Electronic document certification method
A method for generating certification data for electronic documents using user authentication and blockchain verification addresses security and tracking challenges, ensuring data integrity and transparency.
Patent Information
- Application Number
- PCT/IB2025/055620
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-12-11
AI Technical Summary
Existing methods for generating certification data for electronic documents lack comprehensive security, efficient tracking, and robust cryptographic approaches to ensure document integrity and authenticity.
A computer-implemented method involving user authentication, blockchain-based verification, and certification data generation, including multiple authentication layers, non-relational databases, and Algorand blockchain for timestamping, ensures secure and immutable certification data.
Enhances cybersecurity, ensures data integrity, and provides transparent and reliable tracking of electronic documents through secure user authentication and blockchain-based certification.
Smart Images

Figure IB2025055620_11122025_PF_FP_ABST
Abstract
Description
[0001] METHOD OF CERTIFICATION OF ELECTRONIC DOCUMENT
[0002] TECHNICAL FIELD
[0003] This disclosure relates to computer-based systems and methods that enable the identification, tracking, and verification of the origin of electronic documents. It also relates to computer-based methods and systems for verifying the characteristics and elements of digital documents through the generation of certification data.
[0004] DESCRIPTION OF THE STATE OF THE ART
[0005] Currently, various processes incorporate the transmission of electronic information and documents, such as bank guarantees, performance bonds and trust documents used as collateral, which are issued through electronic documents.
[0006] These processes and their associated transmissions raise several concerns. For example, it is important to maintain detailed records of the actions taken with the information contained in the documents, specifying when and by whom they were carried out. Furthermore, this tracking information must be protected against unauthorized access, preserving data integrity.
[0007] Therefore, it is desirable that procedures and transfers involving electronic documents allow beneficiaries and stakeholders to obtain certification data that facilitates verification of the origin, characteristics, and relevant elements of these electronic documents. The prior art, as disclosed in US patent 11488269B2, describes a blockchain-based system for document transformation and accountability in the real estate sector. This system uses a data model to identify specific rules for a transaction and select documents for a document package. The system interacts with third parties, such as financial and regulatory institutions, to verify the transaction information and documents. The entire process is recorded on the blockchain to ensure transparency and security in the document management process.
[0008] On the other hand, document W02022002526 discloses a computer-implemented method for cryptographically linking multiple documents through a sequence of blockchain transactions. This method involves calculating signature data for documents that meet specific signature requirements, which is done in blockchain transactions associated with the documents. This signature data is then used to sign a linking transaction that cryptographically connects existing and complementary documents. The signature guarantees the integrity and relationship between the documents, and the entire process is recorded on the blockchain to ensure transparency and security in document management.
[0009] US patent 11063744B2 discloses a computer system and method for managing digital documents using blockchain. This system receives encrypted digital documents from a client computer system, records the receipt and transmission of these documents in blockchain transactions, and uses unique identifiers generated from the document content. Furthermore, the system can query the blockchain to retrieve the transaction history of an electronic document, display results to authorized users, and manage modifications to the document content.
[0010] Based on the above, the methods and systems described above do not allow for a comprehensive and efficient approach to the secure generation of certification data for electronic documents, the accurate identification and complete tracking of documents in digital workflows, or the guarantee of document integrity and authenticity through robust cryptographic approaches. Therefore, computer-based methods that enable the identification, tracking, and confirmation of the origin of electronic documents through the generation of certification data remain necessary, and alternatives are thus required. Additionally, there is room for improvement in the area of document and workflow tracking.
[0011] BRIEF DESCRIPTION
[0012] This disclosure relates to a computer-implemented method for generating certification data for an electronic document, comprising executing on a computing unit the following steps: a) authenticating a user through an identity verification process, where the identity verification process includes executing at least a first authentication and a second authentication; where the user accesses from a terminal an application that connects the terminal to the computing unit; b) receiving, from a user terminal, a status certification request associated with a file, where the file is stored in a database, and where the file includes at least one electronic document;c) transmit, to a validator server, a verification request that includes the file, a timestamp data and an identification data associated with the user and, d) receive, from the validator server, a certification data associated with the verification request, where the validator server obtains the certification data through a blockchain-based process;
[0013] In one embodiment of the method described herein, in the blockchain-based process for obtaining the certification data, the validator server obtains the certification data through a blockchain-based process that includes: validating whether a digital wallet associated with the user exists on a blockchain network; if the validation is negative, then a digital wallet associated with the user is created. This digital wallet includes a private key, a public key, and an identification number associated with the user. Using the blockchain network associated with the digital wallet, a hash is generated for the verification request data file, and the certification data is obtained from this hash. The certification data includes the hash, the electronic document status of the file, and a timestamp associated with the moment the hash was generated.
[0014] In some forms of the method described herein, the validator server and the blockchain network are connected via an API gateway, where the API can integrate endpoints that provide services such as authentication, digital signature, notifications, blockchain timestamping, and combinations thereof, as well as making the connection to a backend service.
[0015] BRIEF DESCRIPTION OF THE FIGURES
[0016] FIG. 1 illustrates a flowchart of the computer-implemented method for generating certification data (12) from an electronic document.
[0017] FIG. 2 illustrates a flowchart of a blockchain-based process (13) for obtaining the certification data (12).
[0018] FIG. 3 illustrates one architectural mode of an API gateway (17).
[0019] FIG. 4 A illustrates the first part of the schematic diagram for an example of the computer-implemented method for generating certification data (12).
[0020] FIG.4B illustrates the second part of the schematic diagram for an example of the computer-implemented method for generating certification data (12).
[0021] FIG. 4C illustrates the third part of the schematic diagram for an example of the computer-implemented method for generating certification data (12).
[0022] Figure 5 illustrates an example of a document containing a hash data (15) and a QR code that allows retrieval of certification data (12). DETAILED DESCRIPTION
[0023] Referring to FIG. 1, this disclosure relates to a computer-implemented method for generating certification data (12) of an electronic document, comprising executing on a computing unit (1) the steps of: a) authenticating a user (2) through an identity verification process, where the identity verification process includes executing at least a first authentication and a second authentication; where the user (2) accesses from a terminal (3) an application (4) that connects the terminal (3) to the computing unit (1); b) receiving, from a terminal (3) of the user (2), a status certification request (5) associated with a file (6), where the file (6) is stored in a database (7), and where the file (6) includes at least one electronic document;c) transmitting, to a validator server (9), a verification request (8) that includes the file (6), a timestamp data (10) and an identification data (11) associated with the user (2), and d) receiving, from the validator server (9), a certification data (12) associated with the verification request (8), wherein the validator server (9) obtains the certification data (12) through a blockchain-based process (13).;
[0024] The computer-based method implemented for generating certification data (12) in this disclosure offers several distinct technical advantages: User authentication, which can include multiple layers of identity verification, adds a level of security to the process. Efficient communication between the user terminal (2) and the computing unit (1) helps ensure the integrity and protection of the transmitted data, thereby improving cybersecurity across system connections. Furthermore, the integration of a blockchain-based process (13) for obtaining the certification data (12) provides additional security and verification. This results in the immutability of the certified data and traceability of the certification process, enhancing the transparency and reliability of the system as a whole. These factors make the method a secure solution for generating certification data for electronic documents.
[0025] In some variations of the method disclosed here, in step a) an authentication step may optionally be executed to strengthen the security of user (2) access to the application (4), establishing a secure connection with the computing unit (1). Thus, for example, user (2) logs in by providing their authentication credentials, which triggers the authentication process to verify their identity.
[0026] Once authenticated, access-related information can be securely stored in a database, such as a non-relational database. This facilitates the management and traceability of user interactions (2). Relevant information can then be specifically recorded, ensuring detailed tracking of access activities.
[0027] Additionally, as part of stage a), in one version of the method disclosed here, a status can be assigned to the login action, which can be classified as “request,” “approval,” or “rejection.” This status is determined by the user’s interaction (2) during the credentials entry stage, providing a clear framework for managing digital documents associated with the user (2).
[0028] Similarly, in some variations of the method described here, it is possible to assign roles to a user (2) and create categories such as "salesperson," "officer," "agent," and "company." For example, an identity and access management (LAM) system can be used. First, a user (2) is created in the LAM system, providing details such as name and credentials. Then, roles or profiles are defined, such as "salesperson," "officer," "agent," and "company," each with specific permissions, thus determining their responsibilities and privileges. For each role, access policies are configured that specify the permitted actions and resources. If necessary, access hierarchies are established.
[0029] As an optional measure in step a), you can, for example, implement a security service designed to safeguard data, accounts, and workloads against unauthorized access. Examples of additional security measures can be implemented, for instance, using protocols such as HTTPS (Hypertext Transfer Protocol Secure), supported by security solutions provided by services such as Amazon Web Services (AWS) cloud security. This layer of security acts as a shield against potential threats and helps ensure the integrity and confidentiality of sensitive information.
[0030] Amazon Web Services (AWS) cloud security implements an infrastructure to protect applications using HTTPS (Hypertext Transfer Protocol Secure). This process begins with the use of an AWS Firewall, which acts as a first line of defense, filtering and monitoring incoming and outgoing traffic.
