IP Library › Granted Patent US 12,621,284
Granted Patent B2
US 12,621,284 · App. 18/607,214 · Granted May 5, 2026

Systems and methods for user authentication using subject identifier and/or subject identifier documents

Inventors: Abbie Barbir (Hartford, CT); Alan Bachmann (Hartford, CT); Erick Verry (Hartford, CT); Paul Ivanivsky (Hartford, CT); Cisa Kurian (Hartford, CT); Neal Shah (Hartford, CT); Michael Streuling (Hartford, CT)
Assignee: Aetna Inc.
H04L63/0815H04L63/0442H04L63/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,284
App. No.
18/607,214
Filed
Mar 15, 2024
Granted
May 5, 2026
Kind
B2
Art Unit
2433
USPC
726/8
Abstract

In some instances, a method is provided. The method comprises: generating a first subject identifier for the first domain, wherein the first subject identifier comprises a plurality of elements, wherein at least one of the plurality of elements comprises a subject identifier fragment indicating a unique identifier string for the user; based on a second user request to access second content for a second domain from the user device associated with the user, determining whether the user is enrolled into the subject identifier authentication; in response to determining that the user is enrolled into the subject identifier authentication for the first domain, generating a second subject identifier for the user for the second domain based on the subject identifier fragment from the first subject identifier for the first domain; and granting access to the second content for the second domain based on generating the second subject identifier.

Claims (82)

1 . A system, comprising:

a first back-end application system that is associated with a first domain and is configured to:

receive a first content request for accessing content on the first domain from a user device associated with a user; and

based on the first content request, provide a first identification request to an identity broker system;

the identity broker system, wherein the identity broker system is configured to:

based on receiving the first identification request, determine whether the user is enrolled in subject identifier authentication; and

based on determining that the user is not enrolled in the subject identifier authentication, generate a first subject identifier for the first domain, wherein the first subject identifier comprises a plurality of elements, wherein at least one of the plurality of elements comprises a subject identifier fragment, wherein the subject identifier fragment indicates a unique identifier string for the user; and

a second back-end application system that is associated with a second domain and is configured to:

receive a second content request for accessing content on the second domain from the user device associated with the user; and

based on the second content request, provide a second identification request to the identity broker system, and

wherein the identity broker system is further configured to:

based on receiving the second identification request, determine that the user is enrolled in the subject identifier authentication for the first domain;

generate a second subject identifier for the user based on the subject identifier fragment from the first subject identifier for the first domain;

generate a subject identifier document associated with the second subject identifier, wherein the second subject identifier resolves to a storage location for the subject identifier document;

generate a public and private key pair for the second domain, wherein the public key of the public and private key pair is included within the subject identifier document; and

grant access to the content on the second domain based on using the public and private key pair for the second domain.

2 . The system of claim 1 , wherein the first subject identifier is a first decentralized identifier (DID) and the second subject identifier is a second DID, wherein the plurality of elements of the first DID comprise a scheme element, a DID method element, and a namespace specific string, wherein a portion of the namespace specific string indicates the subject identifier fragment, and wherein the identity broker system is configured to generate the second DID by using the portion of the namespace specific string of the first DID that indicates the subject identifier fragment.

3 . The system of claim 1 , wherein the identity broker system is further configured to:

subsequent to generating the first subject identifier for the first domain, provide, to the user device, an identity request for use in identity binding;

receive, from the user device, user authentication enrollment information indicating one or more biometric features of the user; and

perform the identity binding for the user by binding the user authentication enrollment information with the generated first subject identifier for the user, wherein determining that the user is enrolled in the subject identifier authentication for the first domain is based on the user authentication enrollment information being bound to the generated first subject identifier.

4 . The system of claim 3 , wherein the identity broker system is further configured to:

provide, to the user device, a device request for use in device binding;

receive, from the user device, device information associated with the user device; and

perform the device binding for the user device by binding the device information with the generated first subject identifier for the user and the user authentication enrollment information, wherein determining that the user is enrolled in the subject identifier authentication for the first domain is based on the device information being bound to the generated first subject identifier.

