System and method for identity management
US-10135802-B2 · Nov 20, 2018 · US
US11038868B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11038868-B2 |
| Application number | US-201916669178-A |
| Country | US |
| Kind code | B2 |
| Filing date | Oct 30, 2019 |
| Priority date | Aug 23, 2013 |
| Publication date | Jun 15, 2021 |
| Grant date | Jun 15, 2021 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Some implementations may provide a machine-assisted method for determining a trustworthiness of a requested transaction, the method including: receiving, from a relying party, a request to determine a trustworthiness of a particular transaction request, the transaction request initially submitted by a user to access data managed by the relying party; based on the transaction request, summarizing the particular transaction request into transactional characteristics, the transactional characteristics devoid of source assets of the transaction, the source assets including credential information of the user, the credential information of the relying party, or information content of the requested transaction; generating first machine readable data encoding transactional characteristics of the underlying transaction as requested, the transactional characteristics unique to the particular transaction request; submitting a first inquiry at a first engine to determine an access eligibility of the user submitting the transaction request, the first inquiry including the credential information of the submitting user, as well as the summarized transactional characteristics that is applicable only once to the underlying transaction request; and receiving the access eligibility determination from the first engine.
Opening claim text (preview).
What is claimed is: 1. A computer system comprising at least one non-transitory storage device and at least one processor coupled thereto, the computer system located at a relying party and configured to perform operations of: transmitting, to an authentication server system, a request to determine a trustworthiness of a particular transaction request for an underlying transaction, the particular transaction request initially submitted by a user from a user computing device to access data managed by the relying party, the request to determine trustworthiness causing the authentication server system to: based on the particular transaction request, summarize the particular transaction request into transactional characteristics that are smaller in size than the transaction request or the underlying transaction, the transactional characteristics including a time stamp but devoid of source assets of the underlying transaction being requested, the source assets including credential information of the user, the credential information of the relying party, or information content of the requested underlying transaction being requested; generate first machine-readable data encoding transactional characteristics of the underlying transaction being requested, the transactional characteristics unique to the particular transaction request and used to validate a transaction request; submit a first inquiry at a first engine to determine an access eligibility of the user submitting the transaction request, the first inquiry including the credential information of the submitting user, as well as the summarized transactional characteristics that is applicable only once to the particular transaction request and the underlying transaction being requested; and receiving the access eligibility determination from the first engine, wherein the access eligibility determination factors in a validity of the particular transaction request as determined, at least in part, by virtue of the summarized transactional characteristics being matched; and receiving notification from the authentication server regarding the trustworthiness of the transaction request determined based on, at least in part, on the access eligibility determination. 2. The computer system of claim 1 , wherein the operations further comprise: in response to the transaction request being determined as trustworthy, proceeding with the underlying transaction by granting the user computing device access to the data managed by the relying party. 3. The computer system of claim 1 , wherein the operations further comprise: in response to the transaction request being determined as untrustworthy, terminating the underlying transaction by denying the user computing device access to the data managed by the relying party. 4. The computer system of claim 3 , wherein the operations further comprise: transmitting, to the user computing device, an error message indicating that the requested transaction has failed to go through. 5. The computer system of claim 1 , wherein the request to determine trustworthiness further causes the authentication server system to: log, at a transaction database associated with a second engine, an entry for the particular transaction request by storing the first machine-readable data encoding the transactional characteristics of the particular transaction request. 6. The computer system of claim 5 , wherein storing the first machine-readable data encoding the transactional characteristics of the particular transaction request includes receiving confirmation that the first machine-readable data has been stored at the transaction database associated with the second engine. 7. The computer system of claim 6 , wherein receiving confirmation comprises receiving the confirmation that the first machine-readable data has been stored at the transaction database associated with the second engine before submitting the first inquiry at the first engine. 8. The computer system of claim 5 , wherein storing the first machine-readable data encoding the transactional characteristics of the particular transaction request includes storing the first machine-readable data for only one retrieval query at the transaction database. 9. The computer system of claim 5 , wherein storing the first machine-readable data encoding the transactional characteristics of the particular transaction request includes storing the first machine-readable data for a retrieval query within a time window at the transaction database. 10. The computer system of claim 1 , wherein the request to determine trustworthiness further causes the authentication server system to: log, at an identity database associated with the first engine, an entry of the received access eligibility determination as well as the determined trustworthiness of the transaction request. 11. The computer system of claim 1 , wherein the request to determine trustworthiness further causes the authentication server system to: in response to the computer at the relying party proceeding with the requested particular transaction, generate second machine-readable data encoding transactional characteristics of the particular transaction as consummated, the transactional characteristics of the particular consummated transaction devoid of source assets of the consummated transaction, the source assets including credential information of the user, the credential information of the relying party, or information content of the transaction as consummated. 12. The computer system of claim 11 , wherein the request to determine trustworthiness further causes the authentication server system to: log, at an identity database associated with the first engine, an entry of the particular consummated transaction by storing the second machine-readable data encoding the transactional characteristics of the particular consummated transaction such that the transactional characteristics of the particular consummated transaction provide one and only one match when used to validate a consummated transaction. 13. The computer system of claim 1 , wherein the operations further comprise: generating the request to determine a trustworthiness of the particular transaction request by including credential information attesting to an identity of the submitting user such that the authentication server system, in turn, generates an electronic credential of the submitting user that is unique to the particular transaction request submitted by the user from the user computing device. 14. The computer system of claim 12 , wherein the operations further comprise: causing the electronic credential to be stored at an identity database associated with a first engine. 15. The computer system of claim 13 , wherein the request to determine trustworthiness further causes the authentication server system to submit a second inquiry at a second engine to validate the particular transaction request, wherein the second inquiry is formed to include the summarized transactional characteristics, and wherein the second engine queries the identity database associated with the first engine to verify the electronic credential stored thereon. 16. The computer system of claim 1 , wherein generate the first machine-readable data further comprises: generate a bar code, an alphanumeric string, or a QR code encoding the transactional characteristics. 17. The computer system of claim 1 , wherein the request to determine trustworthiness further causes the authentication server system to: prior to submitting the first inquiry, submit an initial query at a
to a system of files or objects, e.g. local or distributed file system or database · CPC title
Assessing vulnerabilities and evaluating computer system security · CPC title
Program or device authentication · CPC title
User authentication · CPC title
using social networks · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.