Techniques for generating and using uncorrelatable digital credentials
By generating and storing multiple instances of digital credentials, each with a different mobile security object, the problem of associating digital credentials across different requests is solved, achieving enhanced privacy and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- APPLE INC
- Filing Date
- 2024-05-31
- Publication Date
- 2026-07-03
AI Technical Summary
Existing digital credentials are easily linked when responding to different requests, leading to user privacy leaks and information sharing, and failing to effectively protect user privacy.
By generating and storing multiple digital credential instances, each with the same data elements but different Mobile Security Objects (MSOs), it is ensured that different requests use different credential instances, preventing the requester from associating user information.
It achieves independence between different requests, protects user privacy, prevents unauthorized information sharing and collusion, and improves the security and privacy protection of digital credentials.
Smart Images

Figure CN121311911B_ABST
Abstract
Description
[0001] Cross-references to other applications
[0002] This application claims priority to U.S. Patent Application No. 18 / 205,244, filed June 2, 2023, entitled “Techniques For Generating And Using Nonlinkable Digital Credentials” and U.S. Patent Application No. 18 / 205,278, filed June 2, 2023, entitled “Techniques For Generating And Using Nonlinkable Digital Credentials”, the entire contents of which are incorporated herein by reference for all purposes. Technical Field
[0003] This disclosure relates in whole to the generation and use of digital credentials stored on user devices. Background Technology
[0004] Credentials (such as driver's licenses) are issued by the issuer and trusted by the dependent party. Digital credentials can also be issued by the issuer and stored on the user's device to communicate associated information to the dependent party. Attached Figure Description
[0005] Figure 1 This is a block diagram of an example system for responding to requests for information associated with digital credentials.
[0006] Figure 2 This is a block diagram of an example system for responding to requests for information associated with digital credentials.
[0007] Figure 3 This is a block diagram of an example system for generating digital credentials.
[0008] Figure 4 This is a flowchart of an example process for implementing the technology described in this article.
[0009] Figure 5 This is a flowchart of an example process for implementing the technology described in this article.
[0010] Figure 6 This is a flowchart of an example process for implementing the technology described in this article.
[0011] Figure 7 A simplified block diagram of an example system architecture for the controller is shown. Detailed Implementation
[0012] Certain embodiments of this disclosure relate to apparatus, computer-readable media, and methods for implementing various techniques for generating digital credentials and responding to requests for digital credentials. Various embodiments will be described in the following description. For purposes of explanation, numerous specific configurations and details are set forth to provide a thorough understanding of the embodiments. However, it will also be apparent to those skilled in the art that these embodiments can be implemented without these specific details. Furthermore, well-known features may be omitted or simplified to avoid obscuring the embodiments described herein.
[0013] Examples of this disclosure relate to methods, systems, devices, and computer-readable media for generating digital credentials and responding to requests for digital credentials. Digital credentials can include any kind of digital document or data structure (e.g., digital driver's license, digital passport, digital ticket, digital license, etc.) used to convey information about a user. In some examples, digital credentials may be authorized and / or issued by an issuer. An issuer can be any entity deemed trustworthy or conveying authorization to provide the digital credential. For example, a driver's license can be a digital credential where the issuer is a motor vehicle administration department, etc. Other examples of digital credentials may include digital passports, digital certificates, or any form of digital identification / verification. Digital credentials differ from traditional credentials in that they can be stored electronically, such as on a user device like a smartphone, smartwatch, tablet, laptop, or any other electronic user device.
[0014] Digital credentials may include data elements and / or Mobile Security Objects (MSOs). Data elements may include information about the digital credentials. In the example of a Mobile Driving License (mDL), data elements may include name, first name, last name, middle name, initials of middle name, mailing address, residential address, components of the address, age, date of birth, a picture of the driver's license user / owner, eye color, hair color, height, weight, and other information. Other data elements may include race, nationality, blood type, etc.
[0015] Mobile security objects (MSOs) may include information proving the authenticity of digital credentials. This information can be divided into security elements. Example security elements may include issuer signatures, transaction keys, and hashes as described herein. In some examples, an MSO may include an issuer signature proving that the issuer authorized and issued the digital credentials. For example, an issuer signature on an mDL would indicate that an mDL has been issued by a vehicle administration authority, etc. In some examples, an MSO may include a transaction key from the user device and / or user profile requesting the digital credentials. For example, a transaction key may have been transmitted from the user device to a vehicle administration authority, identifying that the user device and / or associated profile exists and is requesting an mDL. The transaction key can be used by the issuer to issue digital credentials to a specific device and / or profile associated with the user. This prevents digital credentials from being copied by a different device and / or profile associated with another user. Similarly, the transaction key can be used by the requesting party (and associated requesting device) to identify attempts by unauthorized devices to share fraudulent digital credentials with the requesting party. In some examples, an MSO may include an expiration date indicating when the digital credentials are no longer valid. In some examples, the MSO may include a hash, where some or all of the valid data elements of the digital credential are input to ensure that the data elements are verifiable and immutable. In some examples, the hash may have random values included as input so that different hashes are generated even if the valid data elements are all equivalent. By including random values as input to the hash, the MSO associated with each mDL can have different hash values.
[0016] Digital credentials can be used to verify information about a user associated with them. However, unlike traditional physical credentials, digital credentials can be configured to present only partial information to the requesting party or requesting device. For example, a requesting device (e.g., a terminal or point-of-sale (POS) device or credential verification device) at a particular business, entity, or venue (e.g., a bar or restaurant) can request a user's age to verify that the user is legally authorized to order alcohol. The user can use their mDL on their device to respond with only their age and / or birthday, as other information associated with the mDL (e.g., name and address) may be unnecessary for entry or ordering alcohol. This allows digital credentials to better protect user privacy than traditional physical credentials, where presenting a traditional identifier would convey additional information (such as name and address) that is not necessarily needed for a particular instance.
[0017] In some examples, the response to an information request from a digital credential includes a mobile security object for the digital credential. The mobile security object can be used to ensure that the issuer actually issues the digital credential in the same way as using a seal, format, barcode, etc., to prove that the issuer has issued a traditional physical credential such as a driver's license. Additionally, in some cases, the security elements of the mobile security object are immutable when the digital credential is created.
[0018] Alternatively, in some examples, while responses to different requests for information from digital credentials may differ, the responses may include the same mobile security object (MSO). For example, a user might use their mDL to respond to a bar's request with their age, and then also use their mDL to respond to a bank's request with their name, address, and other information. Although the responses to each requester (and their corresponding requesting device) contain different data elements, both responses may include the same MSO. This could inadvertently allow responses to be correlated, enabling the requesting party to determine that all responses are associated with the same user. This could allow banks and bars to collude and potentially correlate responses from users and their mDLs to share information about the user. For example, banks and bars could review the MSO and determine that the same user responded to their requests. Banks and bars could then share the information they have about the user and identify information that was originally intended to be hidden from the parties, such as the bar now knowing the name and address of the user associated with the mDL. Additionally, in this example, even if the user might believe that their transaction was not originally associated with them, banks and bars could still associate the mDL with a specific individual (e.g., the mDL owner). Therefore, the methods and techniques described in this paper provide unlinkable digital credentials.
