Apparatus and computer-implemented method for verifying, proving and checking that a user is authorized to act for an entity

The integration of digital identities and credentials into KYC processes through electronic wallets and exchanges addresses inefficiencies in user authorization verification, enhancing efficiency, security, and compliance with regulatory requirements.

WO2025190646A1PCT designated stage Publication Date: 2025-09-18ROBERT BOSCH GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/054960
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-13
Filing Date
2025-02-25
Publication Date
2025-09-18

AI Technical Summary

Technical Problem

Existing KYC processes are complex and inefficient in verifying and proving user authorization to act on behalf of an entity, particularly in digital environments, lacking seamless integration of digital identities and credentials.

Method used

A computer-implemented method and device that integrates digital identities and credentials into the KYC process, enabling verification, proof, and querying of user authorization through electronic wallets and exchanges, ensuring compliance with KYC regulations by automating identity verification and periodic revalidation.

Benefits of technology

Enhances the efficiency, security, and adaptability of KYC processes by automating identity verification and periodic revalidation, ensuring seamless integration of digital identities and credentials, thereby improving compliance with regulatory requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025054960_18092025_PF_FP_ABST
    Figure EP2025054960_18092025_PF_FP_ABST
Patent Text Reader

Abstract

Apparatuses and computer-implemented methods for verifying, proving and checking that a user (102) is authorized to act for an entity (104), the method for verifying comprising verifying (124, 130) the user (102) and the entity (104), receiving (134) proof that the user (102) is authorized to act for the entity (104) from an electronic wallet (110) of the entity (104), and verifying (136) the proof that the user (102) is authorized to act for the entity (104) on the basis of an electronic wallet (112) of a relying party (106).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] title

[0003] Apparatus and computer-implemented method for verifying, proving, and querying that a user is authorized to act on behalf of an entity

[0004] State of the art

[0005] The invention relates to devices and computer-implemented methods for verifying, proving and querying that a user is authorized to act on behalf of an entity

[0006] To meet regulatory requirements, businesses must adhere to strict KYC (Know Your Customer) regulations. To meet these requirements, the integration of digital identities and digital credentials has emerged to streamline and strengthen KYC procedures for businesses.

[0007] Disclosure of the invention

[0008] The devices and computer-implemented methods according to the independent claims enable the seamless integration of digital identities and digital credentials into a KYC solution. This increases the efficiency, security, and adaptability of the KYC solution.

[0009] This solution addresses the complex KYC process for businesses, providing comprehensive support at every stage. The KYC process involves a user wishing to trade on behalf of an entity, a relying party performing the KYC procedure, and the entity. The computer-implemented process for verifying that the user is authorized to trade on behalf of the entity includes verifying the user and the entity, receiving proof that the user is authorized to trade on behalf of the entity from an electronic exchange of the entity, and verifying the proof that the user is authorized to trade on behalf of the entity against a relying party's electronic exchange. The entity's electronic exchange and the relying party's electronic exchange have the ability to verify the proof. This enables the relying party to comply with KYC regulations.

[0010] The process for verifying that the user is authorized to trade for the entity may include determining that the credential has expired, re-requesting credentials that the user is authorized to trade for the entity from the entity's electronic exchange, and verifying the credentials received in response to the re-request. If the credential has expired, the relying party may re-request the credentials from the entity's electronic exchange and verify the credentials. As part of the periodic review, the data is periodically revalidated to comply with KYC regulations.

[0011] The KYC process may involve processing a document, such as a certificate of incorporation, a partnership agreement, a business license, a legal document, or a document that includes a tax identification number. The KYC process may require verifying the document or storing a document's provenance.