[0031] The service connection can be established, for example, through a “Domain,” allowing centralized management of the resources associated with the web application (4). The Domain serves as an organized and secure entry point for traffic, facilitating security management and activity monitoring.
[0032] For the purposes of this disclosure, "Domain" refers to an Amazon Web Services (AWS) service called Amazon Route 53. This is a Domain Name System (DNS) and domain registry service that allows the user (2) to manage domain name resolution and configure traffic routes in the AWS cloud. This service allows you to assign domain names to AWS resources, such as web server instances or service endpoints. In addition to managing name resolution, Amazon Route 53 facilitates the configuration of DNS records, such as alias records, traffic routing records, and others, to optimize and secure the flow of traffic to the relevant resources.
[0033] In this environment, you can implement, for example, an AWS Web Application Firewall (WAF), which provides an additional layer of protection against application-specific threats. This component allows you to define and apply custom security rules, identifying and mitigating potential attacks, such as SQL injections or cross-site scripting (XSS) attempts.
[0034] Additionally, an SSL (Secure Sockets Layer) service can be integrated, for example, to encrypt communication between the user (2) and the application (4). This encryption layer ensures the confidentiality of transmitted information, preventing the unauthorized interception of sensitive data. For the purposes of this disclosure, the SSL (Secure Sockets Layer) service refers to a standard security protocol used to establish encrypted and secure connections over the internet. In another example within this description, the SSL service is the TLS (Transport Layer Security) protocol.
[0035] In a particular embodiment, the second authentication of step a) of the computer-implemented method for generating certification data (12) of the present invention includes the following sub-steps: a4) sending an authentication request (21) to an OTP (One-Time Password) generation server (20); a5) receiving from the user's (2) terminal (3) an OTP command (22) which includes a one-time code (26) generated by the OTP generation server (20) and which is sent electronically to an electronic device (27) of the user (2).
[0036] This means that it begins with the authentication request (21) sent to the OTP generation server (20), "One-Time Password" or "one-time password," and the OTP generation server (20) responds to the user (2) by providing a one-time password "OTP." This one-time code (26) is generated internally on the OTP generation server (20) and is included in an OTP command (22), which is sent electronically to the user's (2) electronic device (27).
[0037] The one-time code (26) refers to a dynamically generated, single-use security code that is used for a short period of time. Its primary purpose is to provide an additional layer of security in the authentication process, reducing the vulnerability associated with static passwords. Each time a user (2) requests authentication, a new one-time code (26) is generated, meaning that even if the code is intercepted, it will not be usable for future login attempts.
[0038] The OTP generation server (20) is a component in this process. This server has the ability to securely generate, manage, and validate one-time codes (26), also known as OTP codes. When a user (2) requests authentication, the OTP generation server (20) receives the request and generates a one-time code (26), which is then sent electronically to the user's (2) electronic device (27). The generation of one-time codes (26) is generally based on cryptographic algorithms that guarantee the randomness and unpredictability of the codes, thus strengthening the security of the process.
[0039] In another particular embodiment, the second authentication of step a) of the computer-implemented method for generating certification data (12) of the present invention includes the following substeps: a6) sending an authentication request (23) to a validator server (9), where the authentication request (23) includes the user's (2) identification data (11); a7) receiving from the validator server (9) a response data (19) with a selector value between “approved” or “rejected”, where the validator server (9) generates the value “approved” if the value of the user's (2) identification data (11) matches credentials (24) associated with a digital wallet (14) previously created by the user (2); and a8) proceeding to step b) if the value of the response data (19) is “approved”.
[0040] This means that the criterion for determining the "approved" value is based on comparing the user's (2) identification data (11) with the credentials (24) associated with a digital wallet (14) previously created by the user (2). If the user's (2) identification data (11) matches the credentials associated with the digital wallet (14) created by the user (2), the validator server (9) will issue an "approved" value, indicating that the authentication has been successful and proceeding to stage b) of the computer-implemented method for generating certification data (12) described herein. Conversely, if there is no match, a "rejected" value will be issued, indicating that the authentication has failed.
[0041] The creation of a digital wallet (14) by the user (2) is carried out, for example, in a process that involves the generation and configuration of a secure environment to store and manage information digitally.
[0042] Initially, the user (2) initiates the process by selecting the option to create a digital wallet (14) in the corresponding application (4). At this point, they are asked for identification and authentication data to establish their identity in the system.
[0043] Subsequently, the system generates and uniquely assigns a digital wallet (14) to the user (2). This digital wallet (14) acts as a secure container for storing information related to financial transactions, such as balances, histories, and associated credentials.
[0044] During the creation of the digital wallet (14), security measures such as data encryption and two-factor authentication are implemented to safeguard the integrity and confidentiality of the stored information. Furthermore, protocols are established to ensure interoperability and user accessibility (2) to their digital wallet (14) from different devices.
[0045] Once the creation process is complete, the digital wallet (14) is available for the user (2) to conduct secure transactions, access their financial history, and efficiently manage their digital assets. This technical approach to creating digital wallets contributes to providing a secure and functional experience in the digital finance sector.
[0046] Optionally, the digital wallet (14) is a custodial wallet where, for example, the user (2) entrusts the safekeeping of their private keys to a trusted service or entity, such as an exchange platform or a company specializing in the custody of digital assets. This approach provides an additional level of security and management of digital assets, especially in institutional or enterprise environments.
[0047] The concept of private key custody could be applied to other non-financial uses. A custodial wallet could, as in the case of the method disclosed here, be used to manage private keys related to user authentication in computer systems, access control to devices, or even for the secure management of sensitive information in non-financial environments.
[0048] In some embodiments and examples of the method described herein, the creation of a digital wallet (14) is achieved by associating the user (2) on a blockchain network (13). This is done by establishing a connection between the user (2) and a specific address on the blockchain. In this process, the user (2) is authenticated on the blockchain network (13) and assigned a unique digital wallet address (14). This address serves as an identifier on the network.
[0049] In step b) of the method disclosed herein, a status certification request (5) associated with a file (6) is received from a user terminal (3) of the user (2), where the file (6) is stored in a database (7), and where the file (6) includes at least one electronic document. In some embodiments of the method disclosed herein, the database (7) may be a non-relational database.
[0050] When the status certification request (5) is received, the system identifies and accesses the corresponding file (6) in the database (7). This file (6) contains at least one electronic document that requires status certification (5). From this point, one of the following stages in the verification and preparation process for status certification (5) is triggered.
[0051] For the purposes of this description, status certification (5) shall be understood as the confirmation of the origin, characteristics, and relevant elements of electronic documents. This status certification (5) becomes an official declaration that supports the authenticity and integrity of an electronic document, providing information about its origin and other key attributes, which may include, but are not limited to, the file format, creation date, and the presence of digital signatures or other distinctive attributes. It may also reference key elements within the document that are considered relevant to its purpose. This reference may include specific information, such as critical data or metadata associated with the content of the electronic document.Thus, the status certificate not only validates the authenticity and characteristics of the document, but also highlights information relevant to its specific purpose. The inclusion of these characteristics in the certificate reinforces the unique identity of the electronic document, providing an additional layer of certainty regarding its nature and origin, and enabling the traceability and authenticity of electronic documents in digital environments.
[0052] In stage c) of the method disclosed herein, a verification request (8) is transmitted to a validator server (9), which includes the file (6), a timestamp data (10) and an identification data (11) associated with the user (2).
[0053] Step c) of the method described herein begins with the transmission of a verification request (8) to a validator server (9). This request, designed to ensure the authenticity and integrity of the electronic document, incorporates several elements. First, it includes the file (6), which may be stored in the database (7), which can be a non-relational database.
[0054] Additionally, the verification request (8) incorporates a timestamp (10). This timestamp, for example, in some embodiments of the method described in this disclosure, can be obtained through a blockchain network (13) such as the Algorand blockchain, which provides an immutable record of the transaction on the blockchain. This choice of blockchain technology can enhance the security and reliability of the process by ensuring the immutability of the timestamp (10) associated with the electronic document.
[0055] Furthermore, the verification request (8) includes an identification data point (11) associated with the user (2), contributing to the traceability of the process. The identification data point (11) serves as an element to verify the authorship and / or legitimacy of the request.
[0056] For the purposes of this description, Algorand blockchain refers to any blockchain implementation based on the Algorand Consensus Algorithm protocol.
[0057] In stage d) of the method disclosed herein, a certification data (12) associated with the verification request (8) is received from the validator server (9), where the validator server (9) obtains the certification data (12) through a blockchain-based process (13).
[0058] This means that the validator server (9) transmits back a certification data (12) linked to the verification request (8). This certification data (12) is acquired by the validator server (9) through a process based on blockchain technology (13).
