IP Library Granted Patent US 11,558,201
Granted Patent B2
US 11,558,201 · App. 17/313,739 · Granted Jan 17, 2023

Self-authenticating digital identity

Inventor: Louis Gasparini (San Mateo, CA)
Assignee: Banco Bilbao Vizcaya Argentaria, S.A.
H04L9/3255H04L9/14H04L9/30H04L9/3242H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,558,201
App. No.
17/313,739
Granted
Jan 17, 2023
Kind
B2
Abstract

A method of creating and applying a self-authenticating digital identity for a user having an identity is described.

Claims (23)

1. A method of creating and applying a self-authenticating digital identity for a user having an identity, wherein the method comprises:

receiving, by an identity provider computing system, a request for the self-authenticating digital identity;

verifying, by the identity provider computing system, the identity of the user;

delivering, by the identity provider computing system based on the verifying, an identity assertion to a user computing system associated with the user;

creating, by the user computing system, a first aggregated identity assertion comprising the identity assertion received from the identity provider computing system and a public encryption key associated with the user;

digitally signing, by the user computing system, the first aggregated identity assertion with a private encryption key associated with the user;

delivering, by the user computing system, the digitally signed first aggregated identity assertion to the identity provider computing system;

validating, by the identity provider computing system, the digitally signed first aggregated identity assertion;

creating, by the identity provider computing system, a second aggregated identity assertion comprising the first aggregated identity assertion received from the user computing system, a date, and a public encryption key associated with the identity provider computing system;

digitally signing, by the identity provider computing system, the second aggregated identity assertion;

delivering, by the identity provider computing system, the digitally signed second aggregated identity assertion to the user computing system, wherein the digitally signed second aggregated identity assertion constitutes the self-authenticating digital identity;

sending, by the user computing system, the self-authenticating digital identity to a relying party computing system; and

confirming, by the relying party computing system, that the identity provider computing system is a trusted issuer by using a third party identity broker service.

2. The method of claim 1 , further comprising:

verifying, by the user computing system to the relying party computing system, that the user computing system possesses the private encryption key associated with the user.

3. The method of claim 2 , further comprising:

evaluating, by the relying party computing system, the verifying performed by the user computing system to provide assurance regarding the validity of the self-authenticating identity.

4. The method of claim 1 , wherein the confirming that the identity provider computing system is the trusted issuer comprises confirming the public key of the identity provider computing system with the third party identity broker service.

5. The method of claim 4 , further comprising validating, by the relying party computing system, an authenticity of the self-authenticating identity by making an inquiry to the third party identity broker service as to whether the self-authenticating identity is still valid.

6. The method of claim 1 , wherein the identity assertion includes a confidence level.

7. The method of claim 1 , wherein one or more of the public encryption keys is a hashed public key.

8. The method of claim 1 , wherein the second aggregated identity assertion is digitally signed with a private encryption key associated with the identity provider computing system.

9. The method of claim 1 , wherein the second aggregated identity assertion is digitally signed with a group or ring signature.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2021
From: GASPARINI, LOUIS
To: COVAULT INC.
Reel/Frame 056161/0821 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2021
From: COVAULT INC.
To: BANCO BILBAO VIZCAYA ARGENTARIA, S.A.
Reel/Frame 056161/0861 →
Continuity (3)
Continuation 15908554 · Feb 28, 2018
Provisional Application 62465431 · Mar 1, 2017
Related Publication 20210258170A1 · Aug 19, 2021