[0012] The method for verifying that the user is authorized to act on behalf of the entity may include retrieving an attestation for the document from an entity's electronic wallet and verifying the attestation against the relying party's electronic wallet. The relying party's electronic wallet has the ability to verify the credential. This allows the document to be verified based on an attestation the relying party receives from an attestation provider that is a different entity than the entity for which the user is authorized to act. The provider may be a trusted issuer of the attestation, such as a government entity or a qualified trust service provider. The provider may be listed on a list of trusted providers. The list may include different providers for different documents, such as:to differentiate the levels of trust required for the KYC process.

[0013] The process for verifying that the user is authorized to act on behalf of the entity may include retrieving an authentication for the document from the entity's electronic wallet and verifying the authentication against the relying party's electronic wallet. The entity's electronic wallet and the relying party's electronic wallet have the ability to verify the authentication.

[0014] The process for verifying that the user is authorized to act on behalf of the entity may include saving the document if the verification is successful, and discarding or reporting the document if it is not. This allows for recording or monitoring by the trusting entity.

[0015] Verifying the entity may involve retrieving an entity identifier from the entity's electronic wallet and verifying the entity identifier against the relying party's electronic wallet. The entity's electronic wallet and the relying party's electronic wallet have the ability to verify the entity identifier. The entity may be a legal entity. The entity identifier may be an LPID (Legal Person Identification Data) issued by a trusted issuer, such as a government.

[0016] Verifying the user may include receiving a user identifier from the user's electronic wallet and verifying the user identifier against the relying party's electronic wallet. The user's electronic wallet and the relying party's electronic wallet have the ability to verify the user identifier. The user identifier may be a PID (Person Identification Data) issued by a trusted issuer, such as a government. A computer-implemented method for proving that the user is authorized to trade on behalf of an entity includes verifying the entity, sending proof that the user is authorized to trade on behalf of the entity from an electronic wallet of the entity to a relying party's electronic wallet.This allows an entity to prove that a user who wants to act on behalf of the entity is actually authorized to act on behalf of the entity.

[0017] The process for proving that a user is authorized to trade for an entity may involve re-providing the proof from the entity's electronic exchange. This allows the entity to reconfirm that the user is authorized to trade for the entity after a certain period of time, particularly periodically, to comply with KYC regulations.

[0018] The process for proving that a user is authorized to act on behalf of an entity may include receiving a document in the entity's electronic exchange, providing an attestation for the document to the entity's electronic exchange, and sending the attestation to the relying party's electronic exchange. This allows the entity to attestation the document.

[0019] Verifying the entity may involve sending an entity identifier from the entity's electronic wallet to the relying party's electronic wallet. This is an efficient way to authenticate the entity's identity in the KYC process.

[0020] A computer-implemented method for verifying that a user is authorized to trade for an entity includes sending a request for a service that requires the user to be authorized to trade for the entity to a relying party, and sending a user identifier for verifying the user from the user's electronic wallet to the relying party's electronic wallet. This is an exemplary way to initiate the KYC process and an efficient way to authenticate the user's identity in the KYC process.

[0021] The method for verifying that a user is authorized to act for an entity may include providing a document and requesting authentication of the document to the entity's electronic wallet. This allows the user to trigger authentication from the entity for which the user is acting.

[0022] A device for verifying that a user is authorized to act on behalf of an entity is configured to perform the method for verifying that the user is authorized to act on behalf of the entity.

[0023] A device for proving that a user is authorized to act on behalf of an entity is configured to perform the method for proving that the user is authorized to act on behalf of the entity.

[0024] A device for querying that a user is authorized to act on behalf of an entity is configured to perform the method for querying that the user is authorized to act on behalf of the entity.

[0025] A computer program may be provided, the computer program comprising instructions that, when executed by a computer, cause the computer to perform the method of verifying or the method of proving or the method of querying that the user is authorized to act on behalf of the entity.

[0026] Further embodiments are evident from the following description and the drawings. In the drawings:

[0027] Fig. 1 shows a sequence diagram of at least part of a Know Your Customer process,

[0028] Fig. 2 schematically illustrates devices for performing a Know Your Customer process. Figure 1 shows a sequence diagram of at least part of a Know Your Customer (KYC) process.

