Providing user attributes to complete an online transaction

US9384330B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9384330-B2
Application numberUS-201113316251-A
CountryUS
Kind codeB2
Filing dateDec 9, 2011
Priority dateDec 9, 2011
Publication dateJul 5, 2016
Grant dateJul 5, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A first server device receives a request for attributes, of a user, from a second server device associated with a receiving entity. The first server device determines whether the receiving entity is entitled to receive the attributes, and authenticates an identity of the user. The first server device also identifies the attributes based on the identity when the receiving entity is entitled to receive the attributes, and transmits the identified attributes to the second server device.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: receiving, by a first server device, a request for information from a second server device of a receiving entity, wherein the request for information corresponds to a plurality of attributes and are independently-verified attribute data and attribute data self-asserted by a user, corresponding to a same one of the attributes, differ, and wherein the request for information is related to a transaction between the user and the receiving entity; receiving, by the first server device, policy information associated with the receiving entity, wherein the policy information is based upon the type of the receiving entity and the type of transaction; determining, by the first server device, that the receiving entity is entitled to receive the information corresponding to at least one of the requested attributes that is required to process the transaction; determining, by the first server device, that the receiving entity is not entitled to receive the information corresponding to one or more of the requested attributes that are not necessary to process the transaction; based on a determination that the receiving entity is entitled to receive the information corresponding to at least one of the requested attributes that is required to process the transaction, authenticating, an identify of the user; based on a determination that the receiving entity is not entitled to receive the information corresponding to at least one of the requested attributes that is required to process the transaction, generating a request for the user's consent to provide the information corresponding to the one or more of the requested attributes to the receiving entity; receiving, by the first server device, user's consent to provide the information corresponding to the one or more of the requested attributes to the receiving entity; determining, by the first server device, that the user's consent to provide the information corresponding to the one or more of the requested attributes to the receiving entity, was not received; based on a determination that the user's consent to provide the information corresponding to the one or more of the requested attributes to the receiving entity, was not received, transmitting notification to the second server device; identifying, by the first server device, the information corresponding to the at least one necessary attribute, based on the authenticated identity, that the receiving entity is entitled to receive; identifying, by the first server device, the information corresponding to the one or more of the unnecessary attributes for which consent is received from the user; and transmitting, by the first server device, the identified information to the second server device. 2. The method of claim 1 , receiving the request for the information corresponding to the plurality of attributes, comprising one or more of: receiving a request for an age of the user, receiving a request for a gender of the user, receiving a request for an address of the user, or receiving a request for one or more professional attributes associated with a profession identified with the user. 3. The method of claim 1 , receiving the request from the second server device of the receiving entity, comprising one of: receiving the request from the second server device of an online merchant, receiving the request from the second server device of a service provider, or receiving the request from the second server device of a government agency. 4. The method of claim 1 , further comprising: associating the request for the information corresponding to the plurality of attributes with an online transaction between the receiving entity and the user, in which: the online transaction is one of an online purchase or a request for information. 5. The method of claim 1 , further comprising: receiving permission to provide the information corresponding to a particular type of attribute to the receiving entity; requesting the information corresponding to a verified attribute of the particular type of attribute from a third server device; and receiving, before receiving the request for the information corresponding to the plurality of attributes, the information corresponding to the verified attribute from the third server device, where the verified attribute is one of the identified attributes. 6. The method of claim 1 , further comprising: determining a type of the receiving entity; determining types of attributes that are required, for the second server device to process online transactions, based on the type of the receiving entity; and creating a policy for the receiving entity based on the types of attributes that are required. 7. The method of claim 6 , determining that the receiving entity is entitled to receive the information corresponding to the at least one attribute, comprising: determining that the receiving entity is entitled to receive the information corresponding to the attributes that are of the types of attributes specified in the policy. 8. The method of claim 1 , further comprising: determining whether consent is received from the user in response to the request for the user's consent; and not identifying the information corresponding to a first attribute of the one or more of the unnecessary attributes for which consent is not received to provide the information corresponding to the first attribute of the one or more unnecessary attributes to the receiving entity. 9. The method of claim 8 , further comprising: transmitting a notification to the second server device that the consent is not received for the information corresponding to the first attribute of the one or more unnecessary attributes.

Assignees

Inventors

Classifications

  • Identity check for transactions · CPC title

  • G06Q20/12Primary

    specially adapted for electronic shopping systems · CPC title

  • providing single-sign-on or federations · CPC title

  • G06F21/00Primary

    Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity · CPC title

  • for controlling access to devices or network resources · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9384330B2 cover?
A first server device receives a request for attributes, of a user, from a second server device associated with a receiving entity. The first server device determines whether the receiving entity is entitled to receive the attributes, and authenticates an identity of the user. The first server device also identifies the attributes based on the identity when the receiving entity is entitled to r…
Who is the assignee on this patent?
Donfried Paul A, Tippett Peter S, Tallent Jr Guy S, and 2 more
What technology area does this patent fall under?
Primary CPC classification G06Q20/12. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jul 05 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).