[0019] As described herein, a user equipment can be configured to generate, store, and present multiple instances of digital credentials without the user's knowledge. Different instances of a digital credential can have the same data elements but different MSOs. For example, a user equipment can be configured to generate, store, and present multiple different instances of an mDL associated with a user based on the requester. While data elements such as name, address, and eye color are identical for each instance of the mDL, the issuer signature, transaction key, and hash of the mDL data elements can all be unique for each instance of the mDL.
[0020] By using multiple instances of digital credentials, a user device can use different instances to generate responses to the requesting party / requesting device. For example, a user device can use a first instance of the mDL to generate a response to a bar's request for age, and a second instance of the mDL to generate a response to a bank's request for name and address. In this way, the response will include different MSOs corresponding to the instances used to generate the response, making it possible for the bank and the bar to not identify the same user responding to their requests; therefore, the mDLs cannot be associated with each other or with a user.
[0021] Similarly, a user equipment can determine that the same requester / requesting device is requesting information associated with digital credentials. For example, if a user goes to a bar and responds with their age, the user equipment can respond to a second request for age using the same instance of the previously used digital credentials when the user returns to the bar on a subsequent occasion.
[0022] When generating multiple instances of digital credentials, a user equipment (UE) may generate multiple sets of transaction keys to be used in generating the sets of digital credential instances. The transaction key sets can be used to generate a packet that can be transmitted to a first server. The first server can verify that the request packet originates from an authorized UE and is authentic. The first server can then transmit the request packet to a second server associated with the issuer of the digital credential. The issuer can use the request packet, specifically the transaction key sets, to generate the set of digital credential instances to be transmitted to the UE. The issuer's second server can then transmit the set of digital credential instances to the first server. In some examples, the first server can verify that the set of digital credential instances was correctly and authentically generated by the issuer. In some examples, the first server does not verify the set of digital credential instances. The first server can then transmit the set of digital credentials to the UE. The UE can store the credential set for use in generating responses to requests for information associated with the digital credentials.
[0023] User equipment may store some or all of its digital credentials in a secure hardware element designed to securely store and generate cryptographic information. If the secure element detects tampering, it can destroy any information contained therein to prevent tampering or retrieval. In some examples, the user equipment's application processes store digital credentials. These digital credentials may be stored cryptographically using a cryptographic key stored in the secure element. Therefore, digital credentials can be in a format that is unreadable and immutable without decryption using the encryption key stored in the secure element.
[0024] Now turn to the attached image. Figure 1Example Figure 100 illustrates the digital credential technology described herein. A user device 102 associated with user 104 may store one or more digital credentials 106 of one or more types associated with user 104. Example digital credentials may be a mobile driving license (mDL) in electronic or digital form, a passport, certificate, license, or any other form of digital certificate or authorization. User device 102 may store multiple types of digital credentials. For example, user device 102 may have a first type of digital credential in the form of a driving license, a second type of digital credential in the form of a digital passport, and a third type of digital credential such as a professional license. Digital credential 106 may include data element 108 and a Mobile Security Object (MSO) 110. Data element 108 may include information about the digital credential. As described herein, in an example of a mobile driving license (mDL), data element 108 may include name, first name, last name, middle name, initials of middle name, mailing address, residential address, components of address, age, date of birth, a picture of the user / owner of the driving license, eye color, hair color, height, weight, and other information. In the example of a professional license, data element 108 may include the license number, professional telephone number, professional email address, and other information.
[0025] Mobile security object 110 may include information proving the authenticity of digital credential 106. As described herein, the information proving MSO 110 may be divided into security elements. Example security elements may include issuer signature, transaction key, and hash as described herein. In some examples, MSO 110 may include an issuer signature proving that the issuer authorized and issued digital credential 106. For example, the issuer signature on the mDL would indicate that the mDL has been issued by a vehicle management authority, etc. In some examples, MSO 110 may include a transaction key from the user device and / or user profile requesting the digital credential. For example, the transaction key transmitted from the user device to the vehicle management authority identifies that the user device and / or associated profile exists and is requesting the mDL. The transaction key may be used by the issuer to issue digital credentials to a specific device and / or profile associated with the user. This prevents digital credentials from being copied by a different device and / or profile associated with another user. Similarly, the transaction key may be used by the requesting party (and associated requesting device) to identify attempts by unauthorized devices to share fraudulent digital credentials with the requesting party. In some examples, MSO 110 may include an expiration date that identifies when digital credential 106 is no longer valid. In some examples, user equipment 102 may use the expiration date to determine that digital certificate 106 cannot be used to generate a response. In some examples, requesting equipment may use the expiration date to determine that a response is invalid. In some examples, MSO 110 may include a hash of some or all of the valid data elements 108 of digital credential 106 to ensure that data elements 108 are verifiable and immutable.
[0026] User equipment 102 may store multiple instances of digital credentials 106. For example, user equipment 102 may store multiple instances of mDL and / or multiple instances of digital passports (also referred to as mobile passports). Each instance of digital credentials 106 includes a set 108 of the same data elements and different MSOs 110. For example, a first instance of mDL and a second instance of mDL may include the same data elements as described herein, such as name, mailing address, etc. However, the first instance of mDL and the second instance of mDL may have different mobile security objects. Instances of digital credentials 106 may have different issuer signatures, different transaction keys, and / or different hashes of some or all of the valid data elements 108 as described herein. User equipment 102 may generate multiple instances of digital credentials 106 as described herein.
[0027] User equipment 102 may receive requests 124, 134 from requesting devices 120, 130 for information from digital credentials 106. Requesting devices may be user equipment such as smartphones, smartwatches, tablets, laptops, computers, or computing devices, or any other electronic user equipment configured to request information associated with digital credentials. Requesting devices may also be terminals or point-of-sale (POS) devices. In some examples, a request may include information about a specific requested information. For example, a request may ask for age or address. In some examples, a request may include information about the type of digital credentials to be used. For example, a request may include a request for specific information from an mDL and / or digital passport. Requesting devices 120, 130 may be associated with requesters 122, 132 and corresponding profiles, such that a requester may have multiple requesting devices associated with each requester. For example, a requester may be a bar requesting age information to verify that the user associated with the digital credentials is legally permitted to purchase and consume alcohol. A requester may have multiple requesting devices, all of which are associated with the requester's profile.
[0028] User equipment 102 may generate responses 126 and 136 to send to requesting devices 120 and 130. Responses 126 and 136 may be generated based on data element 108 of the digital credential and MSO 110. In some examples, the response may be generated to include the entire digital credential. In some examples, the response may be generated to include a subset of data element 108 of the digital credential 106 and MSO 110. For example, the requesting device may be associated with a zoo offering discounts to local residents. The request may query address information to verify that the user 104 associated with digital credential 106 is considered a local resident.