[0029] The KYC process extends to a user 102, an entity 104 and a relying party 106.

[0030] According to one example, an electronic wallet 108 is associated with user 102, an electronic wallet 110 is associated with entity 104, and an electronic wallet 112 is associated with relying party 106.

[0031] Entity 104 may be a customer of relying party 106, represented by user 102. The electronic exchanges provide a customer identification infrastructure that allows relying party 106 to verify that user 102 is authorized to trade on behalf of entity 104.

[0032] The electronic wallet 108 associated with the user 102 offers the possibility of providing personal identification, e.g., a PID (Personal Identification Data). The user identifier is issued by a trusted issuer, e.g., a government. An example of a user identifier is a PID—personal identification data issued by the government to individuals based on the elDAS 2.0 regulation. An example of the electronic wallet 108 associated with the user 102 is a personal wallet, e.g., a portion of the EU ID wallet held by the individual user.

[0033] The electronic exchange 108 associated with the user 102 may have the ability to verify the entity 104 and / or the relying party 106.

[0034] The electronic wallet 110 associated with the entity 104 may have the ability to provide the entity identifier, e.g., LPID (Legal Personal Identification Data). The entity identifier is issued by a trusted issuer, e.g., a government. An example of the entity identifier is a legal entity identifier issued to entities by a government and / or a qualified trust service provider based on the elDAS 2.0 regulation. An example of the electronic wallet 110 associated with the entity 104 is an organization's wallet, i.e., a part of the EUID wallet that the entity owns.

[0035] The electronic exchange 110 associated with the entity 104 may have the ability to verify the user 102 and / or the relying party 106.

[0036] The electronic exchange 110 associated with the entity 104 issues proof that the user 102 is authorized to trade for the entity 104.

[0037] The electronic exchange 110 linked to the entity has the ability to verify the proof.

[0038] The proof is issued by entity 104 to user 102. According to one example, the proof is linked to the user identifier, e.g., the personal identification number.

[0039] Storing the proof in the electronic wallet 110 of entity 104 ensures data protection.

[0040] In case of revocation of the authorization, the proof can be revoked, e.g. removed from the electronic wallet 110 of the entity 104.

[0041] The proof may include an attribute or attributes for the KYC process. The attribute or attributes can be defined based on the required attributes in the KYC process.

[0042] The electronic exchange 112, linked to the relying party 106, has the ability to verify the user 102, the entity 104, and the credentials. According to one example, the user 102 sends a request 114 to the relying party 106 to access a service requiring the KYC process.

[0043] Upon receiving the request 114, the relying party 106 performs a step 116. In step 116, the relying party 106 initiates the KYC process.

[0044] Then a step 118 is executed.

[0045] In step 118, the relying party 106 accesses the electronic wallet 112 associated with the relying party 106 and starts a verification process for the user 102.

[0046] The verification process for user 102 in the example includes a step 120.

[0047] In step 120, the electronic wallet 112 linked to the relying party 106 queries and receives the user ID of the user 102 from the user 102.

[0048] The user 102 may, in a step 122, access the electronic wallet 108 associated with the user 102 to provide the user identification.

[0049] The verification process for the user 102 includes a step 124.

[0050] In step 124, the electronic wallet 112 associated with the relying party 106 verifies the user 102. In the example, the electronic wallet 112 associated with the relying party 106 verifies the user identifier.

[0051] Then a step 126 is executed.

[0052] In step 126, the relying party 106 accesses the electronic wallet 112 linked to the relying party 106 and starts a verification process for the entity 104. The relying party 106 may only start the verification process for the entity 104 after successful validation of the user 102 and may not start the verification process for the entity 104 otherwise.

[0053] The verification process for entity 104 in the example includes a step 128.

[0054] In step 128, the electronic wallet 112 associated with the relying party 106 queries and receives the entity identifier from the electronic wallet 110 associated with the entity 104.

