IP Library Granted Patent US 9,372,972
Granted Patent B2
US 9,372,972 · App. 14/410,305 · Granted Jun 21, 2016

System and method for establishing and monetizing trusted identities in cyberspace with personal data service and user console

Inventors: David Hemphill Coxe (Vienna, VA); Robert Lloyd Coxe, Jr. (Vienna, VA); John Joseph Dials, Jr. (Vienna, VA); Christine W. McKay-Donovan (Vienna, VA)
Assignee: ID DATAWEB, INC.
G06F21/31G06F21/41G06F21/604G06Q20/00H04L9/3213H04L63/0815H04L63/0884H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,372,972
App. No.
14/410,305
Granted
Jun 21, 2016
Kind
B2
Abstract

A system and method for establishing and monetizing trusted identities in cyberspace relying upon user opt in. Users request to attain secure IDs for accessing parties that will rely on secure IDs to complete a transaction, for example merchants and service providers (relying parties). The relying parties (RPs) communicate with identity service providers and attribute providers via an Attribute Exchange Network (AXN) in order to obtain verified attributes associated with an entity (end user or user) that wishes to conduct business with the relying party. The relying party makes requests for verified attributes that are important to consummating business transactions for the relying party. Users are informed of requests for attributes on behalf of relying parties and users have the option to verify attributes, and add new attributes that may be useful or required for conducting business with relying parties.

Claims (43)

1. A method providing access to end user-asserted attributes, the method comprising:

receiving, by an attribute exchange network (AXN) device, a first credential asserted by an end-user to one or more relying parties (RPs);

requesting, by the AXN device, a first location of a first encrypted token associated with the asserted first credential from a database;

acquiring, by the AXN device, the first encrypted token associated with the asserted first credential from the first location;

acquiring, by the AXN device, from the first encrypted token a first set of attributes of the end user, wherein the first set of attributes includes verified attributes and further identifies permissions granted by the end user to the one or more RPs to view attributes selected from the first set of attributes; and

populating, by the AXN device, a web page with the first set of attributes and the permissions granted for each of the one or more RPs to view attributes selected from the first set of attributes.

2. The method of claim 1 further comprising linking, by the AXN device, a second credential to the first credential.

3. The method of claim 2 further comprising:

acquiring, by the AXN device, the second credential using the first credential;

requesting, by the AXN device, a second location of a second encrypted token associated with the second credential;

acquiring, by the AXN device, the second encrypted token associated with the second credential from the second location;

acquiring, by the AXN device, from the second encrypted token a second set of attributes of the end user, wherein the second set of attributes further identifies permissions granted by the end user to the one or more RPs to view attributes selected from the second set of attributes; and

populating, by the AXN device, the web page with the second set of attributes and the permissions granted for each of the one or more RPs to view attributes selected from the second set of attributes.

4. An attribute exchange network (AXN) device, comprising:

a memory; and

a processor coupled to the memory, wherein the processor is configured with processor-executable instructions to perform operations comprising:

receiving a first credential asserted by an end-user to one or more relying parties (RPs);

requesting from a database a first location of a first encrypted token associated with the asserted first credential;

acquiring the first encrypted token associated with the asserted first credential from the first location;

acquiring from the first encrypted token a first set of attributes of the end user, wherein the first set of attributes includes verified attributes and further identifies permissions granted by the end user to the one or more RPs to view attributes selected from the first set of attributes; and

populating a web page with the first set of attributes and the permissions granted for each of the one or more RPs to view attributes selected from the first set of attributes.

5. The AXN device of claim 4 , wherein the processor is configured with processor-executable instructions to perform operations further comprising:

linking a second credential to the first credential.

6. The AXN device of claim 5 , wherein the processor is configured with processor-executable instructions to perform operations further comprising:

acquiring the second credential using the first credential;

requesting a second location of a second encrypted token associated with the second credential;

acquiring the second encrypted token associated with the second credential from the second location;

acquiring from the second encrypted token a second set of attributes of the end user, wherein the second set of attributes further identifies permissions granted by the end user to the one or more RPs to view attributes selected from the second set of attributes; and

populating the web page with the second set of attributes and the permissions granted for each of the one or more RPs to view attributes selected from the second set of attributes.

7. A non-transitory computer readable storage medium having stored thereon processor-executable software instructions configured to cause a processor in an attribute exchange network (AXN) device to perform operations comprising:

receiving a first credential asserted by an end-user to one or more relying parties (RPs);

requesting from a database a first location of a first encrypted token associated with the asserted first credential;

acquiring the first encrypted token associated with the asserted first credential from the first location;

acquiring from the first encrypted token a first set of attributes of the end user, wherein the first set of attributes includes verified attributes and further identifies permissions granted by the end user to the one or more RPs to view attributes selected from the first set of attributes; and

populating a web page with the first set of attributes and the permissions granted for each of the one or more RPs to view attributes selected from the first set of attributes.

8. The AXN device of claim 4 , wherein the stored processor-executable software instructions are configured to cause a processor to perform operations comprising:

linking a second credential to the first credential.

9. The AXN device of claim 5 , wherein the stored processor-executable software instructions are configured to cause a processor to perform operations comprising:

acquiring the second credential using the first credential;

requesting a second location of a second encrypted token associated with the second credential;

acquiring the second encrypted token associated with the second credential from the second location;

acquiring from the second encrypted token a second set of attributes of the end user, wherein the second set of attributes further identifies permissions granted by the end user to the one or more RPs to view attributes selected from the second set of attributes; and

populating the web page with the second set of attributes and the permissions granted for each of the one or more RPs to view attributes selected from the second set of attributes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2015
From: COXE, DAVID HEMPHILL; COXE, ROBERT LLOYD, JR.; DIALS, JOHN JOSEPH, JR.; MCKAY-DONOVAN, CHRISTINE W.
To: ID DATAWEB, INC.
Reel/Frame 034959/0212 →
Continuity (6)
Provisional Application 61666560 · Jun 29, 2012
Provisional Application 61676140 · Jul 26, 2012
Provisional Application 61753247 · Jan 16, 2013
Provisional Application 61762527 · Feb 8, 2013
Provisional Application 61764619 · Feb 14, 2013
Related Publication 20150332029A1 · Nov 19, 2015