Permission-based system and network for access control using mobile identification credential

US11711699B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11711699-B2
Application numberUS-202217584223-A
CountryUS
Kind codeB2
Filing dateJan 25, 2022
Priority dateApr 13, 2020
Publication dateJul 25, 2023
Grant dateJul 25, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A provider system is connected to readers disposed at distances from the provider system. A secure local connection is established between the client device and the provider system via one of the readers. Before the client reaches an access touchpoint, the provider system receives from the client device a request for client access, the provider system sends to the client device a request for identification information of the client, and the client device sends client information associated with a first mobile identification credential (MIC) which the client device received from an authorizing party system (APS), the client having consented to release the client information to the provider system, and the client information having been verified. The provider system uses the verified client information associated with the first MIC to verify or not verify the identity of the client before granting or denying the request to the client.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for a client having a client device to request client access from a provider having a provider system, the method comprising: connecting the provider system to a plurality of readers disposed at distances from an access touchpoint and from each other; establishing a secure local connection between the client device and the provider system via a reader of the plurality of readers, before the client and the client device reach the access touchpoint; receiving, by the provider system from the client device, a request for client access before the client and the client device reach the access touchpoint; sending, by the provider system to the client device, a request for identification information of the client before the client and the client device reach the access touchpoint; receiving, by the provider system before the client and the client device reach the access touchpoint, part or all of client information included in a first mobile identification credential (MIC) which the client device received from a first authorizing party system (APS), the part or all of user information including the identification information of the client, the client having consented to release the part or all of client information to the provider system, and the part or all of client information having been verified by the first APS; using, by the provider system, the verified part or all of client information included in the first MIC to verify or not verify an identity of the client; and verifying the identity of the client, by the provider system, before granting the client the request for client access. 2. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from the client device before the client and the client device reach the access touchpoint, a token specifying the part or all of client information which the client has consented to release to the provider system; sending, by the provider system to the first APS, the received token, which is to be verified by the first APS with another token sent from the client device to the first APS; when the tokens are received by the first APS within a preset timeframe and are verified by the first APS, receiving, by the provider system from the first APS, the verified part or all of client information; and when the tokens are not received by the first APS within the preset timeframe or are not verified by the first APS, receiving, by the provider system from the first APS, a notification to resubmit the request for identification information of the client. 3. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from the client device before the client and the client device reach the access touchpoint, an electronic document specifying the part or all of client information which the client has consented to release to the provider system; sending, by the provider system to the first APS, the received electronic document; when the received electronic document is verified by the first APS, receiving, by the provider system from the first APS, the verified part or all of client information; and when the received electronic document is not verified by the first APS, receiving, from the provider system from the first APS, a notification to resubmit the request for identification information of the client. 4. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from client device before the client and the client device reach the access touchpoint, an electronic document and the part or all of client information which the client has consented to release to the provider system; sending, by the provider system to the first APS, the received electronic document; when the received electronic document is verified by the first APS, receiving, by the provider system from the first APS, an authentication key to verify the part or all of client information received from the client device; and when the received electronic document is not verified by the first APS, receiving, by the provider system from the first APS, a notification to resubmit the request for identification information of the client. 5. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from the client device before the client and the client device reach the access touchpoint, the part or all of client information which the client has consented to release to the provider system; and receiving, by the provider system from the first APS, an authentication key to verify the part or all of client information received from the client device, based on a request sent from the client device to the first APS. 6. The method of claim 1 , further comprising: performing a liveness check of the client using live-captured client information at the access touchpoint and determining whether the liveness check is valid or invalid; granting the request from the client, by the provider system, to provide the client access when the identity of the client is verified and when the liveness check is valid; and denying the request from the client, by the provider system, to provide the client access when the identity of the client is not verified or when the liveness check is invalid. 7. The method of claim 1 , further comprising: sending, by the provider system to the client device, a request for client eligibility information of the client; receiving, by the provider system, part or all of client eligibility information associated with the first MIC which the client device received from the first APS or a second MIC which the client device received from a second APS, wherein the client has consented to release the part or all of client eligibility information to the provider system, and wherein the part or all of client eligibility information has been verified by the first APS or the second APS as verified part or all of client eligibility information; using, by the provider system, the verified part or all of client eligibility information to verify or not verify client eligibility of the client; granting the client the request for client access, by the provider system, when the identity and the client eligibility of the client are verified; and denying the client the request for client access, by the provider system, when the identity or the client eligibility of the client is not verified. 8. The method of claim 1 , further comprising: sending, by the provider system to an escrow provider system, a request for information showing that the client has met escrow obligations to receive the client access; receiving, by the provider system, part or all of client escrow fulfillment information associated with an escrow MIC which the client device received from an escrow APS, which is the first MIC issued by the first APS or another MIC issued by another APS, wherein the client has consented to release the part or all of client escrow fulfillment information to the provider system, and wherein the part or all of client escrow fulfillment information has been verified by the escrow APS; using, by the provider system, the verified part or all of client escrow fulfillment information to verify or not verify escrow fulfillment of the client; granting the request for client access, by the provider system to the escrow provider system, to provide to the client the client access when the identity of the client is verified and the escrow fulfillment of the client is verified; and denying the request for client access, by the p

Assignees

Inventors

Classifications

  • H04W12/71Primary

    Hardware identity · CPC title

  • Authentication · CPC title

  • Access security · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • using certificates or pre-shared keys · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11711699B2 cover?
A provider system is connected to readers disposed at distances from the provider system. A secure local connection is established between the client device and the provider system via one of the readers. Before the client reaches an access touchpoint, the provider system receives from the client device a request for client access, the provider system sends to the client device a request for id…
Who is the assignee on this patent?
The Government Of The Us Secretary Of Homeland Security
What technology area does this patent fall under?
Primary CPC classification H04W12/71. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 25 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 10 related publications on this page (citations in our corpus or others sharing the same primary CPC).