[0055] The querying and receiving of the entity identifier from the electronic wallet 110 associated with the entity 104 may be automated, i.e., may not require human interaction.

[0056] The verification process for the entity 104 includes a step 130.

[0057] In step 130, the electronic exchange 112 associated with the relying party 106 verifies the entity 104. In the example, the electronic exchange 112 associated with the relying party 106 verifies the entity identifier 106.

[0058] Then a step 132 is executed.

[0059] In step 132, the relying party 106 accesses the electronic wallet 112 associated with the relying party 106 and starts a verification process for the proof.

[0060] The relying party 106 may only start the verification process for the proof after successful validation of the entity 104 and may not start the verification process for the proof otherwise.

[0061] The verification process for the proof in the example includes a step 134. In step 134, the electronic wallet 112 associated with the relying party 106 requests and receives the proof from the electronic wallet 110 associated with the entity 104.

[0062] The retrieval and receipt of the proof from the electronic wallet 110 linked to the entity 104 may be automated, ie, may not require human interaction.

[0063] The verification process for the proof includes a step 136.

[0064] In step 136, the electronic exchange 112 associated with the relying party 106 verifies the credential. In the example, the electronic exchange 112 associated with the relying party 106 verifies that the issuer of the credential is the entity 104 and that the credential is associated with the user 102. In the example, the electronic exchange 112 associated with the relying party 106 verifies that the issuer of the credential has the entity identifier and that the credential includes the user identifier. For example, the electronic exchange 112 associated with the relying party 106 verifies that the issuer is listed in a list of trusted entities.

[0065] The infrastructure provided for customer identity verification can be further used in subsequent phases of the KYC process.

[0066] For example, the infrastructure is used for tasks related to customer due diligence, risk assessment, reporting or monitoring, periodic review or logging.

[0067] These tasks may include editing a document provided by user 102 acting on behalf of entity 104.

[0068] The KYC process may require notarization of the document. The electronic exchange 110 of entity 106 may have the ability to verify the notarization. The electronic exchange 112 of relying party 106 may have the ability to verify the notarization.

[0069] In a step 138, the user 102 may upload a document associated with the entity 104 to the electronic wallet 110 for authentication.

[0070] The electronic wallet 110 linked to the entity 104 may generate the authentication for the document in a step 140. The authentication may be a self-authentication of the entity 104. The entity 104 may be a trusted authentication provider, and the authentication may be an authentication for another entity.

[0071] In a step 142, the electronic exchange 110 associated with the entity 104 may communicate with the electronic exchange 112 associated with the relying party 106 to provide the attestation to the electronic exchange 112 of the relying party 106.

[0072] In a step 144, the electronic exchange 112 of the relying party 106 may verify the authentication.

[0073] Step 144 may include saving the document if the authentication verification is successful and otherwise discarding or reporting the document.

[0074] The KYC process may require reconfirmation of user 102's authorization to act on behalf of entity 104.

[0075] In a step 146, the electronic wallet 112 of the relying party 106 may access the electronic wallet 110 of the entity to retrieve the proof again from the electronic wallet 110 of the entity 106.

[0076] Step 146 may include determining that the credential has expired, re-requesting credentials that the user is authorized to trade for the entity from the electronic wallet 110 of the entity 104. In a step 148, the electronic wallet 112 of the relying party 106 may re-verify the credential received in response to the request against the electronic wallet 112 of the relying party 106.

[0077] Step 148 may include storing the evidence if the verification of the evidence is successful, or otherwise discarding the evidence, or reporting the evidence.

[0078] Figure 2 schematically illustrates devices for carrying out a Know Your Customer process.

[0079] A first device 202 is configured to verify that the user 102 is authorized to act on behalf of the entity 104.