5 . The system of claim 4 , wherein the identity broker system is configured to generate the second subject identifier for the user by:

retrieving the generated first subject identifier that is bound to the user authentication enrollment information and the device information; and

generating the second subject identifier by using the subject identifier fragment from the retrieved first subject identifier.

6 . The system of claim 5 , wherein the first subject identifier comprises an element, from the plurality of elements, indicating the subject identifier fragment and the first domain, and wherein the generated second subject identifier comprises an element indicating the subject identifier fragment and the second domain.

7 . The system of claim 1 , wherein the identity broker system is further configured to:

based on a new content request for accessing the content on the second domain, determine that the user is enrolled in the subject identifier authentication for the second domain using the second subject identifier; and

provide instructions to the second back-end application system to grant access to the content based on determining that the user is enrolled in the subject identifier authentication for the second domain.

8 . The system of claim 7 , wherein the identity broker system is configured to determine that the user is enrolled in the subject identifier authentication for the second domain using the second subject identifier by:

based on an authentication request, obtaining authentication information from the user device;

comparing the authentication information with user authentication enrollment information stored in a wallet system; and

determining that the user is enrolled in the subject identifier authentication for the second domain based on the comparison and using the second subject identifier.

9 . The system of claim 7 , wherein the identity broker system is configured to determine that the user is enrolled in the subject identifier authentication for the second domain using the second subject identifier by:

based on a device verification request, obtaining device information from the user device;

comparing the device information from the user device with device information stored in a wallet system; and

determining that the user is enrolled in the subject identifier authentication for the second domain based on the comparison and using the second subject identifier.

10 . The system of claim 7 , wherein the identity broker system is configured to determine that the user is enrolled in the subject identifier authentication for the second domain using the second subject identifier by:

providing a challenge to the user device;

receiving a signed challenge from the user device, wherein the user device signed the challenge using the private key of the public and private key pair for the second domain;

resolving the second subject identifier to determine the storage location of the subject identifier document;

retrieving the public key from the subject identifier document based on the determined storage location; and

verifying that the user is enrolled in the subject identifier authentication based on using the public key from the subject identifier document and the signed challenge from the user device.

11 . The system of claim 1 , wherein the identity broker system is further configured to:

bind the first subject identifier, the second subject identifier, and the subject identifier document together within a wallet system.

12 . A method, comprising:

based on a first content request to access first content for a first domain from a user device associated with a user, generating a first subject identifier for the first domain, wherein the first subject identifier comprises a plurality of elements, wherein at least one of the plurality of elements comprises a subject identifier fragment indicating a unique identifier string for the user;

based on a second user request to access second content for a second domain from the user device associated with the user, determining whether the user is enrolled into subject identifier authentication;

in response to determining that the user is enrolled into the subject identifier authentication for the first domain, generating a second subject identifier for the user for the second domain based on the subject identifier fragment from the first subject identifier for the first domain;

generating a subject identifier document associated with the second subject identifier, wherein the second subject identifier resolves to a storage location for the subject identifier document;

generating a public and private key pair for the second domain, wherein the public key of the public and private key pair is included within the subject identifier document; and

granting access to the second content for the second domain based on using the public and private key pair for the second domain.

13 . The method of claim 12 , wherein the first subject identifier is a first decentralized identifier (DID) and the second subject identifier is a second DID, wherein the plurality of elements of the first DID comprise a scheme element, a DID method element, and a namespace specific string, wherein a portion of the namespace specific string indicates the subject identifier fragment, and wherein generating the second subject identifier comprises generating the second DID using the portion of the namespace specific string of the first DID that indicates the subject identifier fragment.

14 . The method of claim 12 , further comprising:

subsequent to generating the first subject identifier for the first domain, providing, to the user device, an identity request for use in identity binding;

receiving, from the user device, user authentication enrollment information indicating one or more biometric features of the user; and

performing the identity binding for the user by binding the user authentication enrollment information with the generated first subject identifier for the first domain, wherein determining whether the user is enrolled into the subject identifier authentication is based on the user authentication enrollment information being bound to the generated first subject identifier.