[0059] Referring to FIG. 2 in an embodiment of the method of the present disclosure, the blockchain-based process (13) for obtaining the certification data (12) comprises the sub-steps of: i. validating whether a digital wallet (14) exists associated with the user (2) on a blockchain network (13); ii. if the validation of the previous sub-step i is negative then create a digital wallet (14) associated with the user (2); wherein the digital wallet (14) includes a private key data, a public key data, and an identification data (11) associated with the user (2); iii. generating, with a blockchain network (13) associated with the digital wallet (14), a hash data (15) associated with the file (6) of the verification request data (8); and iv.obtain the certification data (12) from the hash data (15), where the certification data (12) includes the hash data (15), an electronic document status data of the file (6) and a timestamp data (10), associated with the time when the hash data (15) is generated, which is obtained through blockchain time stamping.
[0060] In these sub-stages, a technical process is implemented that involves generating a hash (15) associated with a file (6) that includes at least one electronic document. This hash (15) acts as a unique and cryptographically secure representation of the file's (6) content, providing a unique identifier for subsequent integrity verification.
[0061] Thus, for example, file (6) can be subjected to a hash data function (15) within a blockchain network (13) that includes at least one electronic document or verification request data (8). This hash data function (15) takes the content of file (6) as input and generates a unique hash value, which is a fixed-length alphanumeric string. This process is deterministic, meaning that the same content will always generate the same hash data (15).
[0062] The resulting hash (15) is directly associated with the file (6) and stored on the blockchain (13) as part of the corresponding transaction or record. Any modification to the file (6), however small, will generate a completely different hash (15), making it possible to detect any change in the original content of the electronic document associated with the file (6).
[0063] When a verification request (8) is made, the file (6) in question is subjected to the hash function again, generating a new hash (15). This new hash (15) is compared to the value of the hash (15) previously stored on the blockchain (13). If both values match, the integrity of the file (6) is verified, indicating that the content has not been altered since its initial recording.
[0064] Thus, the function of the hash data (15) in the blockchain network (13) provides a method for verifying the integrity of the file (6) and data associated with the digital wallet
[0065] (14), allowing reliable tracking of the validity of the information stored on the blockchain.
[0066] In sub-step iv) for obtaining the certification data (12), the technical process extends to obtaining certification data (12) from the hash data (15) associated with a file (6) that includes at least one electronic document. This certification data (12) encompasses three fundamental components. First, it incorporates the hash data (15) itself, which serves as a unique cryptographic identifier for the content of the file (6). Second, the certification data (12) includes status data for the electronic document contained in the file (6). This component provides information about the current state of the electronic document, indicating whether it has been modified or remains unchanged since its last certification. This allows for maintaining a reliable record of the electronic document's evolution over time.
[0067] Finally, the third component of the certification data (12) is a timestamp data (10). This data is associated with the specific moment when the hash data is generated.
[0068] (15) original of file (6). The timestamp (10) is obtained through blockchain time stamping, which ensures that the certification is associated with a specific and immutable moment in the blockchain timeline. In one embodiment of the computer-implemented method for generating certification data (12) of this disclosure, the timestamp data (10) is obtained through the following sub-steps: l. preparing the data to be stamped on the blockchain (13) by providing appropriate structure and format for the information to be stamped; m. generating a transaction with the data from the previous sub-step; n. entering the specific information to be immutable; o. calculating the hash data (15) of the information included in the transaction to ensure its integrity; p. signing the transaction with a private key to authenticate and secure ownership of the information; q.transmit the transaction to the blockchain network (13) for processing and validation;
[0069] Optionally, there may be additional stages to confirm the transaction by the blockchain network (13) and additional stages to verify the stamp by querying the blockchain to confirm the timestamp and data integrity.
[0070] In substage 1, the data to be stamped on the blockchain network is prepared (13). This involves structuring and formatting the information appropriately, ensuring that it meets the requirements for inclusion in the blockchain. These requirements include, for example, identifying and completing mandatory fields, verifying that the data types are appropriate and respecting the maximum allowed lengths, and validating the information, including verifying the existence of associated entities and compliance with standards. Furthermore, encoding and encryption must be applied as needed to preserve the security of the data during its transmission on the blockchain network (13).In some examples and embodiments of the method of the present disclosure, the electronic documents and files (6) may also be digitally signed by the user (2), for example, by using a custodial digital wallet (14), thereby ensuring their authenticity and readiness for the next stage of the process.
[0071] In sub-stage b, a new transaction is generated containing the data prepared in the previous stage. This transaction becomes the vehicle through which the information is made immutable on the blockchain network (13), meaning the information becomes immutable. The transaction carries the payload of data structured specifically for inclusion in the blockchain. This transaction is configured according to the requirements of the blockchain network (13), for example, an Algorand blockchain, ensuring consistency with the accepted data structure. Once created, this transaction is ready to be processed by the blockchain network (13), which will verify and validate the information before immutably incorporating it into the distributed ledger.
[0072] In sub-stage c, the specific information that is to be immutable in the newly generated transaction is introduced, for example, origin, characteristics and relevant elements of an electronic document.
[0073] Subsequently, in substep d, the hash data (15) of the information included in the transaction is calculated. In some embodiments of the method in this disclosure, the resulting hash data (15) can act as a unique digital signature of the information contained in the transaction.
[0074] Substage e involves signing the transaction, using, for example, a custodial digital wallet (14). This signature not only authenticates the transaction but also ensures ownership of the electronic document and its origin.
[0075] Finally, in sub-step f, the signed transaction is transmitted to the blockchain network (13) for processing and validation. The blockchain network (13), for example, an Algorand blockchain, will verify the authenticity of the transaction, incorporate it into the distributed ledger, and generate the timestamp (10) associated with the certification data (12) of the electronic document. In one embodiment of the computer-implemented method for generating certification data (12) in this disclosure, the computing unit (1), the validator server (9), and the blockchain network (13) are connected via an API gateway (17), and where, in step a), the first authentication comprises the sub-steps: a1) transmitting, via the API gateway (17), an authentication request (18) that includes the user's (2) identification data (11) and access credentials data associated with the user (2), and a2) routing the authentication request (18).through the API gateway (17), to a backend service configured to validate the access credentials data associated with the user (2) according to a predetermined security protocol; a3) receiving, through the API gateway (17), a response data (19) with a selector value between “approved” or “rejected” generated by the backend service; wherein the API gateway (17) is configured to restrict access of the computing unit (1) to the digital wallet (14) on the blockchain network (13), according to the predetermined security protocol.
[0076] For the purposes of this disclosure, API stands for "Application Programming Interface." The API employs a set of rules and protocols that enables interaction and communication between different software applications and services. It serves as a bridge that facilitates the application (4) communicating and sharing data with other services.
[0077] The API gateway (17) acts as an intermediary to transmit and route the authentication request (18) from the compute unit (1) to the backend service responsible for validating the access credentials associated with the user (2). The API gateway (17) provides a set of rules and endpoints that specify how the authentication requests (18) should be structured and sent, as well as the format of the expected responses, such as the selected value between “approved” or “rejected.”
[0078] For the purposes of this disclosure, an "endpoint" refers to a specific URL or point of access that can be used to perform operations or exchange information. Endpoints are access points to a service or an API (Application Programming Interface) and are used in service-oriented architectures to facilitate communication between different systems and applications, enabling secure and structured data exchange.
[0079] Each endpoint is associated with a specific functionality or operation that can be performed through the API gateway (17). For example, in an authentication service, there might be an endpoint for logging in, another for registering a new user (2), and another for logging out. Each of these endpoints represents a specific action that the authentication service can perform.
[0080] In a specific example from this disclosure, the following endpoint groups are used: user endpoints, company endpoints, endpoints for managing electronic warranty documents, endpoints for managing digital documents, endpoints for managing digital wallets, endpoints for providing analytics, endpoints for authentication, and endpoints for social media. A description of these endpoint groups follows:
[0081] User endpoints, referred to as usersRouter for the purposes of this disclosure, provide a range of functions for managing users within an application. These functions include generating and verifying one-time passwords (OTPs) for authentication, retrieving user lists based on criteria such as role or group membership, and accessing the profile of the currently authenticated user. They also allow for the creation, editing, and deletion of users, as well as the management of user sessions, such as logging in and refreshing authentication tokens. Furthermore, they offer functionality for enabling or disabling users, editing user roles, and managing notifications and signatures for specific users. All of these functions are supported by a global database, such as Mongoose.
[0082] The company endpoints, referred to as companiesRouter for the purposes of this disclosure, are grouped under the name companiesRouter. These endpoints allow users to perform various actions related to company administration. For example, they allow users to obtain a list of companies by type, add electronic documents to specific companies, and accept individual or global quota requests. They also allow users to create new companies and obtain detailed information about existing companies using unique identifiers. To improve interaction with companies, they also provide functions to search for companies based on specific roles and associated IDs. Similarly, they offer functionalities to add users to companies, enable or disable companies as needed, and edit information for existing companies.In addition to these basic actions, this group of endpoints allows for specific operations such as approving disbursements for particular companies.