[0029] Figure 2Example Figure 200 illustrates the digital credentials technology described herein. As described herein, with user 204 (e.g., Figure 1 User 104) associated with user device 202 (e.g., Figure 1 User equipment 102) can obtain from requester 222 (e.g., Figure 1 The requesting device 220 associated with the requesting parties 122, 132 (e.g., Figure 1 The requesting devices 120 and 130) receive digital credentials (e.g., stored on the user equipment 204) regarding the request. Figure 1 Request 224 for information (e.g., digital credentials 106) Figure 1 Requests 124 and 134). User equipment 204 may generate response 226 (e.g., Figure 1 The response 226 (or 126, 136) is sent to the requesting device 220. Response 226 may include the requested data element 232 and MSO 234. In some examples, the requested data element 232 is a data element associated with a digital credential (e.g., ...). Figure 1 Data element 108). In some examples, the requested data element 232 is a subset of the data elements associated with the digital credential. In some examples, MSO 234 is the MSO of the digital credential (e.g., Figure 1 MSO 110). In some examples, MSO 234 includes a subset of the elements of the MSO of digital credentials.
[0030] In some examples, request 224 may specify what type of digital credentials can be used to generate response 226. For example, request 224 may specify that mDL and / or digital passports can be used to generate response 226.
[0031] In some examples, when generating response 226, user equipment 202 may determine which type of digital credentials to use to generate response 226. As described herein, user equipment may store two or more types of digital credentials. For example, user equipment 202 may determine to use mDL to generate response 226 to request 224. Alternatively, user equipment 202 may determine to use a digital passport (also known as a mobile passport) to generate response 226 to request 224. When determining which type of digital credentials to use to generate the response, user equipment 202 may assign a priority to each type of digital credential such that user equipment 202 will use the higher priority type of digital credential instead of the lower priority type. For example, user equipment 202 may assign higher priority to mDL and lower priority to the digital passport such that if both digital credentials are available to generate the response, mDL will be used to generate the response due to the higher priority. In some examples, the priority of each type of digital credential may be selected by user 204 or may be dynamically calculated and / or updated over time.
[0032] In some examples, when generating response 226, user equipment 202 may determine which instance of a specific digital credential should be used to generate response 226 as described herein. For example, user equipment 202 may have 10 instances of mDL. User equipment 202 may have any number of instances of a specific digital credential. For example, user equipment 202 may have 2, 3, 4, 5, 6, 7, 8, 9, 10, 15, 20, 25, 30, 40, 50, 100, or 1000 instances of a specific digital credential. When requesting device 220 transmits a request to user equipment 202, user equipment 202 may determine which of the 10 instances of mDL to use when generating the response. As described herein, each instance of mDL has the same data elements but different MSOs. Therefore, response 226 will differ based on which instance of the digital credential was used to generate response 226.
[0033] In some examples, request 224 includes information about requester 222. In some examples, the request includes information about a profile associated with requester 222. Multiple requesting devices of requester 222 (such as requesting device 220) may be associated with the same profile of requester 222. When user device 202 receives request 224, user device 202 may determine whether user device 202 has previously received a request from or associated with the profile associated with requester 222. If user device 202 has previously received a request associated with the profile, user device 202 may use the same instance of digital credentials to generate a response. For example, user device 202 may receive a request to verify age from a first requesting device associated with a bar as the requester. User device 202 may use a first instance of mDL to generate response 226 and send it to the first requesting device. At a later time, a second requesting device associated with the bar may transmit a request to verify age to user device 202. The request may include information about the bar's profile, and user device 202 may determine that the bar has previously requested information from user device 202. User equipment 202 may determine to use a first instance of mDL to generate a response and send that response to the second requesting device. Similarly, if the first requesting device transmits request 224 to user equipment 202, the request may include information about the bar's profile, and user equipment 202 may determine that the bar has previously requested information from user equipment 202 and determine to use a first instance of mDL to generate a response.
[0034] In some examples, user equipment 202 may store profile information and associate the profile information with a specific instance used to generate a response to a request from an associated requester 222. For example, the user equipment may associate profile information from a bank requesting information from an mDL with a fourth instance of the mDL stored on the user equipment. Thus, when the user equipment receives a request from a requesting device associated with the bank, the user equipment can use the fourth instance of the mDL to generate a response. By using the same instance of digital credentials to process requests associated with the same requester, the user equipment can efficiently utilize instances of digital credentials and requires less storage capacity and / or computing resources. As described herein, using different instances of digital credentials for at least a number of requesters reduces the ability of requesters to collude and share information about users and / or associated digital credentials without the permission and / or knowledge of the associated users.
[0035] In some examples, user equipment 202 may determine that the profile associated with the requesting device has not previously requested information from user equipment 202. Request 224 may include profile information associated with requester 222 and enables user equipment 202 to determine that user equipment 202 has not previously received a request from any device associated with requester 222. User equipment 202 may then determine an instance of digital credentials from which a response is generated. In some examples, user equipment 202 may select an unused instance of digital credentials. For example, user equipment 202 may determine that a fifth instance of mDL has not yet been used to generate a response and determine to use that fifth instance of mDL to generate a response. As described herein, using different instances of digital credentials for at least a number of requesters reduces the ability of requesters to collude and share information about users and / or associated digital credentials without the permission and / or knowledge of the associated users.
[0036] In some examples, user equipment 202 may select the least frequently used instance of a digital credential. For example, user equipment 202 may store ten instances of a digital credential. Nine of the instances of the digital credential are each used for three requesters, and the tenth instance is used for only two requesters. When generating a response to a request associated with a new requester, user equipment 202 may determine to use the tenth instance to generate the response to the request from the new requester.
[0037] In some examples, user equipment 202 may determine that all instances of digital credentials have been associated with a threshold number of requesters. User equipment 202 may then generate new digital credentials as described herein. In some examples, the threshold number may be one, while in others it may be two, three, four, five, six, seven, eight, nine, ten, twenty, or one hundred. In some examples, user equipment 202 may use the techniques described herein to generate new digital credentials to add to the list of available digital credentials. In some examples, user equipment 202 may generate new digital credentials and delete and / or remove existing digital credentials stored on the device.
[0038] In some examples, request 224 may include a certificate indicating a profile of the requester 222 associated with requesting device 220. The certificate may indicate what type of requester is requesting information. For example, the certificate may indicate that requester 222 is a bank, bar, airport security, etc. User device 202 may use the certificate to generate response 226 and determine which data elements from digital credentials should be included in response 226 as requested data elements 232.
[0039] In some examples, when generating response 226, user equipment 202 may determine, based on its location information, which data elements from digital credentials should be included in response 226 as requested data elements 232. For example, user equipment 202 may determine, based on its location information, that it is located at a specific bar. User equipment 202 may also determine, based on a specific location or location type, which data elements from digital credentials should be included in response 226 as requested data elements 232. For example, user equipment 202 may determine that it is at a bar and the bar requests age information. Alternatively, user equipment 202 may determine that it is located at a specific government building requesting a specific set of information.
[0040] In some examples, when generating response 226, user equipment 202 may determine, based on user 204's selection, which data elements from digital credentials should be included as requested data element 232 in response 226. For example, user equipment 202 may receive a request 224 requesting specific information (such as age). User 204 may select on user equipment 202 which data elements to include as requested data element 232 when generating response 226. For example, user 204 may select age, name, and birthday for use in generating response 226 after receiving request 224.