15 . The method of claim 14 , further comprising:

providing, to the user device, a device request for use in device binding;

receiving, from the user device, device information associated with the user device; and

performing the device binding for the user device by binding the device information with the generated first subject identifier for the first domain and the user authentication enrollment information, wherein determining whether the user is enrolled into the subject identifier authentication is based on the device information being bound to the generated first subject identifier.

16 . The method of claim 15 , wherein generating the second subject identifier for the user comprises:

retrieving the generated first subject identifier that is bound to the user authentication enrollment information and the device information; and

generating the second subject identifier by using the subject identifier fragment from the retrieved first subject identifier.

17 . The method of claim 16 , wherein the first subject identifier comprises an element, from the plurality of elements, indicating the subject identifier fragment and the first domain, and wherein the generated second subject identifier comprises an element indicating the subject identifier fragment and the second domain.

18 . The method of claim 12 , further comprising:

binding the first subject identifier, the second subject identifier, and the subject identifier document together within a wallet system.

19 . A non-transitory computer-readable medium having processor-executable instructions stored thereon, wherein the processor-executable instructions, when executed, facilitate:

based on a first content request to access first content for a first domain from a user device associated with a user, generating a first subject identifier for the first domain, wherein the first subject identifier comprises a plurality of elements, wherein at least one of the plurality of elements comprises a subject identifier fragment indicating a unique identifier string for the user;

based on a second user request to access second content for a second domain from the user device associated with the user, determining whether the user is enrolled into subject identifier authentication;

in response to determining that the user is enrolled into the subject identifier authentication for the first domain, generating a second subject identifier for the user for the second domain based on the subject identifier fragment from the first subject identifier for the first domain;

granting access to the second content for the second domain based on generating the second subject identifier;

based on a new content request for accessing the second content on the second domain, providing a challenge to the user device;

receiving a signed challenge from the user device, wherein the user device signed the challenge using a private key for the second domain;

resolving the second subject identifier to determine a storage location of a subject identifier document, wherein the subject identifier document comprises a public key that is a key pair to the private key;

retrieving the public key from the subject identifier document based on the determined storage location;

verifying that the user is enrolled in the subject identifier authentication based on using the public key from the subject identifier document and the signed challenge from the user device; and

granting access to the second content based on determining that the user is enrolled in the subject identifier authentication for the second domain.

20 . The non-transitory computer-readable medium of claim 19 , wherein the first subject identifier is a first decentralized identifier (DID) and the second subject identifier is a second DID, wherein the plurality of elements of the first DID comprise a scheme element, a DID method element, and a namespace specific string, wherein a portion of the namespace specific string indicates the subject identifier fragment, and wherein generating the second subject identifier comprises generating the second DID using the portion of the namespace specific string of the first DID that indicates the subject identifier fragment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2024
From: BARBIR, ABBIE; BACHMANN, ALAN; VERRY, ERICK; IVANIVSKY, PAUL; KURIAN, CISA; SHAH, NEAL; STREULING, MICHAEL
To: AETNA INC.
Reel/Frame 066803/0584 →
Continuity (1)
Related Publication 20250294017A1 · Sep 18, 2025
References Cited (9)
US 6256737B1 · Bianco · 2001 [cited by examiner]
US 20010011274A1 · Klug · 2001 [cited by examiner]
US 20110276627A1 · Blechar · 2011 [cited by examiner]
US 20150127943A1 · Luo · 2015 [cited by examiner]
US 20170222822A1 · Lopez · 2017 [cited by examiner]
US 20200027091A1 · Hassani et al. · 2020 [cited by applicant]
US 20220345297A1 · Barbir · 2022 [cited by examiner]
US 20250202882A1 · Griffin-Allwood et al. · 2025 [cited by applicant]
CN 110769001 · 2022 [cited by examiner]