[0083] The endpoints for managing electronic guarantee documents, referred to herein as guaranteesRouter, are grouped under this name. This name encompasses a variety of endpoints for managing different aspects of guarantees within a system. These endpoints enable operations such as retrieving information about specific guarantees, creating new guarantees and guarantee requests, and managing guarantee-related issues and updates. In addition to these actions, it also provides functionalities for generating guarantee reports and performing automated operations such as automatic guarantee signing.The functions associated with these endpoints include creating and updating electronic document requests and tokens, retrieving expired and active guarantees, and managing specific actions performed by operators related to guarantees. All these interactions are designed to provide efficient and comprehensive guarantee management within the system, enabling users to take the necessary actions to effectively manage and monitor the status and operation of guarantees.
[0084] The endpoints for managing electronic documents, referred to in this disclosure as documentsRouter, are grouped under the name documentsRouter. This group provides specific endpoints for managing electronic documents associated with companies. These endpoints allow for editing and deleting electronic documents. The document editing endpoint allows changes to be made to an existing electronic document within a company. The logic for this process is implemented in the corresponding controller, where the electronic document editing operations are handled. On the other hand, the electronic document deletion endpoint allows for the deletion of a specific document within a company. This is done using the electronic document ID as a parameter in the URL. The deletion logic is managed in the respective controller, where the necessary operations to securely delete the electronic document are performed.
[0085] The endpoints for managing digital wallets, referred to in this disclosure as walletsRouter, provide a series of access points for managing users' digital wallets within the system. These endpoints allow users to perform various operations related to creating, recovering, enabling, and disabling digital wallets, as well as updating associated passwords. There are endpoints for adding new wallets for specific users, where the user is identified by their ID. Additionally, there are endpoints for recovering all available wallets, both for the general user and for a specific user. These interactions are designed to facilitate the efficient management of users' digital wallets, providing access to the necessary functionalities for administration and ensuring their secure use.
[0086] The endpoints for providing analytical information, referred to in this disclosure as analyticsRouter, are a series of endpoints designed to provide analytical information about the performance and key metrics of different entities within the system. These endpoints provide an overview of analytics, as well as specific metrics for agents and operators. These endpoints provide parameterized key performance indicators (KPIs), allowing users to obtain metrics according to their needs and providing them with a view of relevant performance and metrics, enabling them to make informed decisions.
[0087] Key performance metrics for analyticsRouter can include usage rate, which indicates the frequency of requests made; response time, which measures the efficiency of delivering results; errors, which indicate problems in processing requests; user satisfaction, which reflects user opinions about quality; and resource utilization, which assesses the effectiveness of resource use. These metrics help evaluate the efficiency and quality of the service provided.
[0088] The authentication endpoints, referred to in this disclosure as indexRouter, provide several endpoints for managing user registration and access to the application. This includes the ability to register with the application, as well as options to log in using standard credentials or a one-time password (OTP). Functionality is also provided for retrieving user profiles and generating specific OTP codes.
[0089] For password management, you can allow, for example, password recovery and reset. You can also include options to enable, disable, and delete specific users.
[0090] The social media endpoints, referred to as socialRouter for the purposes of this disclosure, provide functionality for users to log in using various social media platforms. This includes options for logging in with Google, Facebook, and RUS. For example, this simplifies the login process for users by allowing them to use their account credentials on the aforementioned social media platforms. When making requests to these endpoints, the corresponding social media version must be specified as needed.
[0091] For the purposes of this disclosure, "backend service" refers to the internal processing and management of data behind the visible user interface. Backend services comprise the business logic, database management, and other operations, such as user management and document completion, including user authentication, document signing, document approval, document submission, and electronic document management, enabling the operation of the method described in this disclosure.
[0092] The backend service is responsible, among other functions and activities, for validating the access credentials associated with a user (2) during the authentication process. This service performs tasks such as verifying the user's identity (2), querying the database to compare the provided credentials with those stored, and generating responses that indicate the authentication result according to a predetermined security protocol.
[0093] In some examples and implementations of the method described herein, backend services are virtualized in containers; that is, container technology is used to run and manage these services. Containers offer advantages such as portability, as they can run in any environment compatible with the container system used (e.g., Docker). They also facilitate scalability, since containers are quick to start and stop, allowing the number of service instances to be adjusted as needed. Furthermore, they offer isolation, meaning that applications can run securely without interfering with each other.
[0094] Efficiency is another advantage, as containers share host operating system resources, resulting in more efficient resource utilization compared to virtual machines. In short, container virtualization is an effective strategy for deploying and managing backend services, providing efficiency, flexibility, and isolation.
[0095] In one embodiment of the computer-implemented method for generating certification data (12) of this disclosure in substep a2), the backend service is configured for authentication and is performed by means of the following substeps: u. logging in by the user (2) to an application (4) requesting authentication (18) of the user (2); v. redirecting the authentication request (18) of the user (2) to the server where the authentication backend service (18) is hosted; w. applying an authorization protocol to the access credentials of the user (2), if the authentication (18) is successful, proceed to the next step, otherwise no authorization is generated; x. generating an authorization code by means of the backend service hosted on a server; y. exchanging the authorization code for an access token; z. using the access token to access protected resources on behalf of the user (2).
[0096] In sub-step d, user (2), after being successfully authenticated, requests the backend service hosted on a server to generate an authorization code. This authorization code is a temporary credential that represents user (2)'s consent to access protected resources.
[0097] Next, in sub-step e, user (2) exchanges this authorization code for an access token. This exchange is performed through secure communication with the backend service. The access token is a security element that grants user (2) specific permissions and provides a window of time to access protected resources within the system. Finally, in sub-step f, user (2) uses the access token to access the protected resources on their own behalf. The token acts as an authorization credential when presented to the protected resources, allowing user (2) to perform specific actions or access restricted information based on the permissions associated with the token.
[0098] This authorization and authentication flow can be implemented in protocols such as OAuth, OpenID Connect (OIDC), SAME (Security Assertion Markup Language), JWT (JSON Web Token), Kerberos, CAS (Central Authentication Service), LDAP (Lightweight Directory Access Protocol), a combination of the above protocols, or other protocols known to a person with a moderate knowledge of the subject.
[0099] In a modality of the computer-implemented method for generating certification data (12) of this disclosure, in sub-step a2) the backend service configured to validate the access credentials data associated with the user (2) makes a digital signature by means of the sub-steps of: r. requesting a digital wallet (14) to sign transactions, through a Signer service; s. creating a digital wallet (14) through a Signer service; t. storing the digital wallet (14).
[0100] In this way, under this method described in the present disclosure, a digital wallet (14), such as a custodial wallet, can initially be requested to enable the signing of transactions using a Signer service. The Signer service is a tool or component for managing digital signature operations. Its main function is to manage the private keys associated with the digital wallet (14), such as a custodial wallet, ensuring the security of transactions. In addition to generating digital signatures and verifying transactions, the Signer service can manage private keys in an encrypted manner, ensuring their confidentiality and protection against unauthorized access. When a user (2) requests a digital wallet (14) to sign transactions, the Signer service processes this request, verifying the user's (2) identity and validating the request according to the established business rules.Subsequently, it generates a unique digital wallet (14) for the user (2), which includes the generation of public and private keys using cryptographic algorithms which are stored securely in it to protect them from unauthorized access.
[0101] To complete this process, once the digital wallet (14) has been obtained or created, it can be stored in a database, ensuring its access and availability when it is necessary to perform digital signatures.
[0102] The digital signature provides integrity, authenticity, and non-repudiation of the document. In an example of the method described in this disclosure, the digital signature comprises the following characteristics:
[0103] 1. Authenticity: identifies the author of an electronic document beyond any doubt. For this purpose, in an example of the method in this disclosure, the digital signature has the following elements of authenticity: a. Signer's Address: The format of the signer's address, which is a hexadecimal identifier, followed by 58 hexadecimal digits.
[0104] An example of Address is:
[0105] FODSTL3L7AN36I546H6LXSKSS3RA2OJDBAJMVTS6ND67MPQ4 TJVSHPQPCI. b. Signed message: This will be the hash (15) resulting from the electronic document, which could be, for example, a guarantee issued by an entity. The algorithm used to generate the hash (15) of the document will be SHA3-512. c. Version: Version of the digital signature method used, agreed upon by the parties. d. Resulting digital signature: Alphanumeric hexadecimal value resulting from the method used for digital signature. An example of a digital signature is: KUCGVQYAGZVUYBHMMUIEVV2FAIJL77PXBOWNEEPBFJ6W5 CGJHLMQ
[0106] 2. Integrity: This indicates that the message has not been altered or modified after being communicated. For example, the message to be digitally signed will always be the SHA3-512 hash (15) of the electronic document, which could be, for example, a guarantee from an entity. In the event that the electronic document is modified, the resulting hash (15) of the modified electronic document will always be different from the hash (15) of the original electronic document. Furthermore, the hash (15) of the modified electronic document will not correspond to the resulting digital signature, nor to the signing address, since that address never issued the digital signature with said electronic document.
[0107] 3. Non-repudiation: The digital signature whose use is recognized in the electronic document guarantees that the parties, for example, to an agreement, contract, or smart contract, cannot reject the electronic document with digital signatures issued in accordance with the stipulations of the electronic document. Therefore, the parties recognize as authentic and complete the digital signature validated by a blockchain network (13).
