IP Library › Granted Patent US 12,418,532
Granted Patent B2
US 12,418,532 · App. 18/489,107 · Granted Sep 16, 2025

Portable access point for secure user information using a blockchain backed credential

Inventors: Zachary S. Ankrom (Austin, TX); Kamran Khaliq (Ashburn, VA)
Assignee: Oracle International Corporation
H04L63/10G06F21/32G06F21/602G06F21/606G06F21/6245H04L9/50H04L63/083H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,532
App. No.
18/489,107
Granted
Sep 16, 2025
Kind
B2
Abstract

Embodiments permit scope limited access to a user's secure information using blockchain backed credential(s). A user can register with a secure information manager and control the scope with which the user's secure information is shared. For example, the user can permit a vetted entity access to the user's secure information via a portable access point. The user can select scope definition that control how the user's secure information is shared with the vetted entity. The vetted entity can scan the user's portable access point and request a credential. The credential can be a blockchain backed credential that is assigned access privileges that correspond the user's selections. The vetted entity can then issue data access request(s) using the credential. The secure information manager can permit the vetted entity scope limited access to the user's secure information that corresponds to the access privileges assigned to the credential.

Claims (63)

1. A method for permitting limited access to a user's secure information, the method comprising:

receiving, at a secure information manager from a requesting system, a credential request for one or more credentials that permit access to a user's secure information, the credential request comprising user identifying information, entity identifying information, and scope definitions, wherein the requesting system generates the credential request in response to scanning a portable access point of a user;

validating, at the secure information manager, the user identifying information and the entity identifying information;

assigning, to the entity and in response to the validating, a blockchain credential with access privileges that correspond to the scope definitions, wherein the blockchain credential assignment is recorded on a private blockchain that manages the blockchain credential; and

permitting, in response to one or more access requests from the entity that comprises the assigned blockchain credential, access to the user's secure information limited to the access privileges of the blockchain credential.

2. The method of claim 1 , wherein,

the portable access point for the user comprises encoded information,

in response to scanning the portable access point, the requesting system is configured to decipher the user identifying information and scope definitions from the encoded information.

3. The method of claim 2 , wherein,

the user provides selections via input at a portable device,

the portable device is configured to generate the portable access point in response to the user selections, and

the requesting system scans the portable access point from the portable device.

4. The method of claim 3 , wherein,

the user selections correspond to segment identifiers that define segments of the user's secure information selected by the user for sharing with the entity,

the encoded information of the portable access point comprises encoded representations of the segment identifiers,

the requesting system is configured to decipher the encoded representations of the segment identifiers in response to scanning the portable access point, and

the scope definitions provided in the credential request comprise the deciphered segment identifiers.

5. The method of claim 4 , further comprising:

mapping the scope definitions that comprise the deciphered segment identifiers to segments of the user's secure information using a predefined mapping, wherein the access privileges of the assigned blockchain credential permit the entity access to the mapped segments of the user's secure information.

6. The method of claim 5 , further comprising:

storing, using one or more blockchains of a blockchain manager, one or more logs of the scope limited access to the user's secure information, the logs comprising one or more of: an identifier for the entity, portions of the access requests, segment identifiers for the user's secure information accessed by the entity, timestamps for the accessing of the user's secure information, or any combination thereof, wherein the one or more logs are recorded as blocks of the one or more blockchains.

7. The method of claim 6 , further comprising:

storing, using the one or more blockchains of the blockchain manager, the predefined mapping, wherein the predefined mapping comprises an active mapping from among a plurality of predefined mappings recorded as blocks of the one or more blockchains.

8. The method of claim 7 , further comprising:

providing, in response to an audit request, audit information descriptive of scope limited access to the user's secure information over a time period, wherein the audit information is generated by: accessing the logs of the scope limited access to the user's secure information over the time period and the stored plurality of predefined mappings, and translating mapped segment identifiers from the accessed logs using the stored predefined mappings.

9. The method of claim 1 , wherein the entity comprises a vetted entity that is vetted after performance of a vetting workflow.

10. The method of claim 1 , wherein permitting scope limited access to the user's secure information further comprises:

receiving, at a secure information manager, the one or more access requests, the access requests comprising an unauthenticated credential;

authenticating, via the private blockchain, the unauthenticated credential as the blockchain credential assigned to the entity; and

permitting, in response to the authenticating, the access to the user's secure information limited to the access privileges of the blockchain credential.

11. A non-transitory computer readable medium having instructions stored thereon that, when executed by a processor, cause the processor to permit limited access to a user's secure information, wherein, when executed, the instructions cause the processor to:

receive, at a secure information manager from a requesting system, a credential request for one or more credentials that permit access to a user's secure information, the credential request comprising user identifying information, entity identifying information, and scope definitions, wherein the requesting system generates the credential request in response to scanning a portable access point of a user;

validate, at the secure information manager, the user identifying information and the entity identifying information;

assign, to the entity and in response to the validating, a blockchain credential with access privileges that correspond to the scope definitions, wherein the blockchain credential assignment is recorded on a private blockchain that manages the blockchain credential; and

permit, in response to one or more access requests from the entity that comprises the assigned blockchain credential, access to the user's secure information limited to the access privileges of the blockchain credential.

