IP Library › Granted Patent US 12,231,428
Granted Patent B2
US 12,231,428 · App. 18/396,358 · Granted Feb 18, 2025

Digital identity step-up

Inventors: Gregory Slowiak (Chicago, IL); Eric Woodward (San Francisco, CA); Philip Lam (San Francisco, CA); Jeff Shultz (Waco, TX)
Assignee: Early Warning Services, LLC
H04L63/0884G06F9/445G06V40/172
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,428
App. No.
18/396,358
Filed
Dec 26, 2023
Granted
Feb 18, 2025
Kind
B2
Art Unit
2433
USPC
726/7
Abstract

Described herein is an identity network for validating the digital identity of a user. The identity network may receive, from a relying party, an identity validation request to validate a digital identity of the user. The identity network may provide, to the relying party, a link associated with an identity provider application based on the identity validation request. The identity network may receive, from an identity provider associated with the identity provider application, a confirmation that the user has successfully accessed the identity provider application via the link. After receiving the confirmation, the identity network may receive from the identity provider, an attribute validation request to validate identity attributes of the user, where the attribute validation request includes a plurality of identity attributes of the user. The identity network may validate the digital identity of the user based on the plurality of identity attributes.

Claims (70)

1. A method for validating a digital identity of a user, comprising:

receiving, at an identity network from a relying party, an identity validation request to validate a digital identity of the user;

providing, from the identity network to the relying party, a link associated with an identity provider application based on the identity validation request;

receiving, at the identity network from an identity provider associated with the identity provider application, a confirmation that the user has successfully accessed the identity provider application via the link;

after receiving the confirmation, receiving, at the identity network from the identity provider, an attribute validation request to validate identity attributes of the user, wherein the attribute validation request includes a plurality of identity attributes of the user; and

validating, by the identity network, the digital identity of the user based on the plurality of identity attributes.

2. The method of claim 1 , wherein validating the digital identity of the user includes comparing, by the identity network, a first identity attribute of the plurality of identity attributes to a second identity attribute of the plurality of identity attributes.

3. The method of claim 1 , further comprising receiving, at the identity network, a first identity attribute from a third-party device, wherein validating the digital identity of the user includes comparing the first identity attribute with a second identity attribute of the plurality of identity attributes.

4. The method of claim 1 , wherein:

the identity validation request includes a second identity attribute; and

validating the digital identity of the user is based on the plurality of identity attributes and the second identity attribute.

5. The method of claim 1 ,

wherein the attribute validation request includes a document, and

the method further comprises extracting, by the identity network, a first identity attribute based on the document, wherein validating the digital identity of the user is based on the plurality of identity attributes and the first identity attribute.

6. The method of claim 1 , further comprising, prior to receiving the confirmation:

receiving, at the identity network from the identity provider, a device check request, wherein the device check request includes a first device identifier associated with a user device of the user;

generating, by the identity network, a device check result by comparing the first device identifier and a second device identifier associated with the user device of the user that was previously saved by the identity network; and

providing, by the identity network, the device check result to the identity provider.

7. The method of claim 6 ,

further comprising:

in response to receiving the identity validation request, providing, from the identity network to the relying party, a first session identifier associated with the identity validation request; and

storing, by the identity network, the first session identifier in a database,

wherein:

the device check includes a second session identifier; and

generating the device check result includes comparing the first session and the second session identifier.

8. A system, comprising:

one or more computing devices; and

memory storing instructions, the instructions being executable by the one or more computing devices, wherein the one or more computing devices are configured to perform a method, comprising:

receive, at an identity network from a relying party, an identity validation request to validate a digital identity of a user;

provide, from the identity network to the relying party, a link associated with an identity provider application based on the identity validation request;

receive, at the identity network from an identity provider associated with the identity provider application, a confirmation that the user has successfully accessed the identity provider application via the link;

after receiving the confirmation, receive, at the identity network from the identity provider, an attribute validation request to validate identity attributes of the user, wherein the attribute validation request includes a plurality of identity attributes of the user; and

validating, by the identity network, the digital identity of the user based on the plurality of identity attributes.

