Remote identity verification and dynamic storage of identity data

US12593203B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12593203-B2
Application numberUS-202318296547-A
CountryUS
Kind codeB2
Filing dateApr 6, 2023
Priority dateApr 6, 2023
Publication dateMar 31, 2026
Grant dateMar 31, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods are provided to offer security or trust services to entities over a network. A method, according to one implementation, includes the step of receiving, from a representative of an enterprise, a selection of a group of users to be assigned one or more authorities within the enterprise. The method also includes the step of remotely accessing one or more identity information repositories associated with the enterprise to obtain records pertaining to each user of the group. Also, the method includes the step of using the records to onboard the group of users, whereby onboarding the group includes assigning the one or more authorities to each user of the group.

First claim

Opening claim text (preview).

What is claimed is: 1 . A Trust Service Provider (TSP) comprising: a processing device; and a memory device configured to store a computer program having logic that enables the processing device to execute the steps of receiving, from a representative of an enterprise, a selection of a group of users to be assigned one or more authorities within the enterprise, remotely accessing one or more identity information repositories associated with the enterprise to obtain records pertaining to each user of the group, wherein the records are obtained by searching through the one or more identity information repositories to gather a name and other identifying information associated with each user, whereby the name and identifying information are used for performing a Remote Identity Verification (RIV) process to allow the user to perform an action that falls within the one or more authorities assigned to the user, and using the records to onboard the group of users, whereby onboarding the group includes assigning the one or more authorities to each user of the group, and wherein the selection of the group of users includes configuring a policy engine by the representative, the policy engine being adapted to obtain the records pertaining to each user of the group and to automatically capture changes in the records over time, wherein the enterprise includes multiple identity information repositories located in different locations, and wherein onboarding each user further includes: extracting data from a government-issued ID provided by the user; determining, based on the extracted data, an issuer of the government-issued ID and a location of the issuer; searching location information regarding the multiple identity information repositories; selecting one of the multiple identity information repositories that is either in a same territory as the issuer or is closest to the issuer; and storing the name and other identifying information of the user in the selected identity information repository. 2 . The TSP of claim 1 , wherein the logic further enables the processing device to perform an identity verification process, wherein, for each user, the identity verification process includes the steps of: a) receiving input from the respective user to verify the identity of the user, and b) when the identity of the user is verified, enabling the user to perform an action that falls within the one or more authorities assigned to the user. 3 . The TSP of claim 2 , wherein receiving input from the user includes receiving one or more scans of the government-issued ID and one or more visual images of the user captured by a processing device. 4 . The TSP of claim 3 , wherein the one or more visual images include a video of the user when both the processing device and the user's head are in motion. 5 . The TSP of claim 3 , wherein the government-issued ID is a driver's license, a passport, or a national identity card. 6 . The TSP of claim 2 , wherein performing the action includes electronically signing a document. 7 . The TSP of claim 1 , wherein the selection of the group of the users includes: a) allowing the representative to configure or choose a policy engine adapted to obtain the records pertaining to each user of the group; and b) scheduling the policy engine to automatically capture changes in the records. 8 . A non-transitory computer-readable medium configured to store computer logic having instructions that, when executed, enable a processing device to: receive, from a representative of an enterprise, a selection of a group of users to be assigned one or more authorities within the enterprise, remotely access one or more identity information repositories associated with the enterprise to obtain records pertaining to each user of the group, wherein the records are obtained by searching through the one or more identity information repositories to gather a name and other identifying information associated with each user, whereby the name and identifying information are used for performing a Remote Identity Verification (RIV) process to allow the user to perform an action that falls within the one or more authorities assigned to the user, and use the records to onboard the group of users, whereby onboarding the group includes assigning the one or more authorities to each user of the group, and wherein the selection of the group of users includes configuring a policy engine by the representative, the policy engine being adapted to obtain the records pertaining to each user of the group and to automatically capture changes in the records over time, wherein the enterprise includes multiple identity information repositories located in different locations, and wherein onboarding each user further includes: extracting data from a government-issued ID provided by the user; determining, based on the extracted data, an issuer of the government-issued ID and a location of the issuer; searching location information regarding the multiple identity information repositories; selecting one of the multiple identity information repositories that is either in a same territory as the issuer or is closest to the issuer; and storing the name and other identifying information of the user in the selected identity information repository. 9 . The non-transitory computer-readable medium of claim 8 , wherein the instructions further enable the processing device to perform an identity verification process, wherein, for each user, the identity verification process includes the steps of: a) receiving input from the respective user to verify the identity of the user, and b) when the identity of the user is verified, enabling the user to perform an action that falls within the one or more authorities assigned to the user. 10 . The non-transitory computer-readable medium of claim 9 , wherein receiving input from the user includes receiving one or more scans of government-issued ID and one or more visual images of the user captured by a processing device. 11 . The non-transitory computer-readable medium of claim 10 , wherein the one or more visual images include a video of the user when both the processing device and the user's head are in motion. 12 . The non-transitory computer-readable medium of claim 10 , wherein the government-issued ID is a driver's license, a passport, or a national identity card. 13 . The non-transitory computer-readable medium of claim 9 , wherein performing the action includes electronically signing a document. 14 . The non-transitory computer-readable medium of claim 8 , wherein the selection of the group of the users includes: a) allowing the representative to configure or choose a policy engine adapted to obtain the records pertaining to each user of the group; and b) schedule the policy engine to automatically capture changes in the records. 15 . A method comprising steps of: receiving, from a representative of an enterprise, a selection of a group of users to be assigned one or more authorities within the enterprise, remotely accessing one or more identity information repositories associated with the enterprise to obtain records pertaining to each user of the group, wherein the records are obtained by searching through the one or more identity information repositories to gather a name and other identifying information associated with each user, whereby the name and identifying information are used for performing a Remote Identity Verification (RIV) process to allow the user to perform an action that falls within the one or more authorities assigned to the user, and using

Assignees

Inventors

Classifications

  • Identity-dependent · CPC title

  • Processing or transfer of terminal data, e.g. status or physical capabilities · CPC title

  • H04W12/02Primary

    Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12593203B2 cover?
Systems and methods are provided to offer security or trust services to entities over a network. A method, according to one implementation, includes the step of receiving, from a representative of an enterprise, a selection of a group of users to be assigned one or more authorities within the enterprise. The method also includes the step of remotely accessing one or more identity information re…
Who is the assignee on this patent?
Digicert Inc
What technology area does this patent fall under?
Primary CPC classification H04W12/02. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).