IP Library Granted Patent US 8,549,602
Granted Patent B2
US 8,549,602 · App. 11/779,795 · Granted Oct 1, 2013

System and method for handling permits for user authentication tokens

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,549,602
App. No.
11/779,795
Granted
Oct 1, 2013
Kind
B2
Abstract

The invention consists of a method of handling permits, comprising the steps of: (a) providing a user with a user permit linked to a user authentication token, the user permit defining permissions granted to the user and the user token containing identity authentication information for the user; (b) presenting the user token to a gatekeeper to confirm the user's identity; (c) validating the user permit based on the permit issuer's digital signature; and, (d) granting the user access based on said permissions within the user permit.

Claims (22)

1. A method of handling permits, comprising the steps of:

(a) providing a user with a user permit linked to a user authentication token, said user permit defining permissions granted to said user and said user token containing identity authentication information for said user;

(b) generating user token authentication data using said user authentication token;

(c) simultaneously presenting said user permit and said user token authentication data to a gatekeeper to confirm said user's identity;

(d) verifying the user's identity via said user permit and said user token authentication data;

(e) validating the user permit based on the permit issuer's digital signature; and,

(f) granting said user access based on said permissions within said user permit.

2. The method of claim 1 , wherein said user authentication token is a hardware token.

3. The method of claim 1 , wherein said user authentication token is a software token.

4. The method of claim 1 , wherein said user token authentication data comprises a one-time password.

5. A system for handling permits, comprising:

(a) a token granting authority, which provides users with user tokens containing identity authentication information for each user, said user tokens generating user token authentication data for authenticating said users;

(b) a permit granting authority, which provides users with user permits containing permissions granted to each user and binds each of said user permits to one of said user tokens

(c) a mobile device configured to generate user token authentication data using one of said user tokens, and present said user token authentication data and one of said user permits to a gatekeeper, said user token authentication data authenticating the user of said mobile device.

6. The system of claim 5 , wherein said permit granting authority has an existing relationship with said token granting authority such that the permit granting authority can efficiently validate the user token when issuing permits for that user.

7. The system of claim 5 , wherein the user token identifier contained in the user permit is a globally unique identifier, such that the permit can be validated in an open network outside of a domain in which the token was issued.

8. The system of claim 5 , wherein said user token authentication data comprises a one-time password.

9. A method of generating user permits for a user, comprising the steps of:

(a) authenticating said user's identity via user token authentication data generated using a user authentication token held by said user; and

(b) generating a user permit for said user which is linked to said user authentication token, such that said user permit and said user token authentication data can be presented simultaneously to authenticate said user.

10. The method of claim 9 , wherein said user permit may be generated by the same entity which granted said user authentication token.

11. The method of claim 9 , wherein said user token authentication data comprises a one-time password.

Assignments (10)
SECURITY INTEREST Recorded Mar 12, 2026
From: IMS SOFTWARE SERVICES LTD.; IQVIA INC.; IQVIA RDS INC.; RULES-BASED MEDICINE, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 075047/0061 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTIES INADVERTENTLY NOT INCLUDED IN FILING PREVIOUSLY RECORDED AT REEL: 065709 FRAME: 618. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT. Recorded Dec 6, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065790/0781 →
SECURITY INTEREST Recorded Nov 29, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065710/0253 →
SECURITY INTEREST Recorded Nov 29, 2023
From: IQVIA INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065709/0618 →
SECURITY INTEREST Recorded May 24, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 063745/0279 →
CHANGE OF NAME Recorded Oct 9, 2018
From: QUINTILES IMS INCORPORATED
To: IQVIA INC.
Reel/Frame 047207/0276 →
CHANGE OF NAME Recorded Sep 7, 2018
From: IMS HEALTH INCORPORATED
To: QUINTILES IMS INCORPORATED
Reel/Frame 047029/0637 →
SECURITY AGREEMENT Recorded Nov 6, 2013
From: IMS HEALTH INCORPORATED
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031592/0179 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2013
From: DIVERSINET CORP.
To: IMS HEALTH INC.
Reel/Frame 031268/0020 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2007
From: VAETH, J. STUART
To: DIVERSINET CORP.
Reel/Frame 019572/0164 →