9. The system of claim 8 , wherein validating the digital identity of the user includes comparing, by the identity network, a first identity attribute of the plurality of identity attributes to a second identity attribute of the plurality of identity attributes.

10. The system of claim 8 , further comprising receiving, at the identity network, a first identity attribute from a third-party device, wherein validating the digital identity of the user includes comparing the first identity attribute with a second identity attribute of the plurality of identity attributes.

11. The system of claim 8 , wherein:

the identity validation request includes a second identity attribute; and

validating the digital identity of the user is based on the plurality of identity attributes and the second identity attribute.

12. The system of claim 8 ,

wherein the attribute validation request includes a document, and

the method further comprises extracting, by the identity network, a first identity attribute based on the document, wherein validating the digital identity of the user is based on the plurality of identity attributes and the first identity attribute.

13. The system of claim 8 , further comprising, prior to receiving the confirmation:

receiving, at the identity network from the identity provider, a device check request, wherein the device check request includes a first device identifier associated with a user device of the user;

generating, by the identity network, a device check result by comparing the first device identifier and a second device identifier associated with the user device of the user that was previously saved by the identity network; and

providing, by the identity network, the device check result to the identity provider.

14. The system of claim 13 ,

further comprising:

in response to receiving the identity validation request, providing, from the identity network to the relying party, a first session identifier associated with the identity validation request; and

storing, by the identity network, the first session identifier in a database,

wherein:

the device check includes a second session identifier; and

generating the device check result includes comparing the first session and the second session identifier.

15. A non-transitory computing-device readable storage medium on which computing-device readable instructions of a program are stored, the instructions, when executed by one or more computing devices, causing the one or more computing devices to perform a method, comprising:

receiving, at an identity network from a relying party, an identity validation request to validate a digital identity of a user;

providing, from the identity network to the relying party, a link associated with an identity provider application based on the identity validation request;

receiving, at the identity network from an identity provider associated with the identity provider application, a confirmation that the user has successfully accessed the identity provider application via the link;

after receiving the confirmation, receiving, at the identity network from the identity provider, an attribute validation request to validate identity attributes of the user, wherein the attribute validation request includes a plurality of identity attributes of the user; and

validating, by the identity network, the digital identity of the user based on the plurality of identity attributes.

16. The non-transitory computing-device readable storage medium of claim 15 , wherein validating the digital identity of the user includes comparing, by the identity network, a first identity attribute of the plurality of identity attributes to a second identity attribute of the plurality of identity attributes.

17. The non-transitory computing-device readable storage medium of claim 15 , further comprising receiving, at the identity network, a first identity attribute from a third-party device, wherein validating the digital identity of the user includes comparing the first identity attribute with a second identity attribute of the plurality of identity attributes.

18. The non-transitory computing-device readable storage medium of claim 15 , wherein:

the identity validation request includes a second identity attribute; and

validating the digital identity of the user is based on the plurality of identity attributes and the second identity attribute.

19. The non-transitory computing-device readable storage medium of claim 15 ,

wherein the attribute validation request includes a document, and

the method further comprises extracting, by the identity network, a first identity attribute based on the document, wherein validating the digital identity of the user is based on the plurality of identity attributes and the first identity attribute.

20. The non-transitory computing-device readable storage medium of claim 15 , further comprising, prior to receiving the confirmation:

receiving, at the identity network from the identity provider, a device check request, wherein the device check request includes a first device identifier associated with a user device of the user;

generating, by the identity network, a device check result by comparing the device first identifier and a second device identifier associated with the user device of the user that was previously saved by the identity network; and