[0080] The first device 202 includes at least one processor 202-1 and at least one memory 202-2. The at least one memory 202-2 of the first device 202 is configured to store instructions that, when executed by the at least one processor 202-1 of the first device 202, cause the first device 202 to at least verify the user 102 and the entity 104, receive the evidence that the user 102 is authorized to trade for the entity 104 from the electronic wallet of the entity 104, and verify the evidence against the electronic wallet 112 of the relying party 106.

[0081] The instructions stored in the at least one memory 202-2 of the first device 202 may cause the first device 202 to receive the user identifier from the electronic wallet 108 of the user 102 and to verify the user identifier against the electronic wallet 112 of the relying party 106.

[0082] The instructions stored in the at least one memory 202-2 of the first device 202 may cause the first device 202 to retrieve the entity identifier from the electronic wallet 110 of the entity 104 and to verify the entity identifier against the electronic wallet 112 of the relying party 106. The instructions stored in the at least one memory 202-2 of the first device 202 may cause the first device 202 to re-retrieve the credential from the electronic wallet 110 of the entity 104 and to re-verify the credential against the electronic wallet 112 of the relying party 106.

[0083] The instructions stored in the at least one memory 202-2 of the first device 202 may cause the first device 202 to receive a document, retrieve a certification for the document from an electronic wallet of a certification provider, and verify the certification against the electronic wallet 112 of the relying party 106.

[0084] The instructions stored in the at least one memory 202-2 of the first device 202 may cause the first device 202 to receive a document, retrieve an authentication for the document from the electronic wallet 110 of the entity 104, and verify the authentication against the electronic wallet 112 of the relying party 106.

[0085] The instructions stored in the at least one memory 202-2 of the first device 202 may cause the first device 202 to store the document upon successful verification and otherwise discard or report the document.

[0086] A second device 204 is configured to prove that the user 102 is authorized to trade for the entity 104. The second device 204 includes at least one processor 204-1 and at least one memory 204-2. The at least one memory 204-2 of the second device 204 is configured to store instructions that, when executed by the at least one processor 204-1 of the second device 204, cause the second device 204 to at least verify the entity 104, send the proof that the user 102 is authorized to trade for the entity 204 from the electronic wallet of the entity 204 to the electronic wallet 112 of the relying party 106.

[0087] The instructions stored in the at least one memory 204-2 of the second device 204 may cause the second device 204 to re-provide the evidence from the electronic wallet 110 to the entity 104.

[0088] The instructions stored in the at least one memory 204-2 of the second device 204 may cause the second device 204 to receive a document at the electronic exchange 110 of the entity 104, provide an attestation for the document at the electronic exchange 110 of the entity 104, and send the attestation to the electronic exchange 112 of the relying party 106.

[0089] The instructions stored in the at least one memory 204-2 of the second device 204 may cause the second device 204 to send the entity identifier from the electronic wallet 110 of the entity 104 to the electronic wallet 112 of the relying party 106.

[0090] A third device 206 is configured to query whether the user 102 is authorized to trade for the entity 104. The third device 206 includes at least one processor 206-1 and at least one memory 206-2. The at least one memory 206-2 of the third device 206 is configured to store instructions that, when executed by the at least one processor 206-1 of the third device 206, cause the third device 206 to at least send the request for the service requiring that the user 102 be authorized to trade for the entity 104 to the relying party 106 and to send the user identifier for verifying the user 102 from the electronic wallet 108 of the user 102 to the electronic wallet 112 of the relying party 106.

[0091] The instructions stored in the at least one memory 206-2 of the third device 206 may cause the third device 206 to provide a document and a request for authentication of the document to the electronic wallet 110 of the entity 106.

[0092] The user 102, the entity 104, the relying party 106, and the electronic wallets are designed to communicate in a communications network. For example, the user 102, the entity 104, the relying party 106, and the electronic wallets are designed to communicate using a corresponding, particularly secure, communications protocol.

[0093] The devices are designed to communicate within the communications network. The instructions include, for example, the corresponding, particularly secure, communication protocol.

