Payment Fraud: Issues for Industry and Public Policy.” (2010). [cited by applicant]
CyberSource. “CyberSource Electronic Check Services Implementation Guide” (2010). [cited by applicant]
Visa, “Visa Best Practices for Tokenization Version 1.0.” (2010). [cited by applicant]
PCI Security Standards Council. “Pci Dss Tokenization Guidelines.” (2011). [cited by applicant]
Tim Horton et al. “A Primer on Payment Security Technologies: Encryption and Tokenization.” (2011). [cited by applicant]
Guenther Starnberger et al. “QR-TAN: Secure Mobile Transaction Authentication.” 2009 International Conference on Availability, Reliability and Security. IEEE. (2009). [cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]