providing, by the identity network, the device check result to the identity provider.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 26, 2023
From: SLOWIAK, GREGORY; WOODWARD, ERIC; LAM, PHILIP; SHULTZ, JEFF
To: EARLY WARNING SERVICES, LLC
Reel/Frame 065955/0428 →
Continuity (7)
Continuation 16908456 · Jun 22, 2020
Provisional Application 62864889 · Jun 21, 2019
Provisional Application 62864906 · Jun 21, 2019
Provisional Application 62864900 · Jun 21, 2019
Provisional Application 62864891 · Jun 21, 2019
Provisional Application 62864911 · Jun 21, 2019
Related Publication 20240129311A1 · Apr 18, 2024
References Cited (82)
US 7912971B1 · Dunn · 2011 [cited by applicant]
US 8843997B1 · Hare · 2014 [cited by examiner]
US 10069811B2 · Curtis et al. · 2018 [cited by applicant]
US 10237259B2 · Ronda et al. · 2019 [cited by applicant]
US 10255598B1 · Dean et al. · 2019 [cited by applicant]
US 10853791B1 · Ellis et al. · 2020 [cited by applicant]
US 11157954B1 · Belanger et al. · 2021 [cited by applicant]
US 11244034B1 · Nagappan et al. · 2022 [cited by applicant]
US 11328356B1 · Slowiak et al. · 2022 [cited by applicant]
US 11394724B1 · Slowiak et al. · 2022 [cited by applicant]
US 11438331B1 · Slowiak et al. · 2022 [cited by applicant]
US 11522701B2 · Rowe et al. · 2022 [cited by applicant]
US 11784995B1 · Slowiak et al. · 2023 [cited by applicant]
US 11816728B2 · Slowiak et al. · 2023 [cited by applicant]
US 11830066B2 · Slowiak et al. · 2023 [cited by applicant]
US 11847694B2 · Slowiak et al. · 2023 [cited by applicant]
US 11888849B1 · Slowiak et al. · 2024 [cited by applicant]
US 11900453B2 · Slowiak et al. · 2024 [cited by applicant]
US 11941093B2 · Slowiak et al. · 2024 [cited by applicant]
US 20040236965A1 · Krohn · 2004 [cited by applicant]
US 20060129816A1 · Hinton · 2006 [cited by applicant]
US 20090133107A1 · Thoursie · 2009 [cited by applicant]
US 20100145861A1 · Law et al. · 2010 [cited by applicant]
US 20100154046A1 · Liu et al. · 2010 [cited by applicant]
US 20130036456A1 · Boysen et al. · 2013 [cited by applicant]
US 20130086657A1 · Srinivasan et al. · 2013 [cited by applicant]
US 20140173754A1 · Barbir · 2014 [cited by applicant]
US 20140359741A1 · Kistner et al. · 2014 [cited by applicant]
US 20150058930A1 · Mitchell et al. · 2015 [cited by applicant]
US 20150332029A1 · Coxe et al. · 2015 [cited by applicant]
US 20170041296A1 · Ford et al. · 2017 [cited by applicant]
US 20170140174A1 · Lacey et al. · 2017 [cited by applicant]
US 20170186084A1 · Koch · 2017 [cited by applicant]
US 20170244676A1 · Edwards · 2017 [cited by applicant]
US 20170250972A1 · Ronda et al. · 2017 [cited by applicant]
US 20170257358A1 · Ebrahimi et al. · 2017 [cited by applicant]
US 20180145979A1 · Lu et al. · 2018 [cited by applicant]
US 20180152440A1 · Hande et al. · 2018 [cited by applicant]
US 20180181745A1 · Chen et al. · 2018 [cited by applicant]
US 20180197263A1 · Pearson et al. · 2018 [cited by applicant]
US 20180218121A1 · Gassner et al. · 2018 [cited by applicant]
US 20180219846A1 · Poschel et al. · 2018 [cited by applicant]
US 20180267847A1 · Smith et al. · 2018 [cited by applicant]
US 20180342018A1 · Pancholi et al. · 2018 [cited by applicant]
US 20180349581A1 · Ramalingam · 2018 [cited by applicant]
US 20190182042A1 · Ebrahimi et al. · 2019 [cited by applicant]