Claims

Claims 1. A computer-implemented method for verifying that a user (102) is authorized to trade for an entity (104), characterized in that the method comprises verifying (124, 130) the user (102) and the entity (104), receiving (134) proof that the user (102) is authorized to trade for the entity (104) from an electronic wallet (110) of the entity (104), verifying (136) the proof that the user (102) is authorized to trade for the entity (104) using an electronic wallet (112) of a relying party (106).

2. The method according to claim 1, characterized in that the method comprises determining that the credential has expired, re-requesting (146) from the electronic wallet (110) of the entity (104) a credential that the user is authorized to trade for the entity, and verifying (148) the credential obtained in response to the query.

3. A method according to any one of the preceding claims, characterized in that the method comprises retrieving an authentication for a document from an electronic wallet of an entity and verifying the authentication against the electronic wallet of the relying party.

4. Method according to one of the preceding claims, characterized in that the method comprises retrieving (142) an authentication for a document from the electronic wallet (110) of the entity (104) and verifying (144) the authentication using the electronic wallet (112) of the relying party (106).

5. Method according to one of claims 3 or 4, characterized in that the method comprises storing the document (144) if the verification is successful and otherwise discarding or reporting the document.

6. The method according to any one of the preceding claims, characterized in that verifying (130) the entity (104) comprises retrieving an entity identifier from the electronic wallet (110) of the entity (104) and verifying the entity identifier using the electronic wallet (112) of the relying party (106).

7. Method according to one of the preceding claims, characterized in that verifying the user (102) comprises receiving a user identifier, in particular from an electronic wallet (108) of the user (102), and verifying the user identifier using the electronic wallet (112) of the relying party (106).

8. A computer-implemented method for proving that a user (102) is authorized to trade for an entity (104), characterized in that the method comprises verifying (130) the entity (104), sending (134) a proof that the user (102) is authorized to trade for the entity (104) from an electronic exchange (110) of the entity (104) to an electronic exchange (112) of a relying party (106).

9. The method according to claim 8, characterized in that the method comprises re-providing the proof from the electronic wallet (110) to the entity (104).

10. The method according to claim 8 or 9, characterized in that the method comprises receiving (138) a document in an electronic wallet (110) of the entity (104), providing (140) an authentication for the document using the electronic wallet (110) of the entity (104), and sending (142) the authentication to the electronic wallet (112) of the relying party (106).

11. Method according to one of claims 8 to 10, characterized in that verifying (130) the entity (104) comprises sending (128) an entity identifier from the electronic wallet (110) of the entity (104) to the electronic wallet (112) of the relying party (106).

12. A computer-implemented method for querying that a user (102) is authorized to act for an entity (104), characterized in that the method comprises sending (114) to a relying party (106) a request for a service requiring that the user (102) is authorized to act for the entity (104) and sending (120, 122) a user (102) identifier for verifying the user (102) from an electronic wallet (108) of the user (102) to an electronic wallet (112) of the relying party (106).

13. The method according to claim 12, characterized in that the method comprises providing (138) a document and a request for authentication of the document to an electronic wallet (110) of the entity (104).

14. Device (202) for verifying that a user (102) is authorized to act on behalf of an entity (104), characterized in that the device is designed to carry out the method according to one of claims 1 to 7.

15. Device (204) for proving that a user (102) is authorized to act for an entity (104), characterized in that the device is designed to carry out the method according to one of claims 8 to 11.

16. Device (206) for querying that a user (102) is authorized to act for an entity (104), characterized in that the device is designed to carry out the method according to one of claims 12 or 13.

17. A computer program, characterized in that the computer program comprises instructions which, when executed by a computer, cause the computer to carry out the method according to any one of claims 1 to 13.

Citation Information

Patent Citations

  • Digital credential issuing for an entity

    EP4254234A1

  • Systems and methods for distributed ledger-based identity management

    US20210256508A1