[0041] In some examples, when generating response 226, user equipment 202 may determine, based on the specific request information in request 224, which data elements from the digital credentials should be included as requested data elements 232 in response 226. For example, request 244 may specifically ask for age, name, and address, such that response 226 with age, name, and address can be generated as requested.
[0042] Figure 3 Example Figure 300 illustrates the digital credentials technology described herein. User equipment 302 (e.g., Figure 1 The user equipment 102) has an application system 320 and a security element (SE) 322, which constitutes the application layer and hardware for processing, computing, and managing applications and other software, as described below with respect to Figure 8. The application system 320 will process digital credentials 306 (e.g., Figure 1 Some or all of the digital credentials 306 are stored in memory and / or storage devices. As described herein, digital credentials 306 include data elements 308 (e.g., Figure 1 Data element 108) and MSO 310 (e.g., Figure 1MSO 310 includes hash 312, transaction key 314, and issuer signature 316. In some examples, portions of the digital credentials are stored and / or generated in SE 322. As described herein, user equipment 302 may store multiple digital credentials, including multiple types of digital credentials and / or multiple instances of a single type of digital credential. During the generation of digital credentials or a set of digital credentials, user equipment 302 may send and receive information with credential backend 330. Credential backend 330 may be a first-party backend, which includes a server and / or other computing device configured to assist user equipment 302 in generating digital credentials or a set of digital credentials. Credential backend 330 may communicate with issuer backend 340, which is associated with the issuer of the digital credentials or set of digital credentials. Credential backend 330 may send information to and receive information from issuer backend 340. Issuer backend 340 may include a server and / or other computing device configured to generate digital credentials.
[0043] Figure 4 An example sequence diagram 400 illustrates the digital credential technology described herein. Sequence diagram 400 illustrates the generation of digital credentials (e.g., Figure 1 Example steps in the process of generating digital credentials (106) include multiple instances of generating digital credentials. User equipment 401 (e.g., Figure 1 User equipment 102) includes application system 402 (e.g., Figure 3 Application system 320) and safety element 404 (e.g., Figure 3 Both (Security Element 322) and [other elements]. In some examples, the generation of digital credentials may be the first creation of this type of digital credential. For example, a user equipment may initiate a process for generating an mDL that the user equipment has never previously stored. In some examples, the generation of digital credentials may be based on determining that a threshold criterion has been met regarding a previous set of credentials as described herein. For example, each instance of a digital credential has been used in response to a request from a threshold number of requesting parties, as described herein. Whenever information is transferred between different systems and / or devices, the information may be encrypted.
[0044] At box 412, application system 402 of user equipment 401 may request a set of transaction keys from security element 404. Each transaction key in the set of transaction keys is used to sign a response to an information request, enabling the requester to know that the information from the digital credentials is authentic and originates from an authorized digital credential issued by the issuer for a specific device and / or user. At box 414, security element 404 may generate a set of transaction keys and sign the transaction keys to generate a signed set of transaction keys. The security element also generates a protected private key corresponding to each signed transaction key in the set of signed transaction keys. By signing the transaction keys, other devices and servers can determine that the transaction keys have been properly authorized and / or authenticated by user equipment 401. At box 416, security element 404 may transmit the signed transaction keys and protected private keys to application system 402. The protected private key may be stored by application system 402, but the protected private key is signed and encrypted by security element 404, ensuring that the protected private key cannot be used or modified by any other party or software except by security element 404.
[0045] At box 418, application system 402 may generate a provisioning request. The provisioning request may include a set of signed transaction keys (which may also be referred to as a list of transaction keys). The provisioning request may also include a device encryption key. In some examples, issuer backend 408 may use the encryption key to encrypt an instance of a digital credential, such that only user device 401 can decrypt the instance of the digital credential. In some examples, credential backend device 406 may use the encryption key to decrypt the encrypted digital credential to verify it. The device encryption key included in the provisioning request may be a public device encryption key corresponding to a private device encryption key. The private device encryption key is maintained on the device for decrypting instances of digital credentials.
[0046] At box 420, application system 402 can transmit the provisioning request to credential backend 406 (e.g., Figure 3 Credentials backend 330). As described herein, credentials backend 406 may be a backend system that assists user equipment 401 in generating digital credentials. At box 422, credentials backend 406 may verify a provisioning request. Credentials backend 406 may verify the provisioning request by verifying the signature of the transaction key set and by verifying the device encryption key. At box 424, credentials backend 406 may transmit the verified provisioning request to issuer backend 408 (e.g., Figure 3 The issuer's backend (340).
[0047] The issuer backend 408 can then process the verified provisioning request and generate multiple instances of the digital credential. The number of instances of digital credentials generated by the issuer backend 408 is in a 1:1 ratio to the number of transaction keys in the verified provisioning request. For example, if the verified provisioning request includes five transaction keys, the issuer backend 408 can generate five instances of the digital credential. As described herein, digital credentials include data elements (e.g., Figure 1 Data element 108) and MSO (e.g., Figure 1 MSO 110). Instances of digital credentials can have the same data elements but different MSOs. For example, an issuer backend 408 can generate five instances of mDL. All five instances can have the same data elements, such as name, age, address, etc. However, the five instances can have different MSOs, for example, different hashes (e.g., Figure 3 Hash 312), different transaction keys (e.g., Figure 3 The transaction key 314) and different issuer signatures (e.g., Figure 3 (Issuer's signature 316).
[0048] In some examples, a verified provisioning request may include information for data elements used in digital credentials. For instance, a verified provisioning request may include the name, age, and date of birth that will become data elements in the digital credentials. In some examples, the information for the data elements used in the digital credentials has already been transmitted to and / or received by the issuing backend (408). For example, a motor vehicle administration department may already have the information for data elements used in mDL because it acts as a record system for associated driver's licenses.
[0049] At box 426, the issuer backend 408 may generate a set of instances of digital credentials based on a verified provisioning request. After the issuer backend 408 generates the set of instances of digital credentials, it may encrypt the set of instances of digital credentials using a device encryption key.
[0050] At box 428, the issuing backend 408 may transmit a set of instances of digital credentials to the credential backend 406. In some examples, at box 430, the credential backend 406 may verify the set of instances of digital credentials after decrypting it using the device encryption key. Verification by the credential backend 406 confirms that the issuing backend 408 correctly generated the set of instances of digital credentials. Verification by the credential backend 406 also ensures that the certified / authorized issuing backend actually generated the set of instances of digital credentials, and not a malicious actor. In some examples, the credential backend 406 does not verify the set of instances of digital credentials. For example, the credential backend 406 may not have access to the device encryption key and therefore cannot decrypt the encrypted set of instances of credentials. At box 432, the credential backend 406 transmits the set of instances of digital credentials to the application system 402 of user equipment 401. Once user equipment 401 receives the instances of digital credentials, it can decrypt them using its private device encryption key. User equipment 401 may store a collection of instances of digital credentials, or a portion thereof, in application system 402 and / or security element 404 as described herein. In some examples, application system 402 may generate a symmetric payload protection key used to encrypt instances of digital credentials during storage by application system 402. When a requesting device requests information from digital credentials, the decryption aspect of the symmetric payload protection key can be used to decrypt the instances of digital credentials. Decryption of the instances of digital credentials may be completed after the user has already decrypted them via biometric identification or password authorization.