[0108] 4 Complementary security: In addition to the digital signature, the security associated with the electronic document with a digital signature is guaranteed.
[0109] In an implementation of the computer-based method for generating certification data (12) described in this disclosure, following step a3), a sub-step a10) is performed to connect the computing unit (1), via a Dashboard in an application (4), to the API connection gateway (17), which manages authentication using an authorization protocol and allows access to the digital wallet (14). For the purposes of this disclosure, the API connection gateway (17) is part of the set of rules and endpoints that enable communication between the computing unit (1) and the backend service. This API gateway (17) facilitates the connection, allowing authentication to be managed through an authorization protocol and access to the digital wallet (14).
[0110] In an example of the method in this disclosure, the creation of the digital wallet (14) is done by means of the API gateway (17) which executes the following steps:
[0111] A. Requesting the creation of the digital wallet (14) via email: In this first step, the user (2) is asked to provide their email address. Then, a blockchain network connection service (13), such as the Algorand Connector blockchain service, is used, and together with a state machine, a digital wallet (14) is created on the blockchain network (13), for example, on an Algorand blockchain network (13).
[0112] B. Create an email address when generating a user (2): When a user is created (2), an email address will be automatically generated for that user (2) or the email address provided in step A will be taken and linked to the user's credentials (2).
[0113] C. Request the creation of a user generation contract (2): The platform uses the API gateway (17) and an authentication service to request a contract, for example, a smart contract, that generates a user (2) on the validator server (9). The smart contract is responsible for creating a user record (2) on the validator server (9) with the relevant information of the user (2).
[0114] D. Store the user (2) and password association in a database: User information (2), which includes the email address and digital wallet credentials (14), is securely stored in a database.
[0115] The blockchain network connection service (13) is a tool that facilitates connection and interoperability between the API gateway (17) and the blockchain network (13). In one particular example, the Algorand blockchain service "Algorand Connector" is a tool or interface that helps the user (2) connect to the Algorand blockchain network. This could include, among other functions, transaction management, interaction with smart contracts on the Algorand blockchain network, or obtaining specific blockchain information.
[0116] For the purposes of this disclosure, a state machine is a description of how a system behaves in different states and how it moves between them, which is beneficial for several reasons. First, the digital wallet (14) goes through different states during its operation, such as "offline," "waiting for confirmation," or "transaction completed," among others. The state machine organizes and manages these states in a structured way.
[0117] Furthermore, the state machine provides clear control over the transitions between the different states of the digital wallet (14), ensuring that it follows a logical and secure flow in response to user actions (2) or other events. Each event, such as a transaction request or an update, can trigger a state transition, and the state machine facilitates the orderly handling of these events.
[0118] The state machine also contributes to the security and validation of the digital wallet (14). By having clearly defined states, specific validations and security controls can be implemented for each state. For example, certain validations can be applied only when the digital wallet (14) is in the state of performing a transaction.
[0119] Optionally, the state machine can provide a visual and logical representation of the digital wallet's behavior (14), facilitating code comprehension and the development of new features or troubleshooting. In terms of maintenance and scalability, the state machine can simplify the orderly incorporation of new features or updates without disrupting the overall system structure.
[0120] For the purposes of this disclosure, a smart contract is a sequence of steps executed in a computer program. It is a set of rules and conditions programmed in code that are automatically executed when certain predefined conditions are met. These rules and conditions are executed on a blockchain network (13) and have the ability to automate, verify, or enforce the execution of agreements or contracts autonomously. One of the characteristics of a smart contract is its self-execution capability: when the conditions programmed into the contract are met, it executes automatically without human intervention, eliminating the need for intermediaries. Other characteristics include the immutability of smart contracts, which, once deployed on the blockchain, cannot be modified or deleted.This feature provides security and confidence in the integrity of the contract. Transparency is another key aspect, as all contract details, including terms and executions, are visible on the blockchain network (13), enhancing visibility and trust in the process.
[0121] Creating and managing the digital wallet (14) through the API gateway (17) provides enhanced security for the digital wallet (14). In this respect, the API gateway (17) can function as a single point of entry, centralizing access to the services. This approach reduces exposure by sharing only the API gateway (17) publicly, improving access security and keeping internal implementation details hidden.
[0122] The API gateway (17) can be configured with specific policies to ensure that only authenticated and authorized users (2) can access the services. This strengthens access security and provides better control over who can interact with the digital wallet (14).
[0123] Next, the API gateway (17) also serves to route the request to the appropriate service. This step ensures that each request is directed to the specific service required, preventing unauthorized access and improving data security by channeling it to the correct logic.
[0124] On the other hand, the backend service can, for example, securely process the request, applying security measures and complying with established authorization policies. This helps ensure that data is managed appropriately, contributing to improved security of digital wallet information (14).
[0125] Finally, the API gateway (17) is responsible for returning the response to the user (2), ensuring that only authorized and secure results are shared. For example, the API gateway (17) can communicate with an object storage system through a web service interface such as Amazon S3, Google Cloud Storage, and Azure Blob Storage.
[0126] In an embodiment of the computer-implemented method for generating certification data (12) of this disclosure, subsequent to substep a2), a substep a9) of workload balancing is performed by means of the following substeps: f. receiving access requests by means of the IP address of a load balancer (25); g. distributing the access requests among instances of the target group; h. selecting the instance of the target group that is available; i. verifying that each instance of the target group is operational and capable of handling the traffic; j. redirecting access request response; k.records information about requests and resource performance; For the understanding of this disclosure, a load balancer (25) is a component that distributes user requests evenly among multiple servers or resources, with the aim of optimizing performance, improving availability, and avoiding overloading a server.
[0127] In one embodiment of the method described herein, a load balancer (25) is employed in the process of routing the authentication request (18) to efficiently manage the distribution of the authentication requests (18) among multiple instances of the service. The load balancer (25) operates as an intermediary, receiving the access requests through the IP address associated with the load balancer (25).
[0128] The primary function of the load balancer (25) is to distribute access requests evenly among the different instances in the target group. Using load balancing algorithms, it selects the instance in the target group that is available and capable of handling the traffic at that moment. These algorithms can include, for example, Round Robin, which distributes requests sequentially in order of arrival; Least Connections, which sends new requests to instances with fewer active requests; IP Hashing, which assigns requests to instances based on the client's IP address; or Weighted Round Robin, which assigns weights to each instance, with higher-capacity instances receiving more requests. This approach allows for a uniform distribution of the workload, improving system efficiency and performance.
[0129] The load balancer (25) performs continuous checks to ensure that each instance in the target group is operational and capable of handling incoming traffic. If an instance experiences problems or becomes unavailable, the load balancer (25) redirects the request to an alternative instance, thus contributing to system availability and reliability. In addition to its primary load balancing function, the load balancer (25) can also log information about authentication requests (18) and resource performance. This logged information provides valuable data for continuous system monitoring and optimization, allowing adjustments based on traffic demands and ensuring efficient performance in handling access requests.
[0130] In one example, the infrastructure for the method described in this disclosure is AWS, meaning that a cloud services platform provided by Amazon Web Services (AWS) is used, and the load balancer (25) is the Elastic Load Balancing (ELB) service, more specifically, the Application Load Balancing (ALB). These ALBs are associated with the cluster's Ingress, depending, of course, on the service and namespace. Each one has its own dedicated rule or load balancer to receive requests from the instances. Likewise, within each service or pod, a specific Horizontal Pod Autoscaler (HPA) is configured for each service. This allows the pods to scale horizontally and distribute the workload appropriately when traffic increases. The load balancer (25) can perform, for example, the following functions:
[0131] E. Receiving requests: The load balancer (25) receives requests from users (2) who want to access a service. These requests arrive at the load balancer's (25) entry point, which is the load balancer's (25) public URL or IP address.
[0132] F. Distribute evenly: The load balancer (25) automatically distributes incoming requests among the resources or instances in the pre-configured target group. This is done equitably to prevent one instance from becoming overloaded while others are available. G. Select the target resource: The load balancer (25) selects the most available and fastest-responding resource in the target group at that moment. It uses load balancing algorithms (e.g., Round Robin or Least Connections) to make this decision.
[0133] H. Continuously verify status: The load balancer (25) constantly checks the functionality of the target group's resources. If an instance fails the functionality check, the load balancer stops sending traffic to that instance until it becomes available again.
[0134] I. Redirecting responses: Once the target group resource handles the request, the load balancer (25) redirects the response to the user (2) who made the initial request. This occurs transparently to the user (2), who perceives that they are interacting directly with the load balancer (25).
[0135] J. Logging and monitoring: The load balancer (25) logs information about requests and resource performance. It also allows real-time monitoring to evaluate system performance.
[0136] K. Elasticity and scalability: The load balancer (25) automatically adjusts to changes in workload and resource capacity. If necessary, instances can be added to or removed from the target group to meet demand.
[0137] For the purposes of this disclosure, when it is stated that the load balancer (25) continuously verifies the operation of the target pool's resources, it means that the load balancer (25) ensures that each instance or server can reliably handle traffic. This process involves periodic checks, known as "health checks," which consist of regular requests sent to each instance to verify its operational status. The frequency of these checks is set at regular intervals, such as seconds or minutes, depending on the configuration.
