IP Library › Granted Patent US 12,217,245
Granted Patent B2
US 12,217,245 · App. 17/174,650 · Granted Feb 4, 2025

Systems and methods for distributed ledger-based institutional identity management

Inventors: Christine Moy (New York, NY); Tyrone Lobban (London, GB); George Kassis (London, GB); Vishakh Vishakh (New York, NY); Bhaskar Kishore (Greater Noida, IN); Navkiran Arneja (Westbury, NY)
Assignee: JPMORGAN CHASE BANK, N.A.
G06Q20/3674G06Q20/363G06Q20/38215G06Q20/3825
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,217,245
App. No.
17/174,650
Filed
Feb 12, 2021
Granted
Feb 4, 2025
Kind
B2
Examiner
LEE, CLAY C
Art Unit
3699
USPC
705/67
Abstract

Systems and methods for distributed ledger-based identity management are disclosed. In one embodiment, a computer-based method for managing attestations may include: (1) receiving, by a computer program executed by an electronic device for an identity consumer and from an identity provider, a notification from an identity provider server that an attestation is available, wherein the attestation may be generated by the identity provider based on authorization from a system operator and may include a chain of trust comprising an identification of the system operator and the identity provider; (2) requesting, by the computer program, the attestation from the identity provider; and (3) downloading, by the computer program, the attestation to an identity consumer electronic wallet for the identity consumer. The identity provider may commit the downloading of the attestation to a distributed ledger, wherein the distributed ledger maintains a current status for the attestation.

Claims (48)

1. A computer-based method for providing attestations for an identity consumer from an identity provider to a relying party, comprising:

providing, by the identity consumer to an identity provider server for the identity provider, identity consumer information;

validating, by the identity provider server, the identity consumer information;

receiving, by the identity provider server, a root attestation from a system operator that authorizes the identity provider server to issue identity provider attestations;

generating, by the identity provider server, an identity provider attestation comprising an attestation about the identity consumer information;

generating, by the identity provider server, a nested attestation comprising the identity provider attestation and the root attestation, wherein the nested attestation establishes a chain of trust by building the identity provider attestation on the root attestation in a single attestation;

receiving, by an identity consumer computer program executed by an electronic device for the identity consumer and from the identity provider server, a notification that the nested attestation is available;

requesting, by the identity consumer computer program, the nested attestation from the identity provider server;

downloading, by the identity consumer computer program, the nested attestation to an identity consumer electronic wallet for the identity consumer;

committing, by the identity provider server, the nested attestation to a distributed ledger, wherein the distributed ledger maintains a current status for the root attestation and the identity provider attestation;

receiving, by the identity consumer computer program and from a relying party computer application for the relying party, a request for the nested attestation;

generating, by the identity consumer computer program, a machine-readable code for the nested attestation that is stored in the identity consumer electronic wallet;

communicating, by the identity consumer computer program and to the relying party computer application, the machine-readable code for the nested attestation;

extracting, by the relying party computer application, the nested attestation from the machine-readable code;

identifying, by the relying party computer application, the root attestation and the identity provider attestation from the nested attestation;

verifying, by the relying party computer application and on the distributed ledger, that the root attestation and the identity provider attestation are valid and active; and

executing, by the relying party computer application, an action based on reliance on the verification.

2. The computer-based method of claim 1 , wherein the identity provider attestation comprises a license, a certificate, a credential, or an authorization.

3. The computer-based method of claim 1 , wherein the identity provider comprises one of a financial institution, a government agency, an employer, and a legal entity.

4. The computer-based method of claim 1 , wherein the identity provider attestation comprises an identification of an attestor, an identification of an attestee, a type of identity provider attestation, and a date of issuance.

5. The computer-based method of claim 1 , wherein the identity consumer electronic wallet comprises a wallet application, a mobile wallet, or a web-based wallet.

6. The computer-based method of claim 1 , wherein the current status of the root attestation or the identity provider attestation comprises valid, expired, or revoked.

7. The computer-based method of claim 1 , wherein the relying party computer application periodically verifies the current status of the root attestation or the identity provider attestation using the distributed ledger.

8. The computer-based method of claim 1 , wherein the relying party receives a notification that the root attestation or the identity provider attestation is revoked or expired from the distributed ledger.

