Methods and systems for secure digital credentials

US10645068B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10645068-B2
Application numberUS-201615387473-A
CountryUS
Kind codeB2
Filing dateDec 21, 2016
Priority dateDec 28, 2015
Publication dateMay 5, 2020
Grant dateMay 5, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for resetting a digital credential within a digital credential based authentication system. The method includes logging a first administrative user into the digital credential system, receiving, from the first administrative user, a first portion of authentication credentials for a first customer, validating, by the first administrative user using the digital credential system, the first portion, logging a second administrative user into the digital credential system, receiving, from the second administrative user, a second portion of authentication credentials for the first customer, receiving the second portion by the second administrative user, validating, by the second administrative user using the digital credential system, the second portion; and resetting the authentication credentials based on the validation of the first portion and second portion.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for improving the security of a digital credential based authentication system, the method comprising: receiving first login information and a first login location from a first administrative user; logging the first administrative user into the digital credential based authentication system based on the first login information; receiving, from the first administrative user, a first portion of authentication credentials for a first customer; validating, by the first administrative user using the digital credential system, the first portion; receiving second login information and a second login location from a second administrative user; logging the second administrative user into the digital credential system based on the second login information and based on a comparison of the first login location and the second login location; receiving, from the second administrative user, a second portion of authentication credentials for the first customer different from the first portion; validating, by the second administrative user using the digital credential system, the second portion; and resetting the authentication credentials based on the validation of the first portion and the second portion, wherein at least one of receiving the second portion from the second administrative user and validating the second portion by the second administrative user comprises receiving information from the first customer and occurs via a physical interaction while the first customer is at a physical location. 2. The method of claim 1 , further comprising preventing validation of the second portion by the first administrative user. 3. The method of claim 1 , further comprising: selecting, by the first administrative user, the physical location for validation of the second portion of the authentication credentials; verifying, by the digital credential system, that the receiving of the second portion of the authentication credentials occurs at the selected physical location; and validating, by the digital credential system, the second portion in response to verifying that the receiving of the second portion of the authentication credentials occurs at the selected physical location. 4. The method of claim 3 , wherein verifying the receiving occurs at the selected physical location comprises receiving GPS coordinates from a terminal of the logged in second administrative user, and determining whether the received GPS coordinates are equivalent to the selected physical location. 5. The method of claim 1 , wherein the first portion includes at least one or more of a first requestor name, a first customer account name, a first identification type, a first requestor address, a global positioning system coordinate, a first phone number, and a transaction address. 6. An apparatus for improving the security of a digital credential based authentication system, the apparatus comprising: one or more electronic hardware processors; a memory, operably connected to the one or more processors, and storing instructions that configure the one or more electronic hardware processors to: receive first login information and a first location from a first administrative user; log the first administrative user into the digital credential system based on the first login information; receive, from the first administrative user, a first portion of authentication credentials for a first customer; validate, by the first administrative user using the digital credential system, the first portion; receive second login information and a second location from a second administrative user; log the second administrative user into the digital credential system based on the second login information and based on a comparison of the first location and the second location; receive, from the second administrative user, a second portion of authentication credentials for the first customer different from the first portion; validate, by the second administrative user using the digital credential system, the second portion; and reset the authentication credentials based on the validation of the first portion and second portion, wherein at least one of receiving the second portion from the second administrative user and validating the second portion by the second administrative user comprises receiving information from the first customer and occurs via a physical interaction while the first customer is at a physical location. 7. The apparatus of claim 6 , wherein the memory further stores instructions that configure the one or more electronic hardware processors to prevent validation of the second portion by the first administrative user in response to the validation of the first portion by the first administrative user. 8. The apparatus of claim 6 , wherein the memory further stores instructions that configure the one or more electronic hardware processors to: select by the first administrative user, the physical location for validation of the second portion of the authentication credentials; verify, by the digital credential system, that the receiving of the second portion of the authentication credentials occurs at the selected physical location; and validate, by the digital credential system, the second portion in response to verifying that the receiving of the second portion of the authentication credentials occurs at the selected physical location. 9. The apparatus of claim 6 , wherein verifying the receiving occurs at the selected physical location comprises receiving GPS coordinates from a terminal of the logged in second administrative user and determining whether the received GPS coordinates are equivalent to the selected physical location. 10. The apparatus of claim 6 , wherein the first portion includes at least one or more of a first requestor name, a first customer account name, a first identification type, a first requestor address, a global positioning system coordinate, a first phone number, and a transaction address. 11. A method of improving the security of a web service accessible digital credential, the method comprising: validating, by a first administrative user, a first portion of authentication credentials for a first user; receiving, by a digital credential system, a login from the first administrative user via a first electronic device; receiving, by the digital credential system, a digital credential reset request message for a user account of the first user from the first administrative user, the message identifying a physical location to which at least one of a second administrative user or the first user travels to perform an identity verification of the first user using a second portion of the authentication credentials for the first user, and an identification type to use for the identity verification; receiving, via the digital credential system, a login from the second administrative user from a second electronic device at the identified physical location; displaying, via the digital credential system, at the second electronic device, an indication of the identification type to use for the identity verification; receiving, via the digital credential system, an indication of whether the indicated identification type was verified, wherein the indicated identification type was verified based on a physical interaction between at least one of the second administrative user or the second electronic device and the user while at the identified physical location; generating, via the digital credential system, a digital credential reset response message based on the verification indication; and transmitting, via the digital credential system, the digital credential reset r

Assignees

Inventors

Classifications

  • by using authentication-authorization-accounting [AAA] servers or protocols · CPC title

  • G06Q10/063Primary

    Operations research, analysis or management · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10645068B2 cover?
Methods and systems for resetting a digital credential within a digital credential based authentication system. The method includes logging a first administrative user into the digital credential system, receiving, from the first administrative user, a first portion of authentication credentials for a first customer, validating, by the first administrative user using the digital credential syst…
Who is the assignee on this patent?
United States Postal Service
What technology area does this patent fall under?
Primary CPC classification G06Q10/063. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 05 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).