[0051] Figure 5 This is a flowchart illustrating an example process 500 for generating a response to an information request, as described herein. Process 500 is illustrated as a logic flowchart, where each operation represents a series of operations that can be implemented in hardware, computer instructions, or combinations thereof. In the context of computer instructions, an operation represents computer-executable instructions stored on one or more computer-readable storage media that perform the operation when executed by one or more processors. Generally, computer-executable instructions include routines, programs, objects, components, data structures, etc., that perform a particular function or implement a particular data type. The order in which the operations are described is not intended to be construed as limiting, and any number of the described operations can be combined in any order and / or in parallel to implement the described process. For digital credentials (e.g., Figure 1 A request for information (e.g., digital credentials 106) Figure 1 Requests 124 and 134 can be obtained from the requesting party (e.g., Figure 1 The requesting device associated with the requesting party 122, 132 (e.g., Figure 1 The request from devices 120 and 130 is transmitted to the user (e.g., Figure 1 User 104) associated user device (e.g., Figure 1 User equipment 102). The user equipment may generate a response based on digital credentials (e.g., Figure 1 Responses 126 and 136), the response may include data elements associated with the digital credentials (e.g., Figure 1 Some or all of the data elements 108. The response may also include MSOs (e.g., Figure 1 MSO 110).
[0052] The process can begin at 502. Computing devices (e.g., Figure 1 The user device 102 may receive a request from the requesting device for one or more data elements associated with digital credentials as described herein. The computing device may store digital credentials comprising a set of data elements and a security object. Data elements may be associated with a user, and may include one or more of the following: name, age, date of birth, residential address, a picture of the user, gender, hair color, eye color, height, and weight. Security objects may include an issuer's signature, a transaction key associated with the computing device, and a hash. A hash may include at least a subset of the data elements. In some examples, a hash may include other inputs, such as a random value and / or identifier associated with the data element. Security objects may include an expiration date. The computing device may store two or more types of digital credentials. The computing device may determine the type of credentials used to generate a response.
[0053] A computing device may store multiple instances of digital credentials. Each instance may include a set of identical data elements and different security objects. A requesting device may be associated with a profile. The request may include profile information about the profile. The computing device may further determine the instance of the digital credentials used to generate a response. Determining the instance of the digital credentials may include determining whether the computing device has already received a previous request associated with the profile for the data elements associated with the digital credentials. Based on the determination that the computing device has received a previous request associated with the profile for the data elements associated with the digital credentials, the computing device may determine to generate a response using the same instance of the digital credentials used to generate a previous response to the previous request. Based on the determination that the computing device has not yet received a previous request associated with the profile for the data elements associated with the digital credentials, the computing device may determine to generate a response using the least-used instance of the digital credentials.
[0054] At position 504, the computing device may determine a subset of data elements based at least in part on a request as described herein. The determination of the subset of data elements may be based on a specific data element specified in the request.
[0055] At point 506, the computing device may generate a response as described herein. The response may include a subset of data elements and a security object. The response may be generated based on digital credentials stored on the computing device. Determining the subset of data elements may be based on a certificate indicating a profile associated with the requesting device. Determining the subset of data elements may be based on location information of the computing device. Determining the subset of data elements may further be based on the selection of a user associated with the computing device.
[0056] At point 508, the computing device may send a response to the requesting device as described herein.
[0057] Figure 6 This is a flowchart illustrating an example process 600 for a set of digital credentials or digital credentials as described herein. Process 600 is illustrated as a logic flowchart, where each operation represents a series of operations that can be implemented in hardware, computer instructions, or combinations thereof. In the context of computer instructions, an operation represents computer-executable instructions stored on one or more computer-readable storage media that perform the operation when executed by one or more processors. Generally, computer-executable instructions include routines, programs, objects, components, data structures, etc., that perform a particular function or implement a particular data type. The order in which the operations are described is not intended to be construed as limiting, and any number of the described operations can be combined in any order and / or in parallel to implement the described process. User equipment (e.g., Figure 1 User equipment 102) can begin generating digital credentials (e.g., Figure 1 The process of providing digital credentials (106). The user equipment may transmit a provisioning request, including a set of signed transaction keys, to a first server (e.g., Figure 3 The credentials backend 330). The first server can verify the signed transaction key and transmit the verified provisioning request to the second server (e.g., Figure 3 (Issuer backend 340). The second server can generate a collection of instances of digital credentials and transmit it to the first server. The first server can then transmit the collection of instances of digital credentials to the user device.
[0058] The process can begin at 602. Computing devices (e.g., Figure 1 User equipment 102) can generate a set of transaction keys. The computing device can be configured to present digital credentials to the requesting device. In some examples, the computing device can sign each transaction key in the set of transaction keys. In some examples, the computing device can determine the set of credentials to be generated based on satisfying a threshold criterion regarding a previous set of credentials.
[0059] At position 604, the computing device may generate a request packet. The request packet may include a set of transaction keys. The request packet may refer to... Figure 4Related provisioning requests.
[0060] At 606, the computing device may send a request packet to a first server. The first server may be configured to verify the request packet. The first server may also be configured to transmit the request packet along with a request for a set of credentials to a second server. Each credential in the credential set may correspond to a transaction key in the transaction key set. Each credential may include a data element and a security object. The data element may be the same for each credential. The security object may be different for each credential.
[0061] At point 608, the computing device can receive a set of credentials from the first server.
[0062] At 610, the computing device may store a set of credentials. The computing device may be configured to generate a response based on a specific credential in the credential set when a requesting device requests digital credentials. The requesting device may be associated with a profile. The computing device may be configured to determine that it has already received a previous request associated with the profile for a data element associated with the digital credential. The computing device may be configured to generate a response based on the same credential in the credential set used to generate a previous response to the previous request.
[0063] Figure 7 An example architecture or environment 700 configured to implement the techniques described herein is illustrated according to at least one example. In some examples, the exemplary architecture 700 may also be configured to enable user device 706 and service provider computer 702 to share information. Service provider computer 702 is an example of credential backend 330 and issuer backend 340. User device 706 is an example of user device 102. In some examples, the device may be connected via one or more networks 708 (e.g., via Bluetooth, WiFi, Internet). In some examples, service provider computer 702 may be configured to implement at least some of the techniques described herein with reference to user device 706, and vice versa.
[0064] In some examples, network 708 may include any one or a combination of many different types of networks, such as wired networks, the Internet, wireless networks, cellular networks, satellite networks, other private networks and / or public networks, or any combination thereof. While the illustrated example represents user equipment 706 accessing service provider computer 702 via network 708, the technology can be equally applied to situations where user equipment 706 interacts with service provider computer 702 via a landline, a public phone booth, or any other means. It should also be noted that the technology can be applied to other client / server deployments (e.g., set-top boxes) as well as non-client / server deployments (e.g., locally stored applications, peer-to-peer configurations).