US 20190261169A1 · Kamal et al. · 2019 [cited by applicant]
US 20200153814A1 · Smolny et al. · 2020 [cited by applicant]
US 20200213297A1 · Suraparaju · 2020 [cited by applicant]
US 20200366671A1 · Larson et al. · 2020 [cited by applicant]
US 20210014218A1 · Kurylko et al. · 2021 [cited by applicant]
US 20210099454A1 · Rahimi et al. · 2021 [cited by applicant]
US 20210165865A1 · Trelin · 2021 [cited by applicant]
US 20210320799A1 · Bankston · 2021 [cited by applicant]
US 20210326426A1 · Bouse · 2021 [cited by applicant]
US 20220029985A1 · Malhotra et al. · 2022 [cited by applicant]
US 20220301050A1 · Slowiak et al. · 2022 [cited by applicant]
CA 3074350A1 · 2020 [cited by applicant]
EP 2867814A1 · 2015 [cited by applicant]
WO 2019118682A1 · 2019 [cited by applicant]
U.S. Appl. No. 16/908,435 , Non-Final Office Action, Mailed On Nov. 2, 2021, 14 pages. [cited by applicant]
U.S. Appl. No. 16/908,435 , Notice of Allowance, Mailed On Mar. 17, 2022, 7 pages. [cited by applicant]
U.S. Appl. No. 16/908,443 , Advisory Action, Mailed On Nov. 25, 2022, 4 pages. [cited by applicant]
U.S. Appl. No. 16/908,443 , Final Office Action, Mailed On Jul. 7, 2022, 15 pages. [cited by applicant]
U.S. Appl. No. 16/908,443 , Non-Final Office Action, Mailed On Nov. 9, 2021, 14 pages. [cited by applicant]
U.S. Appl. No. 16/908,443 , Notice of Allowance, Mailed On Jun. 1, 2023, 12 pages. [cited by applicant]
U.S. Appl. No. 16/908,453 , Notice of Allowance, Mailed On May 11, 2022, 9 pages. [cited by applicant]
U.S. Appl. No. 16/908,456 , Advisory Action, Mailed On Apr. 14, 2023, 4 pages. [cited by applicant]
U.S. Appl. No. 16/908,456 , Final Office Action, Mailed On Feb. 6, 2023, 13 pages. [cited by applicant]
U.S. Appl. No. 16/908,456 , Non-Final Office Action, Mailed On Oct. 14, 2022, 12 pages. [cited by applicant]
U.S. Appl. No. 16/908,456 , Non-Final Office Action, Mailed On Jun. 26, 2023, 15 pages. [cited by applicant]
U.S. Appl. No. 16/908,456 , Notice of Allowance, Mailed On Sep. 19, 2023, 19 pages. [cited by applicant]
U.S. Appl. No. 16/908,460 , Notice of Allowance, Mailed On Jan. 12, 2022, 10 pages. [cited by applicant]
U.S. Appl. No. 17/716,516 , Notice of Allowance, Mailed On Aug. 2, 2023, 10 pages. [cited by applicant]
U.S. Appl. No. 17/855,971 , Non-Final Office Action, Mailed On Feb. 15, 2023, 13 pages. [cited by applicant]
U.S. Appl. No. 17/855,971 , Notice of Allowance, Mailed On Jul. 7, 2023, 7 pages. [cited by applicant]
U.S. Appl. No. 17/856,056 , Non-Final Office Action, Mailed On Feb. 15, 2023, 14 pages. [cited by applicant]
U.S. Appl. No. 17/856,056 , Notice of Allowance, Mailed On Jul. 24, 2023, 8 pages. [cited by applicant]
U.S. Appl. No. 17/900,435 , Notice of Allowance, Mailed On Nov. 22, 2023, 9 pages. [cited by applicant]
U.S. Appl. No. 17/900,441 , Notice of Allowance, Mailed On Oct. 2, 2023, 9 pages. [cited by applicant]
Goswami et al., “A Replay Attack Resilient System for PKI Based Authentication in Challenge-Response Mode for Online Application”, 3rd International Conference on Eco-friendly Computing and Communication Systems, Dec. 2… [cited by applicant]
Vassilev et al., “Personal Brokerage of Web Service Access”, Institute of Electrical and Electronics Engineers Security and Privacy Magazine, vol. 5, No. 5, Oct. 1, 2007, pp. 24-31. [cited by applicant]