System and network for access control to real property using mobile identification credential

US11599872B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11599872-B2
Application numberUS-202217834577-A
CountryUS
Kind codeB2
Filing dateJun 7, 2022
Priority dateApr 13, 2020
Publication dateMar 7, 2023
Grant dateMar 7, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A provider system is connected to one or more readers corresponding to one or more access points. A secure local connection is established between the user device and the provider system via one reader. The provider system receives from the user device a request for user access via one access point corresponding to the one reader, the provider system sends to the user device a request for identification information of the user, and the user device sends user information associated with a first mobile identification credential (MIC) which the user device received from an authorizing party system (APS), the user having consented to release the user information to the provider system, and the user information having been verified. The provider system uses the verified user information associated with the first MIC to verify or not verify the identity of the user before granting or denying the request to the user.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for a user having a user device to request user access from a provider having a provider system, the method comprising: connecting the provider system to one or more readers corresponding to one or more restricted area access points; establishing a secure local connection between the user device and the provider system via one reader of the one or more readers which corresponds to one restricted area access point of the one or more restricted area access points; receiving, by the provider system from the user device, a request for user access via the one restricted area access point; sending, by the provider system to the user device, a request for identification information of the user; receiving, by the provider system, part or all of user information included in a first mobile identification credential (MIC) which the user device received from a first authorizing party system (APS), the part or all of user information including the identification information of the user, the user having consented to release the part or all of user information to the provider system, and the part or all of user information having been verified by the first APS, the first APS being a separate system from the provider system; using, by the provider system, the verified part or all of user information included in the first MIC to verify or not verify an identity of the user; and verifying the identity of the user, by the provider system, before granting the user the request for user access via the one restricted area access point corresponding to the one reader. 2. The method of claim 1 , wherein receiving the verified part or all of the user information comprises: receiving, by the provider system from the user device, a token specifying the part or all of user information which the user has consented to release to the provider system; sending, by the provider system to the first APS, the received token, which is to be verified by the first APS with another token sent from the user device to the first APS; when the tokens are received by the first APS within a preset timeframe and are verified by the first APS, receiving, by the provider system from the first APS, the verified part or all of user information; and when the tokens are not received by the first APS within the preset timeframe or are not verified by the first APS, receiving, by the provider system from the first APS, a notification to resubmit the request for identification information of the user. 3. The method of claim 1 , wherein receiving the verified part or all of user information comprises: receiving, by the provider system from the user device, an electronic document specifying the part or all of user information which the user has consented to release to the provider system; sending, by the provider system to the first APS, the received electronic document; when the received electronic document is verified by the first APS, receiving, by the provider system from the first APS, the verified part or all of user information; and when the received electronic document is not verified by the first APS, receiving, from the provider system from the first APS, a notification to resubmit the request for identification information of the user. 4. The method of claim 1 , wherein receiving the verified part or all of user information comprises: receiving, by the provider system from the user device, an electronic document and the part or all of user information which the user has consented to release to the provider system; sending, by the provider system to the first APS, the received electronic document; when the received electronic document is verified by the first APS, receiving, by the provider system from the first APS, an authentication key to verify the part or all of user information received from the user device; and when the received electronic document is not verified by the first APS, receiving, by the provider system from the first APS, a notification to resubmit the request for identification information of the user. 5. The method of claim 1 , wherein receiving the verified part or all of user information comprises: receiving, by the provider system from the user device, the part or all of user information which the user has consented to release to the provider system; and receiving, by the provider system from the first APS, an authentication key to verify the part or all of user information received from the user device, based on a request sent from the user device to the first APS. 6. The method of claim 1 , further comprising: performing a liveness check of the user using live-captured user information captured at the one restricted area access point and determining whether the liveness check is valid or invalid; granting the request from the user, by the provider system, to provide the user access when the identity of the user is verified and when the liveness check is valid; and denying the request from the user, by the provider system, to provide the user access when the identity of the user is not verified or when the liveness check is invalid. 7. The method of claim 1 , further comprising: sending, by the provider system to the user device, a request for user eligibility information of the user; receiving, by the provider system, part or all of user eligibility information associated with (i) the first MIC which the user device received from the first APS or (ii) a second MIC which the user device received from a second APS, wherein the user has consented to release the part or all of user eligibility information to the provider system, and wherein the part or all of user eligibility information has been verified by the first APS or the second APS as verified part or all of user eligibility information; using, by the provider system, the verified part or all of user eligibility information to verify or not verify user eligibility of the user; granting the user the request for user access, by the provider system, when the identity and the user eligibility of the user are verified; and denying the user the request for user access, by the provider system, when the identity or the user eligibility of the user is not verified. 8. The method of claim 1 , further comprising: sending, by the provider system to an escrow provider system, a request for information showing that the user has met escrow obligations to receive the user access; receiving, by the provider system, part or all of user escrow fulfillment information associated with an escrow MIC which the user device received from an escrow APS, which is the first MIC issued by the first APS or another MIC issued by another APS, wherein the user has consented to release the part or all of user escrow fulfillment information to the provider system, and wherein the part or all of user escrow fulfillment information has been verified by the escrow APS; using, by the provider system, the verified part or all of user escrow fulfillment information to verify or not verify escrow fulfillment of the user; granting the request for user access, by the provider system, to provide to the user the user access when the identity of the user is verified and the escrow fulfillment of the user is verified; and denying the request for user access, by the provider system, to provide to the user the user access when at least one of the identity of the user or the escrow fulfillment of the user is not verified. 9. The method of claim 1 , wherein the user access is subject to a quantity limit, the method further comprising: granting the user the request for user access, by the provider system, when the identity of the user is verified and when an accumulated quantity of t

Assignees

Inventors

Classifications

  • involving authentication · CPC title

  • Use of secure elements separate from M-devices · CPC title

  • G06Q20/347Primary

    Passive cards · CPC title

  • using certificates or pre-shared keys · CPC title

  • Transactions dependent on location of M-devices · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11599872B2 cover?
A provider system is connected to one or more readers corresponding to one or more access points. A secure local connection is established between the user device and the provider system via one reader. The provider system receives from the user device a request for user access via one access point corresponding to the one reader, the provider system sends to the user device a request for ident…
Who is the assignee on this patent?
The Government Of The Us Secretary Of Homeland Security
What technology area does this patent fall under?
Primary CPC classification G06Q20/347. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Mar 07 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).