12. The non-transitory computer readable medium of claim 11 , wherein,

the portable access point for the user comprises encoded information,

in response to scanning the portable access point, the requesting system is configured to decipher the user identifying information and scope definitions from the encoded information.

13. The non-transitory computer readable medium of claim 12 , wherein,

the user provides selections via input at a portable device,

the portable device is configured to generate the portable access point in response to the user selections, and

the requesting system scans the portable access point from the portable device.

14. The non-transitory computer readable medium of claim 13 , wherein,

the user selections correspond to segment identifiers that define segments of the user's secure information selected by the user for sharing with the entity,

the encoded information of the portable access point comprises encoded representations of the segment identifiers,

the requesting system is configured to decipher the encoded representations of the segment identifiers in response to scanning the portable access point, and

the scope definitions provided in the credential request comprise the deciphered segment identifiers.

15. The non-transitory computer readable medium of claim 14 , wherein the instructions further cause the processor to:

map the scope definitions that comprise the deciphered segment identifiers to segments of the user's secure information using a predefined mapping, wherein the access privileges of the assigned blockchain credential permit the entity access to the mapped segments of the user's secure information.

16. The non-transitory computer readable medium of claim 15 , wherein the instructions further cause the processor to:

store, using one or more blockchains of a blockchain manager, one or more logs of the scope limited access to the user's secure information, the logs comprising one or more of: an identifier for the entity, portions of the access requests, segment identifiers for the user's secure information accessed by the entity, timestamps for the accessing of the user's secure information, or any combination thereof, wherein the one or more logs are recorded as blocks of the one or more blockchains.

17. The non-transitory computer readable medium of claim 16 , wherein the instructions further cause the processor to:

store, using the one or more blockchains of the blockchain manager, the predefined mapping, wherein the predefined mapping comprises an active mapping from among a plurality of predefined mappings recorded as blocks of the one or more blockchains.

18. The non-transitory computer readable medium of claim 17 , wherein the instructions further cause the processor to:

provide, in response to an audit request, audit information descriptive of scope limited access to the user's secure information over a time period, wherein the audit information is generated by: accessing the logs of the scope limited access to the user's secure information over the time period and the stored plurality of predefined mappings, and translating mapped segment identifiers from the accessed logs using the stored predefined mappings.

19. The non-transitory computer readable medium of claim 11 , wherein the entity comprises a vetted entity that is vetted after performance of a vetting workflow.

20. A system for permitting limited access to a user's secure information, the system comprising:

a processor; and

a memory storing instructions for execution by the processor, the instructions configuring the processor to:

receive, at a secure information manager from a requesting system, a credential request for one or more credentials that permit access to a user's secure information, the credential request comprising user identifying information, entity identifying information, and scope definitions, wherein the requesting system generates the credential request in response to scanning a portable access point of a user;

validate, at the secure information manager, the user identifying information and the entity identifying information;

assign, to the entity and in response to the validating, a blockchain credential with access privileges that correspond to the scope definitions, wherein the blockchain credential assignment is recorded on a private blockchain that manages the blockchain credential; and

permit, in response to one or more access requests from the entity that comprises the assigned blockchain credential, access to the user's secure information limited to the access privileges of the blockchain credential.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2023
From: ANKROM, ZACHARY S.; KHALIQ, KAMRAN
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 065262/0360 →
Continuity (6)
Provisional Application 63501742 · May 12, 2023
Provisional Application 63497528 · Apr 21, 2023
Provisional Application 63493155 · Mar 30, 2023
Provisional Application 63493150 · Mar 30, 2023
Provisional Application 63417321 · Oct 18, 2022
Related Publication 20240129313A1 · Apr 18, 2024
References Cited (22)
US 8275632B2 · Awaraji et al. · 2012 [cited by applicant]
US 11443838B1 · Cordonnier et al. · 2022 [cited by applicant]
US 20080172737A1 · Shen et al. · 2008 [cited by applicant]
US 20120179490A1 · Fuhrmann et al. · 2012 [cited by applicant]
US 20170076405A1 · Shah · 2017 [cited by applicant]
US 20180211059A1 · Aunger et al. · 2018 [cited by applicant]
US 20200053081A1 · Park et al. · 2020 [cited by applicant]
US 20200168306A1 · Chen et al. · 2020 [cited by applicant]
US 20200226285A1 · Bulleit et al. · 2020 [cited by applicant]
US 20210174972A1 · Pavlatos et al. · 2021 [cited by applicant]
US 20210357893A1 · Kang · 2021 [cited by examiner]
US 20220035936A1 · Lin · 2022 [cited by applicant]
US 20220150711A1 · Lim et al. · 2022 [cited by applicant]
US 20220158997A1 · Guinard · 2022 [cited by examiner]
US 20220222364A1 · Roberts et al. · 2022 [cited by applicant]
US 20230421399A1 · Quirk · 2023 [cited by examiner]
US 20240354866A1 · Schwartz · 2024 [cited by examiner]
KR 20220129245A · 2022 [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2023/032871 dated Dec. 4, 2024. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2024/021434 dated Jun. 24, 2024. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2024/021435 dated Jun. 24, 2024. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2024/021921 dated Jul. 1, 2024. [cited by applicant]