9. A computer-based method for sending an object using attestations, comprising:

providing, by an identity consumer computer program executed by an identity consumer electronic device to an identity provider server for an identity provider, identity consumer information for an identity consumer;

receiving, by the identity provider server, a root attestation from a system operator that authorizes the identity provider server to issue identity provider attestations;

generating, by the identity provider server, an identity provider attestation comprising an attestation about the identity consumer information;

generating, by the identity provider server, a nested attestation comprising the identity provider attestation and the root attestation, wherein the nested attestation establishes a chain of trust by building the identity provider attestation on the root attestation in a single attestation;

receiving, by the identity consumer computer program, an identity of an object to sign;

requesting, by the identity consumer computer program the nested attestation from the identity provider server;

receiving, by the identity consumer computer program, the nested attestation;

storing, by the identity consumer computer program, the nested attestation in an identity consumer electronic wallet for the identity consumer;

retrieving, by the identity consumer computer program, the object;

signing, by the identity consumer computer program, the object with the nested attestation that is stored in the identity consumer electronic wallet by embedding the attestation in the object;

sending, by the identity consumer computer program, the signed object to a receiving party computer program executed by an electronic device for a receiving party;

extracting, by the receiving party computer program, the nested attestation from the object; and

verifying, by the receiving party computer program and on a distributed ledger that maintains a current status for the root attestation and the identity provider attestation, that the root attestation and the identity provider attestation are valid and active.

10. The computer-based method of claim 9 , wherein the object comprises a document, and the identity provider attestation attests that the identity consumer is authorized to sign the document.

11. The computer-based method of claim 9 , wherein the object is a payment, and the identity provider attestation attests that the identity consumer is authorized to make the payment.

12. The computer-based method of claim 9 , wherein the object comprises digital currency.

13. The computer-based method of claim 9 , wherein the identity provider attestation comprises a license, a certificate, a credential, or an authorization, and further comprises an identification of an attestor, an identification of an attestee, a type of identity provider attestation, and a date of issuance.

14. The computer-based method of claim 9 , further comprising:

generating, by the identity provider server, a receiving party attestation comprising an attestation about the receiving party;

generating, by the identity provider server, a receiving party nested attestation comprising the receiving party attestation and the root attestation, wherein the nested attestation establishes a chain of trust by building the receiving party attestation on the root attestation in a single attestation;

receiving, by the identity provider computer program and from the receiving computer program, a request for the object and the receiving party nested attestation; and

verifying, by the identity consumer computer program and on the distributed ledger, that the root attestation and the receiving party attestation are valid and active before sending the object to the receiving party.

15. The computer-based method of claim 14 , wherein the receiving party attestation attests to an account for the receiving party.

Continuity (3)
Provisional Application 63126335 · Dec 16, 2020
Provisional Application 62976262 · Feb 13, 2020
Related Publication 20210256508A1 · Aug 19, 2021
References Cited (14)
US 20170111175A1 · Oberhauser · 2017 [cited by examiner]
US 20170250972A1 · Ronda et al. · 2017 [cited by applicant]
US 20170353435A1 · Pritikin · 2017 [cited by examiner]
US 20190230073A1 · Patel et al. · 2019 [cited by applicant]
US 20190260594A1 · Singhal · 2019 [cited by examiner]
US 20190296904A1 · Smith · 2019 [cited by examiner]
US 20200042958A1 · Soundararajan · 2020 [cited by examiner]
US 20200076601A1 · Tabrizi · 2020 [cited by examiner]
US 20210012447A1 · Glaude · 2021 [cited by examiner]
US 20210097528A1 · Wang · 2021 [cited by examiner]
WO WO2016128569A1 · 2016 [cited by examiner]
Lee, J., “Collective Attestation for Manageable IoT Environments”, Applied Sciences 8.12 MDPI AG. (Dec. 2018) (Year: 2018). [cited by examiner]
International Search Report, dated Jun. 1, 2021, from corresponding International Application No. PCT/US2021/017832. [cited by applicant]
Written Opinion of the International Searching Authority, dated Jun. 1, 2021, from corresponding International Application No. PCT/US2021/017832. [cited by applicant]