Systems and methods for use in securing digital identities for user authentication

US12580911B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12580911-B2
Application numberUS-202418595299-A
CountryUS
Kind codeB2
Filing dateMar 4, 2024
Priority dateMar 4, 2024
Publication dateMar 17, 2026
Grant dateMar 17, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods are provided for use in provisioning digital identities for users. One example computer-implemented method includes receiving, by a computing device, a request to register a digital identity to the communication device, where the request includes a unique device identifier specific to the communication device and at least one biometric, and determining, by the computing device, whether the unique device identifier is associated with an existing digital identity. The method also includes, in response to determining that the unique device identifier is associated with the existing digital identity, declining, by the computing device, provisioning of a digital identity to the communication device.

First claim

Opening claim text (preview).

What is claimed is: 1 . A system for use in provisioning a digital identity for a user to a communication device, the system comprising: a database including multiple existing digital identities; and a computing device, which is configured by executable instructions, to: receive a request to register a digital identity to the communication device, the request including a unique device identifier specific to the communication device and at least one biometric; search for the unique device identifier in the database; in response to the unique device identifier being included in the database in one of the multiple existing digital identities, decline to provision a digital identity to the communication device; and in response to the unique device identifier not being included in the database in one of the multiple existing digital identities: determine whether the at least one biometric is included in the database; and in response to the at least one biometric not being in the database, generate a digital identity for the communication device based on the request to register the digital identity. 2 . The system of claim 1 , wherein the unique device identifier includes an electronic serial number (ESN) and/or a MAC address. 3 . The system of claim 1 , wherein the request includes additional data; and wherein the computing device is further configured, by the executable instructions, to: in response to the unique device identifier not being included in the database in one of the multiple existing digital identities, determine whether the at least one biometric is included in the database; and in response to the at least one biometric being in the database in one of the multiple digital identities, determine whether the additional data matches data included in the one of the multiple existing digital identities in the database; and in response to the additional data matching the data included in the one of the multiple existing digital identities in the database, generate a digital identity for the communication device based on the request to register the digital identity. 4 . The system of claim 3 , wherein the additional data includes a government identification number, a mobile number, and a name. 5 . The system of claim 3 , wherein the computing device is configured, by the executable instructions, in determining whether the additional data matches data included in the one of the multiple existing digital identities in the database, to: hash the additional data; and compare the hashed data to the data included in the one of the multiple existing digital identities in the database. 6 . The system of claim 3 , wherein the additional data includes a public key generated by the communication device. 7 . The system of claim 3 , wherein the computing device is further configured, by the executable instructions, to, in response to the additional data not matching the data included in the one of the multiple existing digital identities in the database, decline to provision a digital identity to the communication device. 8 . A non-transitory computer-readable storage medium comprising executable instructions, which when executed by at least one processor in connection with provisioning a digital identity for a user to a communication device, cause the at least one processor to: receive a request to register a digital identity to the communication device, the request including a unique device identifier specific to the communication device and at least one biometric; search for the unique device identifier in a database having multiple existing digital identities; and in response to the unique device identifier being included in the database in one of the multiple existing digital identities, decline to provision a digital identity to the communication device; in response to the unique device identifier not being included in the database in one of the multiple existing digital identities: determine whether the at least one biometric is included in the database; and in response to the at least one biometric not being in the database, generate a digital identity for the communication device based on the request to register the digital identity. 9 . The non-transitory computer-readable storage medium of claim 8 , wherein the unique device identifier includes an electronic serial number (ESN) and/or a MAC address. 10 . The non-transitory computer-readable storage medium of claim 8 , wherein the request includes additional data; and wherein the executable instructions, when executed by the at least one processor, further cause the at least one processor to: in response to the unique device identifier not being included in the database in one of the multiple existing digital identities, determine whether the at least one biometric is included in the database; and in response to the at least one biometric being in the database in one of the multiple existing digital identities, determine whether the additional data matches data included in the one of the multiple existing digital identities in the database; and in response to the additional data matching the data included in the one of the multiple existing digital identities in the database, generate a digital identity for the communication device based on the request to register the digital identity. 11 . The non-transitory computer-readable storage medium of claim 10 , wherein the additional data includes a government identification number, a mobile number, and a name. 12 . The non-transitory computer-readable storage medium of claim 10 , wherein the executable instructions, when executed by the at least one processor to determine whether the additional data matches data included in the one of the multiple existing digital identities in the database, cause the at least one processor to: hash the additional data; and compare the hashed data to the data included in the one of the multiple existing digital identities in the database. 13 . The non-transitory computer-readable storage medium of claim 10 , wherein the additional data includes a public key generated by the communication device. 14 . The non-transitory computer-readable storage medium of claim 10 , wherein the executable instructions, when executed by the at least one processor, in response to the additional data not matching the data included in the one of the multiple existing digital identities in the database, to decline to provision a digital identity to the communication device.

Assignees

Inventors

Classifications

  • using biometrical features, e.g. fingerprint, retina-scan (cryptographic mechanisms or cryptographic arrangements for entity authentication using biological data H04L9/3231) · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12580911B2 cover?
Systems and methods are provided for use in provisioning digital identities for users. One example computer-implemented method includes receiving, by a computing device, a request to register a digital identity to the communication device, where the request includes a unique device identifier specific to the communication device and at least one biometric, and determining, by the computing devi…
Who is the assignee on this patent?
Mastercard International Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0876. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 17 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).