[0065] As described above, user equipment 706 can be any type of computing device, such as, but not limited to, mobile phones, smartphones, personal digital assistants (PDAs), laptops, desktop computers, thin client devices, tablet computers, wearable devices (such as smartwatches), etc. In some examples, user equipment 706 can communicate with service provider computer 702 via network 708 or via other network connections.
[0066] In one exemplary configuration, user equipment 706 may include at least one memory 714 and one or more processing units (or processors) 716. The processor 716 may be implemented, as appropriate, in hardware, computer-executable instructions, firmware, or a combination thereof. The specific implementation of the computer-executable instructions or firmware of the processor 716 may include computer-executable instructions or machine-executable instructions written in any suitable programming language to perform the various functions described. User equipment 706 may also include a geolocation device (e.g., a Global Positioning System (GPS) device, etc.) for providing and / or recording geolocation information associated with user equipment 706.
[0067] Memory 714 may store program instructions that can be loaded and executed on processor 716, as well as data generated during the execution of these programs. Depending on the configuration and type of user equipment 706, memory 714 may be volatile memory (such as random access memory (RAM)) and / or non-volatile memory (such as read-only memory (ROM), flash memory). User equipment 706 may also include additional removable storage devices and / or non-removable storage devices 726, including but not limited to magnetic storage devices, optical disk and / or magnetic tape storage devices. Disk drives and their associated non-transitory computer-readable media may provide non-volatile storage devices for computer-readable instructions, data structures, program modules and other data to the computing device. In some specific implementations, memory 714 may include a variety of different types of memory, such as static random access memory (SRAM), dynamic random access memory (DRAM) or ROM. Although the volatile memory described herein may be referred to as RAM, any volatile memory in which the data stored will not be retained after being removed from the host and / or power supply is appropriate.
[0068] The removable and non-removable memory 714 and the additional storage device 726 are examples of non-transitory computer-readable storage media. For example, non-transitory computer-readable storage media may include volatile or non-volatile, removable or non-removable media implemented by any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Memory 714 and additional storage device 726 are examples of non-transitory computer storage media. Additional types of computer storage media that may be present in user equipment 706 may include, but are not limited to, phase-change RAM (PRAM), SRAM, DRAM, RAM, ROM, electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, optical disc read-only memory (CD-ROM), digital video disc (DVD) or other optical storage devices, magnetic tape cassettes, magnetic tape, disk storage devices or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to user equipment 706. Any combination of the above should also be included within the scope of non-transitory computer-readable storage media. Alternatively, computer-readable communication media may include computer-readable instructions, program modules, or other data transmitted within data signals such as carrier waves or other transmission means. However, as used herein, computer-readable storage media do not include computer-readable communication media.
[0069] User equipment 706 may also include a communication connection 728 that allows user equipment 706 to communicate with a data repository, another computing device or server, user terminal and / or other devices via a network 708. User equipment 706 may also include I / O devices 730, such as a keyboard, mouse, pen, voice input device, touch screen input device, display, speaker and printer.
[0070] Turning more specifically to the contents of memory 714, memory 714 may include operating system 713 and / or one or more applications or services for implementing the features disclosed herein, such as application 711 (e.g., application system 320, health application, digital wallet, third-party application, browser application). Application 711 may perform some or all of the technologies described as described in reference processes 400, 500, 600. Similarly, at least some of the technologies described in reference service provider computer 702 may be performed by user equipment 706.
[0071] The service provider computer 702 may also be any type of computing device, such as, but not limited to, a collection of virtual or “cloud” computing resources, a remote server, a mobile phone, a smartphone, a PDA, a laptop computer, a desktop computer, a thin client device, a tablet computer, a wearable device, a server computer, or a virtual machine instance. In some examples, the service provider computer 702 may communicate with the user equipment 706 via network 708 or via other network connections.
[0072] In one exemplary configuration, the service provider computer 702 may include at least one memory 742 and one or more processing units (or processors) 744. The processor 744 may be implemented, as appropriate, in hardware, computer-executable instructions, firmware, or a combination thereof. The specific implementation of the computer-executable instructions or firmware of the processor 744 may include computer-executable instructions or machine-executable instructions written in any suitable programming language to perform the various functions described.
[0073] Memory 742 may store program instructions that can be loaded and executed on processor 744, as well as data generated during the execution of these programs. Depending on the configuration and type of service provider computer 702, memory 742 may be volatile memory (such as RAM) and / or non-volatile memory (such as ROM, flash memory). Service provider computer 702 may also include additional removable storage devices and / or non-removable storage devices 746, including but not limited to magnetic storage devices, optical disk and / or magnetic tape storage devices. Disk drives and their associated non-transitory computer-readable media may provide non-volatile storage devices for computer-readable instructions, data structures, program modules and other data for computing devices. In some specific implementations, memory 742 may include a variety of different types of memory, such as SRAM, DRAM or ROM. Although the volatile memory described herein may be referred to as RAM, any volatile memory in which the data stored will not be retained after being removed from the host and / or power supply is appropriate. Removable and non-removable memory 742 and additional storage device 746 are additional examples of non-transitory computer-readable storage media.
[0074] The service provider computer 702 may also include a communication connection 748 that allows the service provider computer 702 to communicate with a data repository, another computing device or server, user terminals and / or other devices via a network 708. The service provider computer 702 may also include I / O devices 750, such as a keyboard, mouse, pen, voice input device, touch input device, monitor, speakers and printer.
[0075] For more details, turn to the contents of memory 742, which may include operating system 752 and / or one or more applications 741 or services for implementing the features disclosed herein.
[0076] Various examples can be further implemented in a wide variety of operating environments. In some cases, the operating environment may include one or more user computers, computing devices, or processing devices that can be used to operate any of the multiple applications. User devices or client devices may include any of many general-purpose personal computers, such as desktop or laptop computers running standard operating systems, and cellular, wireless, and handheld devices running mobile software and capable of supporting multiple networking and instant messaging protocols. The system may also include multiple workstations running any of a variety of commercially available operating systems and other known applications for purposes such as development and database management. These devices may also include other electronic devices, such as virtual terminals, thin clients, gaming systems, and other devices capable of communicating via a network.
[0077] Most examples utilize at least one network familiar to those skilled in the art to support communication using any of the various commercial protocols, such as TCP / IP, OSI, FTP, UPnP, NFS, CIFS, and AppleTalk. The network can be, for example, a local area network (LAN), a wide area network (WAN), a virtual private network (VPN), the Internet, an intranet, an extranet, the public switched telephone network (PSTN), an infrared network, a wireless network, and any combination thereof.
[0078] In examples utilizing a web server, the web server can run any of a variety of server or middleware applications, including HTTP servers, FTP servers, CGI servers, data servers, Java servers, and business application servers. The server can also execute programs or scripts in response to requests from user devices, such as by executing one or more applications, which can be implemented as one or more scripts or programs written in any programming language, such as Java. ® The server may be C, C#, or C++, or any scripting language such as Perl, Python, or TCL, and combinations thereof. The server may also include a database server, including but not limited to those retrievable from Oracle. ® Microsoft ® Sybase ® and IBM ® Those obtained through commercial purchases.
