EP4513832A2

Systems, methods, and storage media for permissioned delegation in a computing environment

Abstract

Systems, methods, and storage media, for enforcing transaction permissions delegation in a computing environment are disclosed. Exemplary implementations may: receive a permissions request, from a requesting computing system for a permissions certificate; transmit a login request to a user computing system associated with a user; receive an acceptance from the user in response to the login request; generate a permissions certificate data structure in response to the acceptance; and return the permissions certificate to the requesting computing system whereby the requesting computing system will be permitted to accomplish the transaction with a transacting party in place of the issuer computing system based on possession of the permissions certificate paired with a cryptographic signature based on a private cryptographic key associated with the requesting computing system.

EP4513832A2, drawing sheet 1
Sheet 1 of 7

Term

13.6 yearsto projected expiry

Projected expiry 6 May 2040, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

26 claims: 4 independent, 22 dependent

  1. 1
    A certificate issuer computing system (102) for enforcing permissions delegation in a computing environment, the certificate issuer computing system (102) having permissions to execute at least one transaction on behalf of a user, the system comprising:one or more hardware processors configured by machine-readable instructions (106) to: receive a permissions request, from a requesting computing system, for a permissions certificate, the permissions request specifying permissions to execute at least a subset of the at least one transaction on behalf of the user and preferably a cryptographic public key associated with the requesting computing system;transmit a login request to a user computing system associated with a user, preferably the login request causing a login interface to be displayed on the user computing system;receive an acceptance from the user in response to the login request;generate a permissions certificate data structure in response to the acceptance, the permissions certificate data structure including an identity, preferably the cryptographic public key, associated with the requesting computing device, an identity, preferably a cryptographic public key, associated with the issuer computing system (102), a permissions indication indicating the permissions held by the certificate issuer computer system to execute a subset of the at least one transaction on behalf of the user, and a certificate signature of the certificate issuer computer system private key against the certificate, preferably the certificate object;and return the permissions certificate data structure to the requesting computing system whereby the requesting computing system will be permitted to accomplish the at least a subset of the at least one transaction on behalf of the user with a transacting party in place of the certificate issuer computing system (102) based on possession of the permissions certificate data structure paired with a cryptographic signature based on a private cryptographic key associated with the requesting computing system.
  2. 13
    A method, implemented by a certificate issuer computing system (102), for permissions delegation in a computing environment, the certificate issuer computing system (102) having permissions to execute at least one transaction on behalf of the user, the method comprising:receiving a permissions request, from a requesting computing system for a permissions certificate, the permissions request specifying permissions to execute at least a subset of the at least one transaction on behalf of the user and preferably a cryptographic public key associated with the requesting computing system;transmitting a login request to a user computing system associated with a user, preferably the login request causing a login interface to be displayed on the user computing system;receiving an acceptance from the user in response to the login request;generating a permissions certificate data structure in response to the acceptance, the permissions certificate data structure including an identity, preferably the cryptographic public key, associated with the requesting computing device, an identity, preferably a cryptographic public key, associated with the issuer computing system (102), a permissions indication indicating permissions to execute the at least a subset of the at least one transaction on behalf of the user, and a certificate signature of the issuer private key against the certificate, preferably the certificate object;and returning the permissions certificate to the requesting computing system whereby the requesting computing system will be permitted to accomplish the at least one transaction on behalf of the user with a transacting party in place of the issuer computing system (102) based on possession of the permissions certificate paired with a cryptographic signature based on a private cryptographic key associated with the requesting computing system.
  3. 25
    A non-transient computer-readable storage medium having instructions embodied thereon, the instructions being executable by one or more processors to perform a method, implemented by a certificate issuer computing system (102), for permissions delegation in a computing environment, the certificate issuer computing system having permissions to execute at least one transaction on behalf of a user, the method comprising:receiving a permissions request, from a requesting computing system for a permissions certificate, the permissions request specifying permissions to execute at least a subset of the at least one transaction on behalf of the user and preferably a cryptographic public key associated with the requesting computing system;transmitting a login request to a user computing system associated with a user, preferably the login request causing a login interface to be displayed on the user computing system;receiving an acceptance from the user in response to the login request;generating a permissions certificate data structure in response to the acceptance, the permissions certificate data structure including an identity, preferably the cryptographic public key, associated with the requesting computing device, an identity, preferably a cryptographic public key, associated with the certificate issuer computing system (102), a permissions indication indicating permissions, preferably held by the certificate issuer computer system, and a certificate signature of the issuer private key against the certificate, preferably the certificate object;and returning the permissions certificate to the requesting computing system whereby the requesting computing system will be permitted to accomplish the transaction with a transacting party in place of the issuer computing system (102) based on possession of the permissions certificate paired with a cryptographic signature based on a private cryptographic key associated with the requesting computing system.
  4. 26
    A method for verifying a permissions certificate issued by a certificate issuer computer system for delegating transaction permissions in a computing environment, the certificate issuer computing system (102) having permissions to execute at least one transaction on behalf of a user, the method comprising:receiving a permissions certificate, wherein the permissions certificate was constructed by: receiving a permissions request, from a requesting computing, system for a permissions certificate, the permissions request specifying permissions to execute at least a subset of the at least one transaction on behalf of the user and preferably a cryptographic public key associated with the requesting computing system;transmitting a login request to a user computing system associated with a user, preferably the login request causing a login interface to be displayed on the user computing system;receiving an acceptance from the user in response to the login request;and generating a permissions certificate data structure in response to the acceptance, the permissions certificate data structure including an identity, preferably the cryptographic public key, associated with the requesting computing device, an identity, preferably a cryptographic public key, associated with the issuer computing system (102), a permissions indication indicating permissions to execute the at least a subset of the at least one transaction on behalf of the user, preferably held by the issuer computer system, and a certificate signature of the issuer private key against the certificate object;checking the validity of the permissions certificate by at least one of;the certificate issuer verifying the certificate signature, the requesting computing system verifying the transaction proof, a check that an expiration time specified in the permissions certificate has not passed and/or a check that the permissions certificate has not have been revoked.