[0138] If an instance successfully passes the functional check, the load balancer (25) considers it operational and ready to receive traffic. In the event of an incorrect response or a non-functional state, the instance is marked as "unhealthy," and the load balancer (25) may stop sending traffic to that instance, redirecting requests to healthy instances.
[0139] Furthermore, the load balancer (25) can, for example, perform automatic recovery. If an instance initially marked as “unhealthy” returns to a “healthy” state, the load balancer (25) reintegrates it into the traffic distribution. This constant monitoring ensures that traffic is directed to operational instances, improving the system's reliability and resilience.
[0140] Referring to FIG. 3 in one modality of the method disclosed here, the architecture of the API gateway (17) is given by:
[0141] The computing unit (1), through an application Dashboard (4), connects to the API gateway (17), also called the Rest API Gateway, which contains all the business logic and is integrated into a cloud services infrastructure such as Koibanx Cloud, which in turn can be complemented by Google Cloud Storage (GCS).
[0142] In this mode, the API gateway (17) communicates with a cloud object storage service (35), such as an S3 (Simple Storage Service), which is a cloud object storage service provided by Amazon Web Services (AWS) that can be used to store and retrieve data from anywhere on the web. The API gateway (17) communicates via an AWS library with the core modules, which consist of the following services: A. Auth (32) (Authentication): a service responsible for managing user registration (2), user credential authentication (2), and the assignment of roles and permissions to control access.
[0143] B. Notifications (33): A service that notifies users about relevant events on the platform. It communicates with external services such as messaging systems (31), such as Twilio, via HTTPS to send notifications.
[0144] C. Signer (28) (Signer): A service used to create digital wallets and allow them to sign transactions with a unique identifier. It is responsible for generating and managing keys to securely sign transactions.
[0145] D. Algorand Stamper (29) (Algorand Stamper): a service that stamps data onto the Algorand blockchain network (13). It prepares, creates, and sends transactions to the Algorand network for inclusion on the blockchain network (13).
[0146] E. Algorand Connector (30): is a service that helps the user (2) connect to the Algorand blockchain network (13). This could include, among other functions, transaction management, interaction with smart contracts on the Algorand blockchain network (13), or obtaining specific information from the blockchain (13).
[0147] Any of the above services can be connected to a database (7) which can be a non-relational database, such as MongoDB.
[0148] For the purposes of this disclosure, it should be understood that “services” refers to software components, or specific methods that perform specialized functions essential to the operation of the API gateway (17). Each of these services has a specific task and contributes to the overall functionality of the system.
[0149] In one example the Auth (32) (Authentication) service performs the following steps: F. User registration: when a new user (2) registers on the platform, the Auth (32) (Authentication) service collects and stores the user's (2) information, including access credentials.
[0150] G. Authentication: The Auth (32) (Authentication) service verifies the user's access credentials (2) during the login process to ensure that only authorized users have access to the platform.
[0151] H. Role and permission management: Auth (32) (Authentication) manages the assignment of roles and permissions to users (2) according to their needs and access levels on the platform.
[0152] In one example, the Algorand Stamper (29) performs a service of chronological stamping on a blockchain network (13), for example an Algorand blockchain network, of the states of the electronic document, which is done through the sub-stages of:
[0153] A. Data preparation: The Algorand Stamper service (29) begins by preparing the data to be stamped onto the blockchain network (13). This may include the appropriate structure and format of the information to be stamped.
[0154] Bl. Transaction creation: Based on the prepared data, the service creates an Algorand Stamper transaction (29) containing the relevant information to be stamped on the Algorand Stamper blockchain network (13) (29).
[0155] Cl. Transaction Submission: The prepared transaction is sent to the Algorand Stamper (29) stamping node for processing. This involves sending the transaction to the Algorand Stamper (29) network for inclusion in the Algorand Stamper (29) blockchain.
[0156] DI. Stamping on the Blockchain: The Algorand Stamper stamping node (29) processes the transaction and includes it on the Algorand Stamper blockchain network (29). The transaction is confirmed and becomes part of the immutable ledger of the blockchain network (13). In one example, the Notifications service (33) performs the following steps:
[0157] A2. Event notification: When a relevant event occurs on the platform (e.g., a successful transaction), the Notifications service (33) collects the event details.
[0158] B2. Connection to messaging system (31) (e.g., Twilio): The Notifications service uses a secure connection, e.g., via HTTPS, to send notifications via the messaging system (31).
[0159] C2. Notification Delivery: Notifications are efficiently delivered to the appropriate recipient, whether a user or an external system, to inform about the event that occurred.
[0160] Referring to Figure 5, in a specific example, an electronic document contained in a file (6) and bearing a hash (15) obtained through a blockchain-based process (13) as described in this disclosure can be printed as a PDF or a physically printed document. A visual code (34) is added to this document for identification and data capture, using visual patterns to represent information. Examples of visual codes (34) include barcodes and two-dimensional codes, encompassing traditional barcodes such as linear barcodes, as well as two-dimensional codes such as QR codes, data matrix codes (such as PDF417 and DataMatrix barcodes), and others.
[0161] The visual code (34) allows the consultation of the certification data (12) of the electronic document obtained in stage d) of the computer-based method implemented in this disclosure. In one particular example, the visual code (34) is a QR code.
[0162] For the purposes of this disclosure, a QR (Quick Response) code is a code consisting of an array of dots (squares) arranged in a square pattern. It can store various types of data such as text, numbers, web addresses, contact information, or even instructions to perform a specific action, for example, on a computer unit (1) or an electronic device (27).
[0163] Furthermore, this disclosure also relates to a system configured to execute one or more of the modalities, realizations, and examples of the method described in this disclosure above.
[0164] The system may include a computing unit (1) configured to authenticate a user (2) through an identity verification process, where the identity verification process includes performing at least a first authentication and a second authentication. The computing unit (1) connects to the terminal (3), from which the user (2) accesses an application (4) that connects the terminal (3) to the computing unit (1). Additionally, the system may include a validator server (9), which connects to the computing unit (1), for example, via the communications network.
[0165] The system may include a process for creating and encrypting a digital wallet (14) on a blockchain network (13) configured to execute any of the methods described in this disclosure.
[0166] In any of the system modalities that include a computing unit (1), the validator server (9) can be selected from a virtual machine, a server, a computer, a server farm, and combinations of these.
[0167] Optionally, the databases or data storage modules (7) can be part of a service architecture based on "bucket" type applications or cloud data storage web services (e.g., Amazon S3, Firebase, among others) with which the API gateway services (17) can communicate in a service-based communications protocol.
[0168] Furthermore, this disclosure also describes a computer program and a readable medium comprising instructions, which, when executed in a system program (according to any of the system modalities described above), cause that system to carry out the steps of a method, according to any of the methods described above in this disclosure.
[0169] The computer-readable medium can be selected from executable files, installer files, compact discs, RAM (cache memory, SRAM, DRAM, DDR), ROM (Flash, Cache, hard drives, SSD, EPROM, EEPROM, removable ROM (e.g. SD (miniSD, microSD, etc.), MMC (MultiMedia Card), Compact Flash, SMC (Smart Media Card), SDC (Secure Digital Card), MS (Memory Stick), among others)), CD-ROM, digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tapes, storage or any other medium that can be used to store information and that can be accessed by a processing unit.
[0170] The computer-readable medium can be a set of computer-readable elements in which instructions are divided or broken down that, when executed by a computing unit (1), validator server (9) and other hardware elements of any of the previously described modalities of the system, allow the steps, stages, and sub-stages of a method to be carried out in accordance with any of the modalities of the methods previously described in this disclosure.
[0171] Example
[0172] Referring to Figures 4A, 4B, and 4C, in one example, the terminal (3) connects to the electronic device (27), from which the user (2) accesses it. Furthermore, the user terminal (3) is connected to the computing unit (1), through which access is gained from an application (4). In turn, the user terminal (3) is also connected to the validator server (9), which allows access to the application (4).
[0173] The validator server (9) is connected to both the terminal (3) and the database (7) and to an OTP (One-Time Password) generation server (20). The database (7) is connected to the terminal (3), the validator server (9), and a system for creating and encrypting a digital wallet (14) on a blockchain network (13). The database (7) records a timestamp (10), the user's (2) identification data (11), and a file (6) containing at least one electronic document.
[0174] The compute unit (1) and the validator server (9) are connected to the OTP (One-Time Password) generation server (20). The OTP generation server (20) is connected to the load balancer (25). The load balancer (25) can optionally be connected to a VPN, for example, Amazon Virtual Private Cloud (AVP), in an Amazon EKS cluster, henceforth referred to as the EKS VPC, which is connected to the blockchain network (13) via the API gateway (17). The API gateway (17) is optionally connected to both the EKS VPC and the blockchain network (13), the latter of which is in turn connected to the database (7).