[0079] The environment can include various data repositories and other storage media, as discussed above. These can reside in various locations, such as on storage media local to one or more computers or on storage media of any or all computers on a network (and / or reside within one or more computers). In a particular set of examples, information can reside in a storage area network (SAN) familiar to those skilled in the art. Similarly, any necessary files for performing functions belonging to a computer, server, or other network device may be stored locally and / or remotely as needed. Where the system includes computerized devices, each such device may include hardware elements electrically coupled via a bus, including, for example, at least one central processing unit (CPU), at least one input device (e.g., mouse, keyboard, controller, touchscreen, keypad), and at least one output device (e.g., display device, printer, speaker). Such systems may also include one or more storage devices, such as disk drives, optical storage devices, and solid-state storage devices such as RAM or ROM, as well as removable media devices, memory cards, flash memory cards, and so on.
[0080] Such devices may also include computer-readable storage medium readers, communication devices (e.g., modems, network interface cards (wireless or wired), infrared communication devices), and working memory as described above. Computer-readable storage medium readers may be connected to or configured to receive non-transitory computer-readable storage media representing remote, local, fixed, and / or removable storage devices, as well as storage media for temporarily and / or more permanently containing, storing, transmitting, and retrieving computer-readable information. Systems and various devices typically also include multiple software applications, modules, services, or other elements residing within at least one working memory device, including operating systems and applications such as client applications or browsers. It should be understood that alternative examples may have many variations described above. For example, custom hardware may also be used, and / or specific elements may be implemented in hardware, software (including portable software such as applets), or both. Furthermore, connections to other computing devices such as network input / output devices may be employed.
[0081] Non-transitory storage media and computer-readable media used for containing code or portions thereof may include any suitable media known or used in the art, including storage media such as, but not limited to, volatile and non-volatile, removable and non-removable media, which may be implemented in any method or technique for storing information such as computer-readable instructions, data structures, program modules or other data, including RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, DVD or other optical storage devices, magnetic tape cassettes, magnetic tape, disk storage devices or other magnetic storage devices, or any other media that may be used to store desired information and may be accessed by system devices. Other ways and / or methods for implementing the various examples will be understood by those skilled in the art, at least in part, based on the disclosure and teachings provided herein.
[0082] Accordingly, the specification and drawings should be regarded as illustrative rather than restrictive. However, it will be apparent that various modifications and changes may be made thereto without departing from the broader spirit and scope of this disclosure as set forth in the claims.
[0083] Other variations are within the scope of this disclosure. Therefore, although the disclosed technology is susceptible to various modifications and alternative constructions, certain illustrative examples are shown in the accompanying drawings and have been described in detail above. However, it should be understood that this disclosure is not intended to be limited to the specific forms disclosed, but rather is intended to cover all modifications, alternative constructions, and equivalents falling within the scope and spirit of this disclosure as defined by the appended claims.
[0084] In the context of describing the disclosed examples (particularly in the context of the claims below), the terms “a,” “an,” and “the,” as well as similar indicator words, shall be construed as covering both singular and plural forms, unless otherwise stated or clearly contradicted by the context. Unless otherwise indicated, the terms “comprising” and “having” shall be understood as open-ended terms (i.e., meaning “including but not limited to”). The term “connected” is construed as including, attaching, or joining together, even if there is interference. Unless otherwise stated herein, the description of numerical ranges herein is intended merely as a simple way of individually referring to each individual value falling within that range, and each individual value is incorporated into the specification as if individually referenced herein. All methods described herein can be performed in any suitable order unless otherwise stated or clearly contradicted by the context. Unless otherwise stated, the use of any and all examples or exemplary language (e.g., “such as”) provided herein is intended merely to better illustrate examples of this disclosure and does not limit the scope of this disclosure. No language in the specification should be construed as indicating that any unstated element is essential to the practice of this disclosure.
[0085] Unless otherwise specifically stated, parse languages such as the phrase “at least one of X, Y, or Z” are understood in context to be generally used to represent items, terms, etc., which can be X, Y, or Z, or any combination thereof (e.g., X, Y, and / or Z). Therefore, such parse languages are generally not intended and should not imply that some examples require that at least one of X, at least one of Y, or at least one of Z each exist.
[0086] This document describes preferred examples of the present disclosure, including the best modes known to the inventors for carrying out the present disclosure. Variations of those preferred examples will become apparent to those skilled in the art after reading the foregoing description. The inventors expect those skilled in the art to appropriately employ such variations, and the inventors intend to practice the present disclosure in ways different from those specifically described herein. Therefore, as permitted by applicable law, this disclosure includes all modifications and equivalents to the subject matter recited in the appended claims. Furthermore, unless otherwise indicated herein or clearly contradicted by the context, this disclosure encompasses any combination of all possible variations of the foregoing elements.
[0087] All references cited in this article, including publications, patent applications and patents, are incorporated herein by reference, as each reference is individually and specifically indicated to be incorporated by reference and elaborated in the entire text.
[0088] As described above, one aspect of this technology involves collecting and using data from various sources to provide a comprehensive and complete window into a user's personal health record. This disclosure anticipates that, in some cases, this collected data may include personally identifiable information (PII) data that uniquely identifies or can be used to contact or locate a specific person. Such personal information data may include demographic data, location-based data, telephone numbers, email addresses, Twitter IDs, home addresses, data or records related to a user's health or fitness level (e.g., vital sign measurements, medication information, exercise information), date of birth, health record data, or any other identifying information or personal or health information.
[0089] This disclosure recognizes that the use of such personal information data in the techniques of this invention can be used to benefit users. For example, personal information data can be used to provide enhancements to a user's personal health record. Furthermore, this disclosure also contemplates other uses of personal information data that are beneficial to users. For example, health and fitness data can be used to provide insights into a user's overall health status or can be used as positive feedback to individuals using the technology to pursue health goals.
[0090] This disclosure anticipates that entities responsible for the collection, analysis, disclosure, transmission, storage, or other use of such personal information data will comply with robust privacy policies and / or privacy measures. Specifically, such entities should implement and adhere to privacy policies and measures that are recognized as meeting or exceeding industry or governmental requirements for maintaining the privacy and security of personal information data. Such policies should be easily accessible to users and should be updated as the collection and / or use of data changes. Personal information from users should be collected for legitimate and reasonable entity purposes and should not be shared or sold outside of these legitimate purposes. Furthermore, such collection / sharing should be conducted only after receiving informed consent from users. Additionally, such entities should consider taking any necessary steps to protect and safeguard the right to access such personal information data and ensure that other entities with access to personal information data comply with the privacy policies and procedures of other entities. Furthermore, such entities may subject themselves to third-party assessments to demonstrate their compliance with widely accepted privacy policies and privacy measures. Moreover, policies and measures should be adapted to the specific types of personal information data collected and / or accessed, and to applicable laws and standards, including considerations of specific jurisdictions. For example, in the United States, the collection or acquisition of certain health data may be governed by federal and / or state laws, such as the Health Insurance Portability and Accountability Act (HIPAA); while in other countries, health data may be subject to other regulations and policies and should be handled accordingly. Therefore, different privacy practices should be maintained for different types of personal data in each country.
