Method and system for user-determind attribute storage in a federated environment
First Claim
1. A method for managing user attribute information within a data processing system, the method comprising:
- receiving a request message at an attribute information provider from a service provider that is attempting to retrieve user attribute information for a user to complete a transaction for the user, wherein the request message identifies one or more requested user attributes, wherein the attribute information provider comprises an attribute management machine and an associated database that maintains user attribute information for the user and is distinct from the service provider that is attempting to retrieve the user attribute information to complete the transaction for the user;
verifying that the request message is from a service provider that is trusted by the attribute information provider;
after receipt of the request message at the attribute information provider and prior to the attribute information provider sending a response message, determining whether the attribute information provider is currently maintaining a requested user attribute for the user; and
if the attribute information provider is currently maintaining the requested user attribute for the user, requesting and receiving user input by the attribute information provider prior to sending the response message from the attribute information provider to the service provider, wherein the user input comprises a value that indicates a retrieval condition on subsequent requests while retrieving user attribute information for the user.
4 Assignments
0 Petitions
Accused Products
Abstract
A system is presented for facilitating management of user attribute information at one or more attribute information providers (AIPs), which can manage the user'"'"'s attribute information in accordance with user-selected or administratively-determined options, including options that are stored in attribute release policies and/or dynamically determined during a transaction. E-commerce service providers (ECSPs), such as online banks or merchants, also maintain a relationship with an AIP such that the ECSP can trust the user attribute information that is provided by the AIP on behalf of the user. The user can complete transactions that require user attribute information at any ECSP without having to have previously established a relationship with that particular ECSP. If the ECSP has a relationship with one of the user'"'"'s AIPS, then the user will be able to direct the ECSP to an AIP when the ECSP needs user attribute information to complete a transaction for the user.
33 Citations
33 Claims
-
1. A method for managing user attribute information within a data processing system, the method comprising:
-
receiving a request message at an attribute information provider from a service provider that is attempting to retrieve user attribute information for a user to complete a transaction for the user, wherein the request message identifies one or more requested user attributes, wherein the attribute information provider comprises an attribute management machine and an associated database that maintains user attribute information for the user and is distinct from the service provider that is attempting to retrieve the user attribute information to complete the transaction for the user; verifying that the request message is from a service provider that is trusted by the attribute information provider; after receipt of the request message at the attribute information provider and prior to the attribute information provider sending a response message, determining whether the attribute information provider is currently maintaining a requested user attribute for the user; and if the attribute information provider is currently maintaining the requested user attribute for the user, requesting and receiving user input by the attribute information provider prior to sending the response message from the attribute information provider to the service provider, wherein the user input comprises a value that indicates a retrieval condition on subsequent requests while retrieving user attribute information for the user. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A data processing system for managing user attribute information, the data processing system comprising:
-
a processor; a computer memory holding computer program instructions which, when executed by the processor, perform a method comprising; receiving a request message at an attribute information provider from a service provider that is attempting to retrieve user attribute information for a user to complete a transaction for the user, wherein the request message identifies one or more requested user attributes, wherein the attribute information provider maintains user attribute information for the user and is distinct from the service provider that is attempting to retrieve the user attribute information to complete the transaction for the user; verifying that the request message is from a service provider that is trusted by the attribute information provider; after receipt of the request message at the attribute information provider and prior to the attribute information provider sending a response message, determining whether the attribute information provider is currently maintaining a requested user attribute for the user; and responsive to a determination that the attribute information provider is currently maintaining the requested user attribute for the user, requesting and receiving user input by the attribute information provider prior to sending the response message from the attribute information provider to the service provider, wherein the user input comprises a value that indicates a retrieval condition on subsequent requests while retrieving user attribute information for the user. - View Dependent Claims (13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 29, 30, 31)
-
-
23. A computer program product in a computer readable medium for managing user attribute information in a data processing system, the computer program product holding computer program instructions which, when executed by the data processing system, perform method comprising:
-
receiving a request message at an attribute information provider from a service provider that is attempting to retrieve user attribute information for a user to complete a transaction for the user, wherein the request message identifies one or more requested user attributes, wherein the attribute information provider maintains user attribute information for the user and is distinct from the service provider that is attempting to retrieve the user attribute information to complete the transaction for the user; verifying that the request message is from a service provider that is trusted by the attribute information provider; after receipt of the request message at the attribute information provider and prior to the attribute information provider sending a response message, determining whether the attribute information provider is currently maintaining a requested user attribute for the user; and responsive to a determination that the attribute information provider is currently maintaining the requested user attribute for the user, requesting and receiving user input by the attribute information provider prior to sending the response message from the attribute information provider to the service provider, wherein the user input comprises a value that indicates a retrieval condition on subsequent requests while retrieving user attribute information for the user. - View Dependent Claims (24, 25, 26, 27, 28, 32, 33)
-
Specification