[0175] The API gateway (17) is connected to the validator server (9), for example, via the EKS VPC serial connection, and to the load balancer (25) and the one-time password (OTP) generation server (20). Since the validator server (9) is connected to both the user terminal (3) (2) and the API gateway (17), this enables a connection between the user terminal (3) (2) and the API gateway (17) using the validator server (9) as a bridge. This connection allows the user terminal (3) (2) to consume the Auth (32), Notifications (33), Signer (28), Algorand Stamper (29), and Algorand Connector (30) services.
[0176] In one example, the connection between hardware elements, such as the user terminal (3), the electronic device (27), the computing unit (1), the application (4), the validator server (9), the database (7), an OTP (One-Time Password) generation server (20), a system for creating and encrypting a digital wallet (14), a blockchain network (13), a load balancer (25), and optionally an EKS VPC, can be established over a standard communications network using protocols such as HTTP, HTTPS, TCP / IP, or other compatible protocols. The connection can be direct, via a local or private network, or over the internet, using routers and switches to securely and efficiently direct traffic. The architecture is distributed, with different components deployed on separate servers that communicate with each other over the internet.It is based on principles of scalability, availability and security, using technologies such as load balancers to distribute traffic, firewalls for internet network security and cloud storage services to store data.
[0177] Referring to Figures 4A, 4B, and 4C in an example of the computer-implemented method for generating certification data (12) in this disclosure, the method flow begins when a user (2) accesses an application (4) from a terminal (3) that connects the terminal (3) to the computing unit (1), and step a) of authenticating a user (2) is performed through an identity verification process, where the identity verification process includes executing at least one first authentication and one second authentication. Subsequently, in step b) of the method in this disclosure, a status certification request (5) associated with a file (6) is received from a terminal (3) of the user (2), where the file (6) is stored in a database (7), and the file (6) includes at least one electronic document.Next, stage c) is executed, which involves transmitting a verification request (8) to a validator server (9). This request includes the file (6), a timestamp (10), and an identification (11) associated with the user (2). Then, stage d) is executed, which consists of receiving a certification (12) associated with the verification request (8) from the validator server (9). The validator server (9) obtains the certification (12) through a blockchain-based process (13).
[0178] Referring to FIG. 4A, FIG. 4B and FIG. 4C, the example performs the following sub-steps: i) validating if there is a digital wallet (14) associated with the user (2) on a blockchain network (13); ii) creating a digital wallet (14) associated with the user (2) when the validation is negative; where the digital wallet (14) includes a private key data, a public key data, and an identification data (11) associated with the user (2); iv) generating, with the blockchain network (13) associated with the digital wallet (14), a hash data (15) associated with the file (6) of the verification request data (8), and obtaining the certification data (12) from the hash data (15). The certification data (12) includes the hash data (15), an electronic document status data (6), and a timestamp data (10), associated with the moment the hash data (15) is generated, which is obtained by time stamping on the blockchain network (13). Referring to FIG. 4 A, FIG.In Figures 4B and 4C, the example case shows that the connection between the computing unit (1), the validator server (9), and the blockchain network (13) is established through an API gateway (17). In the initial stage (a), the authentication process comprises the following substages: a) transmitting an authentication request (18), which includes the user's (2) identification data (11) and the access credentials information associated with the user (2), via the API gateway (17); a2) forwarding the authentication request (18) to a backend service configured to validate the access credentials information associated with the user (2) according to a predefined security protocol; a3) receiving, via the API gateway (17), a response data (19) generated by the backend service, with a value indicating whether the authentication was "approved" or "rejected."It is important to note that the API gateway (17) is configured to restrict access of the computing unit (1) to the digital wallet (14) on the blockchain network (13) in accordance with the predefined security protocol.
[0179] Referring to Figures 4A, 4B, and 4C in the example, during step a), the second authentication is broken down into the following substeps: a4) sending an authentication request (18) to the OTP generation server (20); a5) receiving, from the user's (2) terminal (3), an OTP command (22) containing a one-time code (26) generated by the OTP generation server (20) and sent electronically to an electronic device (27) of the user (2). Additionally, during step a), the second authentication comprises the substeps of: a6) sending an authentication request (18) to the validator server (9), where the authentication request (18) includes the user's (2) identification data (11); a7) receiving a response data (19) from the validator server (9) with a value indicating "approved" or "rejected."The validator server (9) generates the value “approved” if the user's (2) identification data (11) matches the credentials (24) associated with a digital wallet (14) previously created by the user (2); a8) proceed to stage b) if the value of the response data (19) is “approved”. In the context of FIG. 4A, FIG. 4B and FIG. 4C, in stage a2), a substage a9) is executed to balance the workload using a load balancer (25).
[0180] GLOSSARY:
[0181] API Gateway: An API (Application Programming Interface) gateway is a component that acts as an intermediary between different applications or services, enabling communication and data transfer between them. The API gateway facilitates interoperability between heterogeneous systems by providing a set of rules and protocols for communication. It can be located between the user (2) and a set of backend services. It functions as a reverse proxy that accepts all calls to the application's programming interface (4), adds the necessary services to fulfill the requests, and returns the appropriate result.The API gateway intercepts incoming requests and handles several necessary functions. For example, the API gateway can perform functions such as directing user requests (2) to the corresponding microservices, managing versions and access, transforming the flow of communications, facilitating logging, monitoring firewalls, managing authentication and authorization, combining service calls, and enabling scalability by distributing network traffic evenly.
[0182] Endpoints: Defined as a specific access point in an API or web service. It is a unique URL that represents an operation or resource within the API. Endpoints are used to perform various actions, such as reading, writing, modifying, or deleting data. Endpoints are associated, for example, with HTTP methods such as GET, POST, PUT, and DELETE, among others, which define what type of action will be performed on the resource. The structure of an endpoint generally follows a URL pattern that includes the base address of the service, followed by a specific path that identifies the resource, and, in some cases, additional parameters that can be used to filter or modify the response. Electronic document: A document in digital format that can store information electronically. It can be contained in files such as text, images, videos, or any type of content that can be represented digitally.
[0183] Blockchain or blockchain network (13): A blockchain is a distributed and decentralized data structure that securely and transparently records transactions. Each block contains a set of transactions and is linked to the previous block, forming an immutable chain.
[0184] Immutable information: This refers to data recorded on a blockchain that, once recorded, cannot be modified or deleted. In the context of a blockchain network, immutability ensures that historical records of transactions, smart contracts, electronic documents and their proof of origin, characteristics, and relevant elements, as well as other types of data, remain intact and reliable over time.
[0185] Validator server (9): This is a server that verifies the authenticity and validity of information or transactions. In the context of the blockchain network (13), the validator server (9) can participate in the consensus process to confirm transactions and add new blocks to the chain.
[0186] Application (4): A computer program designed to perform specific tasks on an electronic device. Applications, or apps, can range from simple tools to complex programs with multiple functions. Application (4) has the following functions: user creation, role approval according to business rules, request for electronic document generation, approval and signing of electronic documents, generation of the electronic document, sending the electronic document to the recipient, and reading and verifying electronic documents, for example, using QR codes, associated signatures, and timestamps. Twilio: A cloud-based communication service using APIs that allows developers to easily integrate features such as text, voice, and video messaging into applications and websites.
[0187] User-associated access credentials: Information used to authenticate and verify a user's identity when accessing online systems or services. Access credentials typically include a username and password, although they may involve other methods such as biometrics or security keys.
[0188] Services: This refers to a self-contained, specialized software component that provides specific functionality or a functional unit within the solution. These software components are designed to be independent and modular, meaning they can be deployed, updated, and scaled independently without affecting other services or the overall architecture.
[0189] Each service exposes a clearly defined interface, usually through an API gateway (17), that specifies how other components can interact with it. This interface defines the types of data that the service accepts and returns, as well as the operations it can perform.
[0190] In the context of this disclosure, the services perform tasks such as user authentication, identity verification, document certification, and data management. They are designed to be scalable, meaning they can handle varying workloads and automatically recover from failures without disrupting overall operation.
[0191] Thus, a service is an independent component that offers specific functionality through a well-defined interface (by means of an API gateway (17)), allowing interaction with other components of the solution in a scalable manner and without coupling difficulties.Computing unit (1), processing unit, or processing module: These are devices that process data, for example, microcontrollers, microprocessors, DSCs (Digital Signal Controllers), FPGAs (Field Programmable Gate Arrays), CPLDs (Complex Programmable Logic Devices), ASICs (Application Specific Integrated Circuits), SoCs (System on Chip), PsoCs (Programmable System on Chip), computers, servers, tablets, cell phones, signal generators, and computing units, processing units, or processing modules known to a person moderately versed in the subject, and combinations thereof.
[0192] Data: It is a symbolic representation that can be numerical, alphabetical, algorithmic, logical, and / or vector that encodes information.
[0193] Data can have a structure or frame composed of blocks of characters or bytes that represent different types of information. Each block consists of character strings, numbers, logical symbols, and other elements.
[0194] Data can also consist solely of bits (strings in binary code), be composed of characters formed one by one by a combination of bits, be formed from fields, records, or tables composed of fields and records, or be formed from data exchange files (formats such as CSV, JSON, XLS, among others). Furthermore, data can be an array of "n" rows by "m" columns. In turn, a single piece of data can contain multiple pieces of data.