[0091] Regardless of the foregoing, this disclosure also contemplates implementation schemes for users to selectively block the use or access to personal information data. That is, this disclosure contemplates providing hardware and / or software components to prevent or block access to such personal information data. For example, with respect to advertising delivery services or other services related to health record management, the inventive technology can be configured to allow users to opt-in or opt-out at any time during or after service registration to participate in the collection of personal information data. In addition to providing opt-in and opt-out options, this disclosure also contemplates providing notifications related to access to or use of personal information. For example, users may be notified when downloading an application that their personal information data will be accessed, and then reminded again just before the application accesses the personal information data.
[0092] Furthermore, the intent of this disclosure is that personal information data should be managed and processed in a manner that minimizes the risk of unintentional or unauthorized access or use. Once data is no longer needed, this risk can be minimized by restricting data collection and deleting data. Additionally, and where applicable, including in certain health-related applications, data deidentification can be used to protect user privacy. Where appropriate, deidentification can be facilitated by removing specific identifiers (e.g., date of birth), controlling the amount or characteristics of stored data (e.g., collecting location data at the city level rather than the address level), controlling how data is stored (e.g., aggregating data among users), and / or other methods.
[0093] Therefore, while this disclosure broadly covers the use of personal information data to implement one or more of the various disclosed embodiments, it is also contemplated that various embodiments can be implemented without access to such personal information data. That is, various embodiments of the present invention will not become inoperable due to the absence of all or part of such personal information data.
Claims
1. A method, the method comprising: A computing device receives a request from a requesting device for one or more data elements associated with a digital credential, wherein the computing device stores multiple instances of the digital credential, wherein each instance includes the same set of data elements and different security objects, and wherein the requesting device is associated with a configuration file; Determining a first instance of the digital credential for generating the response on the computing device, wherein determining the first instance of the digital credential for generating the response includes: On the computing device, determine whether the computing device has received a previous request associated with the configuration file for a data element associated with the digital credentials; Based on the determination that the computing device has received a previous request associated with the configuration file for a data element associated with the digital credential, it is determined that the response will be generated using the same instance of the digital credential used to generate a previous response to the previous request as the first instance; and Based on the determination that the computing device has not yet received a previous request for a data element associated with the digital credential associated with the configuration file, it is determined that a second instance of the digital credential will be used as the first instance to generate the response; On the computing device, a subset of data elements from the first instance of the digital credentials is determined at least in part based on the request; The response is generated on the computing device, wherein the response includes the subset and a security object from the first instance of the digital credentials; and The computing device sends the response to the requesting device.
2. The method of claim 1, wherein the computing device stores two or more types of digital credentials, the method further comprising: The type of credentials used to generate the response is determined on the computing device.
3. The method of claim 1, wherein the request includes configuration file information about the configuration file.
4. The method of claim 1, wherein the subset of data elements is determined based on a specific data element specified in the request.
5. The method of claim 1, wherein determining the subset of data elements is based on a certificate indicating the configuration file.
6. The method of claim 1, wherein the subset of data elements is determined based on the location information of the computing device.
7. The method of claim 1, wherein the subset of data elements is determined based on the selection of a user associated with the computing device.
8. The method of claim 1, wherein the secure object comprises an issuer signature, a transaction key associated with the computing device, and a hash of at least a second subset of data elements.
9. The method of claim 1, wherein the security object includes an expiration date.
10. The method of claim 1, wherein the one or more data elements are associated with a user, and wherein the one or more data elements include one or more of the following: name, age, birthday, residential address, a picture of the user, gender, hair color, eye color, height, and weight.
11. The method of claim 1, wherein the second instance of the digital credential is a least-used instance of the digital credential.
12. A computing device, the computing device comprising: A memory configured to store computer-executable instructions; as well as One or more processors, the one or more processors communicating with the memory and configured to access the memory and execute the computer-executable instructions to: The requesting device receives a request for one or more data elements associated with a digital credential, wherein the computing device stores multiple instances of the digital credential, wherein each instance includes the same set of data elements and different security objects, and wherein the requesting device is associated with a configuration file. Determining a first instance of the digital credential for generating the response on the computing device, wherein determining the first instance of the digital credential for generating the response includes: On the computing device, determine whether the computing device has received a previous request associated with the configuration file for a data element associated with the digital credentials; Based on the determination that the computing device has received a previous request associated with the configuration file for a data element associated with the digital credential, it is determined that the response will be generated using the same instance of the digital credential used to generate a previous response to the previous request as the first instance; and Based on the determination that the computing device has not yet received a previous request for a data element associated with the digital credential associated with the configuration file, it is determined that a second instance of the digital credential will be used as the first instance to generate the response; A subset of data elements from the first instance of the digital credentials is determined, at least in part, based on the request; Generate the response, wherein the response includes the subset and a security object from the first instance of the digital credentials; and The response is sent to the requesting device.
13. The computing device of claim 12, wherein the request includes configuration file information about the configuration file.
14. The computing device of claim 12, wherein the subset of data elements is determined based on the location information of the computing device.
15. The computing device of claim 12, wherein the second instance of the digital credential is a least-used instance of the digital credential.
16. One or more non-transitory computer-readable media including computer-executable instructions, which, when executed by one or more processors, cause the one or more processors to perform operations, the operations including: A computing device receives a request from a requesting device for one or more data elements associated with a digital credential, wherein the computing device stores multiple instances of the digital credential, wherein each instance includes the same set of data elements and different security objects, and wherein the requesting device is associated with a configuration file; Determining a first instance of the digital credential for generating the response on the computing device, wherein determining the first instance of the digital credential for generating the response includes: On the computing device, determine whether the computing device has received a previous request associated with the configuration file for a data element associated with the digital credentials; Based on the determination that the computing device has received a previous request associated with the configuration file for a data element associated with the digital credential, it is determined that the response will be generated using the same instance of the digital credential used to generate a previous response to the previous request as the first instance; and Based on the determination that the computing device has not yet received a previous request for a data element associated with the digital credential associated with the configuration file, it is determined that a second instance of the digital credential will be used as the first instance to generate the response; On the computing device, a subset of data elements from the first instance of the digital credentials is determined at least in part based on the request; The response is generated on the computing device, wherein the response includes the subset and a security object from the first instance of the digital credentials; and The computing device sends the response to the requesting device.
17. One or more non-transitory computer-readable media according to claim 16, wherein the request includes configuration file information regarding the configuration file.
18. One or more non-transitory computer-readable media according to claim 16, wherein the subset of data elements is determined based on a certificate indicating the configuration file.
19. One or more non-transitory computer-readable media according to claim 16, wherein the secure object includes an issuer signature, a transaction key associated with the computing device, and a hash of at least a second subset of data elements.
20. One or more non-transitory computer-readable media according to claim 16, wherein the second instance of the digital credential is a least-used instance of the digital credential.
Citation Information
Patent Citations
Management of credentials on electronic device using online resource
CN106462847A
Method for generating network mapping certificate based on electronic identity certificate entity certificate
CN111209598A