US2023254303A1PendingUtilityA1

Systems and methods for real-time identity verification using a token code

Assignee: MASTERCARD INTERNATIONAL INCPriority: Oct 4, 2019Filed: Apr 18, 2023Published: Aug 10, 2023
Est. expiryOct 4, 2039(~13.2 yrs left)· nominal 20-yr term from priority
H04L 63/0823H04L 9/3213H04L 9/3228H04L 63/0428H04L 9/0825H04L 2209/84H04L 63/0838H04L 63/0892H04L 63/0807
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An identity authority computing device having a processor in communication with a database is described herein. The database stores a plurality of persistent user identifiers associated with a plurality of users. The processor is programmed to receive a service request over a public network, the service request including a service provider identifier and a single-use token value associated with one of the users. The processor is also programmed to determine at least one persistent user identifier associated in the database with the token value, and generate an updated service request including the at least one persistent user identifier. The processor further is programmed to generate an encrypted service request using a public encryption key associated with the service provider identifier, and transmit the encrypted service request to a service provider computing device associated with the service provider identifier.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . An identity authority computing device comprising a processor configured to:
 communicate with a public network and a secure data processing domain, and prevent access from the public network to confidential user data stored in the secure data processing domain;   transmit, within the secure data processing domain, an encrypted service request to a service provider computing device, the encrypted service request including at least one persistent user identifier, the encrypted service request transmitted in response to a service request (i) including a token value associated with a user and (ii) received over the public network from an interface domain associated with an interface computing device;   receive a service response from the service provider computing device, the service response including response data and the at least one persistent user identifier;   filter the at least one persistent user identifier from the service response; and   transmit the filtered service response and the token value to the interface computing device.   
     
     
         22 . The identity authority computing device of  claim 21 , wherein the processor is further configured to filter the at least one persistent user identifier from the service response by replacing the at least one persistent user identifier with the token value. 
     
     
         23 . The identity authority computing device of  claim 22 , wherein replacing the at least one persistent user identifier with the token value enables associating the service response with the service request without using the at least one persistent user identifier. 
     
     
         24 . The identity authority computing device of  claim 21 , wherein transmitting the filtered service response to the interface computing device causes the interface computing device to generate an application view based on the service response, and transmit the application view to a user computing device in communication with the interface computing device. 
     
     
         25 . The identity authority computing device of  claim 24 , wherein the application view includes at least one of credit history data, personal background data, and vehicle insurance data. 
     
     
         26 . The identity authority computing device of  claim 21 , wherein the interface computing device is in communication with a user computing device, and wherein the service request further includes a service provider identifier associated with the service provider computing device. 
     
     
         27 . The identity authority computing device of  claim 21 , wherein the processor is further configured to, in response to the service request, access an identity database within the secure data processing domain, and wherein the identity database stores and indexes confidential information for a plurality users including a plurality of persistent user identifiers. 
     
     
         28 . A computer-implemented method for secure transmission of user identifiers, the method implemented using an identity authority computing device including a processor, the method comprising:
 communicating with a public network and a secure data processing domain, and prevent access from the public network to confidential user data stored in the secure data processing domain;   transmitting, within the secure data processing domain, an encrypted service request to a service provider computing device, the encrypted service request including at least one persistent user identifier, the encrypted service request transmitted in response to a service request (i) including a token value associated with a user and (ii) received over the public network from an interface domain associated with an interface computing device;   receiving a service response from the service provider computing device, the service response including response data and the at least one persistent user identifier;   filtering the at least one persistent user identifier from the service response; and   transmitting the filtered service response and the token value to the interface computing device.   
     
     
         29 . The method of  claim 28  further comprising filtering the at least one persistent user identifier from the service response by replacing the at least one persistent user identifier with the token value. 
     
     
         30 . The method of  claim 29 , wherein replacing the at least one persistent user identifier with the token value enables associating the service response with the service request without using the at least one persistent user identifier. 
     
     
         31 . The method of  claim 28 , wherein transmitting the filtered service response to the interface computing device causes the interface computing device to generate an application view based on the service response, and transmit the application view to a user computing device in communication with the interface computing device. 
     
     
         32 . The method of  claim 31 , wherein the application view includes at least one of credit history data, personal background data, and vehicle insurance data. 
     
     
         33 . The method of  claim 28 , wherein the interface computing device is in communication with a user computing device, and wherein the service request further includes a service provider identifier associated with the service provider computing device. 
     
     
         34 . The method of  claim 28  further comprising, in response to the service request, accessing an identity database within the secure data processing domain, and wherein the identity database stores and indexes confidential information for a plurality users including a plurality of persistent user identifiers. 
     
     
         35 . A non-transitory computer readable storage medium having computer-executable instructions embodied thereon, wherein when executed by an identity authority computing device having a processor, the computer-executable instructions cause the processor to:
 communicate with a public network and a secure data processing domain, and prevent access from the public network to confidential user data stored in the secure data processing domain;   transmit, within the secure data processing domain, an encrypted service request to a service provider computing device, the encrypted service request including at least one persistent user identifier, the encrypted service request transmitted in response to a service request (i) including a token value associated with a user and (ii) received over the public network from an interface domain associated with an interface computing device;   receive a service response from the service provider computing device, the service response including response data and the at least one persistent user identifier;   filter the at least one persistent user identifier from the service response; and   transmit the filtered service response and the token value to the interface computing device.   
     
     
         36 . The non-transitory computer readable storage medium of  claim 35 , wherein the computer-executable instructions further cause the processor to filter the at least one persistent user identifier from the service response by replacing the at least one persistent user identifier with the token value. 
     
     
         37 . The non-transitory computer readable storage medium of  claim 36 , wherein replacing the at least one persistent user identifier with the token value enables associating the service response with the service request without using the at least one persistent user identifier. 
     
     
         38 . The non-transitory computer readable storage medium of  claim 35 , wherein transmitting the filtered service response to the interface computing device causes the interface computing device to generate an application view based on the service response, and transmit the application view to a user computing device in communication with the interface computing device. 
     
     
         39 . The non-transitory computer readable storage medium of  claim 35 , wherein the interface computing device is in communication with a user computing device, and wherein the service request further includes a service provider identifier associated with the service provider computing device. 
     
     
         40 . The non-transitory computer readable storage medium of  claim 35 , wherein the computer-executable instructions further cause the processor to, in response to the service request, access an identity database within the secure data processing domain, and wherein the identity database stores and indexes confidential information for a plurality users including a plurality of persistent user identifiers.

Join the waitlist — get patent alerts

Track US2023254303A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.