[0195] For example, when data has a frame structure, the frame may contain an identification character block, generally known as the header, which contains information related to the computer or processor sending the data, and may also contain information related to the computer or processor receiving the data. Preferably, if the data is in frame format, the frame contains blocks related to layers according to, for example, the OSI reference model. Likewise, the frame may have a tail character block (or simply tail), which identifies the computer or server that is the end of the data; that is, after this block, no more information is found in the data previously identified by the computer or server with the header.In addition, the data has between the "header" block and the "tail" block one or more character blocks that represent statistics, numbers, descriptors, words, letters, logical values (e.g., booleans), and combinations of these.
[0196] OpenID Connect (OIDC): This protocol is based on OAuth 2.0 and adds an authentication layer. It allows web applications to authenticate users through an identity provider and obtain user information in the form of identity tokens.
[0197] SAML (Security Assertion Markup Language): It is an XML standard for the exchange of authentication and authorization information between parties, particularly between service providers and identity providers.
[0198] JWT (JSON Web Token): Although not a protocol itself, JWT is a standard for securely representing claims between two parties. It is commonly used as an access token in conjunction with OAuth 2.0.
[0199] Kerberos: It is a network protocol that authenticates users and services on a computer network where communication takes place over an insecure channel.
[0200] CAS (Central Authentication Service): A single sign-on (SSO) authentication protocol used to authenticate users across multiple applications through a single login process.
[0201] LDAP (Lightweight Directory Access Protocol): Focused on directory access, it is also used for authentication and authorization in distributed systems.
[0202] Guarantee: It is a document issued by a debtor, through which he assumes the irrevocable commitment to pay or guarantee payment up to the maximum guaranteed amount to a beneficiary on behalf of obligations of the ordering party, in case the client fails to comply with them.
[0203] Bank Guarantee: It is a document issued by a banking entity, through which it assumes the irrevocable commitment to pay or guarantee payment up to the maximum guaranteed amount to a beneficiary on behalf of obligations of the ordering party, in case the client fails to comply with them.
[0204] VPC: A VPC is a virtual network virtually identical to a traditional network that can operate in your own data center. Once a VPC is created, you can add subnets. An example of a VPC is the Amazon VPC.
[0205] EKS VPC: This is a dedicated and secure virtual network created when you set up a container or Kubernetes cluster on a cloud service. This VPC is specifically designed to support Kubernetes clusters and is configured with the subnets necessary for the cluster to function correctly. An example of an EKS VPC is the one created when deploying an EKS cluster on AWS, providing a secure and isolated environment for running containerized applications.
[0206] Instance: This refers to a specific execution or individual copy of a software or hardware component within a larger system. An instance represents a unique and concrete entity that can be replicated or executed multiple times in a technological environment, such as a server, an application, or a running process. Instances are used to handle specific tasks independently within a system, enabling greater scalability and resource efficiency.
[0207] For the purposes of this disclosure, a distinction must be made between credentials (24) associated with a digital wallet (14) and the term access credentials data associated with the user (2)
[0208] It should be understood that the present invention is not limited to the embodiments described and illustrated, since, as will be evident to a person versed in the art, there are possible variations and modifications that do not depart from the spirit of the present disclosure, which is defined only by the following claims.
Claims
CLAIMS 1. A computer-implemented method for generating certification data (12) of an electronic document, comprising executing on a computing unit (1) the steps of: a) authenticating a user (2) by means of an identity verification process, wherein the identity verification process includes executing at least a first authentication and a second authentication; wherein the user (2) accesses from a terminal (3) an application (4) that connects the terminal (3) to the computing unit (1); b) receiving, from a terminal (3) of the user (2), a status certification request (5) associated with a file (6), wherein the file (6) is stored in a database (7), and wherein the file (6) includes at least one electronic document;c) transmitting, to a validator server (9), a verification request (8) that includes the file (6), a timestamp data (10) and an identification data (11) associated with the user (2), and d) receiving, from the validator server (9), a certification data (12) associated with the verification request (8), wherein the validator server (9) obtains the certification data (12) through a process based on a blockchain network (13).; 2. The method of Claim 1, wherein the blockchain-based process (13) for obtaining the certification data (12) comprises the sub-steps of: i. validating whether a digital wallet (14) associated with the user (2) exists on a blockchain network (13); ii. creating a digital wallet (14) associated with the user (2), if the validation is negative; wherein the digital wallet (14) includes a private key data, a public key data, and an identification data (11) associated with the user (2); iii. generate, with the blockchain network (13) associated with the digital wallet (14), a hash data (15) associated with the file (6) of the verification request data (8), and iv. obtain the certification data (12) from the hash data (15), where the certification data (12) includes the hash data (15), an electronic document status data of the file (6) and a timestamp data (10), associated with the time when the hash data (15) is generated, which is obtained by timestamping on the blockchain network (13).
3. The method of Claim 1, wherein at least the computing unit (1), the validator server (9), and the blockchain network (13) are connected via an API gateway (17), and wherein, in step a), the first authentication comprises the substeps: a) transmitting, via the API gateway (17), an authentication request (18) that includes the user's (2) identification data (11) and access credentials data associated with the user (2), and a2) routing the authentication request (18), via the API gateway (17), to a backend service configured to validate the access credentials data associated with the user (2) in accordance with a predetermined security protocol; a3) receiving, via the API gateway (17), a response data (19) with a value selected from "approved" or "rejected" generated by the backend service;where the API gateway (17) is configured to restrict access from the computing unit (1) to the digital wallet (14) on the blockchain network (13), in accordance with the default security protocol.; 4. The method of Claim 1, wherein in step a) the second authentication includes a4) send an authentication request (18) to an OTP generation server (20); a5) receive from the user's (2) terminal (3) an OTP command (22) that includes a one-time code (26) generated by the OTP generation server (20) and that is sent electronically to an electronic device (27) of the user (2).
5. The method of Claim 1, wherein in step a) the second authentication includes: a6) sending an authentication request (18) to the validator server (9), wherein the authentication request (18) includes the user's (2) identification data (11); a7) receiving from the validator server (9) a response data (19) with a value selected from “approved” or “rejected”, wherein the validator server (9) generates the value “approved” if the value of the user's (2) identification data (11) matches credentials (24) associated with a digital wallet (14) previously created by the user (2); and a8) proceeding to step b) if the value of the response data (19) is “approved”.
6. The method of Claim 3, wherein after step a2) a substep a9) of balancing a workload is performed by means of the following substeps: f. receiving access requests by means of the IP address of a load balancer (25); g. distributing the access requests among instances of the target group; h. selecting the available instance of the target group; i. verifying that each instance of the target group is operational and capable of handling the traffic; and j. redirecting access request responses; k. record in a history log information about requests and instance performance; 7. The method of Claim 3, wherein after step a3) a sub-step a10) is performed to connect the computing unit (1) with the connection API gateway (17) which is responsible for managing authentication by means of an authorization protocol and allows access to the digital wallet (14).
8. The method of Claim 2, wherein the timestamp data (10) is obtained by means of the sub-steps of: l. preparing the data to be timestamped on the blockchain network (13) by providing a suitable structure and format of the information to be timestamped; m. generating a transaction with the data from the previous sub-step; n. introducing the specific information to be immutable; o. calculating the hash data (15) of the information included in the transaction to ensure its integrity; p. signing the transaction with a private key to authenticate and ensure ownership of the information; and q. transmitting the transaction to the blockchain network (13) for processing and validation.
9. The method of Claim 3, wherein in substep a2 the backend service configured to validate the access credentials data associated with the user (2) performs a digital signature by means of the substeps of: r. requesting a digital wallet (14) to sign transactions, by means of a Signer service; s. creating a digital wallet (14) by means of a Signer service; t. storing the digital wallet (14).
10. The method of Claim 3, wherein in substep a2) the backend service is configured to authenticate the user (2) by means of the substeps of: u. requesting, by means of an application (4) accessed by the user (2), a login by the user (2), wherein the user (2) logs in by entering their access credentials; v. redirecting the authentication request (18) of user (2) to the server hosting the backend service that performs authentication (18); w. applying an authorization protocol to the access credentials of user (2), wherein, if the authentication is successful, the process continues to the next step, otherwise no authorization is generated; x. generating an authorization code by means of the backend service hosted on a server; y. exchanging the authorization code for an access token; z. using the access token to access protected resources on behalf of user (2).
Citation Information
Patent Citations
Method and system for obfuscating sensitive personal data in processes requiring personal identification in unregulated platforms
US11615399B1
Systems and methods for executing and delivering electronic documents
US11900491B2
Systems and methods for identity verification to authorize transactions in decentralized networks
US20240112177A1
Method for transferring data over a blockchain network for digital transactions
US20240135364A1
Verification of digital credentials and digital signatures
WO2024063800A1
Cited By
Computer-implemented method and system for real-time human authorization of digital document lifecycle transitions
US12712858B2
Authority binding system and computer-implemented method for a digital document
US12724757B2