Patent Issued for Multi-purpose device having multiple certificates including member certificate (USPTO 11823282): Visa International Service Association
2023 DEC 12 (NewsRx) -- By a
The assignee for this patent, patent number 11823282, is
Reporters obtained the following quote from the background information supplied by the inventors: “Fraud in the medical service industry is a problem, both in the private and public sector. For instance, a plastic card is commonly used to verify the benefits associated with an individual for medical services. The patient arrives at the medical clinic or pharmacy with a plastic card bearing the insurance provider’s name, the name of the person receiving the medical service and in some cases the co-payment requirement. However, a forger can duplicate an insurance card allowing an individual seeking medical service to associate themselves with a set of benefits that they may not be entitled to.
“Additionally, inconvenience and inefficiency are other problems in the medical industry. A typical patient carries with them multiple cards for different benefits (medical, dental, vision, medicine, etc.) and yet more cards to make payments for the co-payments or remaining balances for the medical services.
“Furthermore, when requesting service, the patient has little understanding of the ultimate financial responsibility from the transaction until much later. Usually, the medical service provider or the patient calls the medical insurer to discuss the coverage further adding to the inefficiency. In many instances, the billing for the medical service provided begins long after the medical services are provided to the patient. The billing is usually accomplished by a long back and forth discourse through mail between the medical service provider, the medical insurer and the patient that usually includes statements, reminders, insurance benefit explanations and appeals. This process of operating with non-verified and incomplete information leads to dissatisfaction and inefficiencies in the system.
“Embodiments of the invention address these and other problems.”
In addition to obtaining background information on this patent, NewsRx editors also obtained the inventors’ summary information for this patent: “Embodiments of the invention broadly described, allow members of an organization to integrate member attributes with payment attributes on a multi-purpose device whose security is provided by a public-key infrastructure system.
“Embodiments of the invention relate to systems and methods for provisioning and using a multi-purpose device. The device contains information regarding a plurality of memberships associated with a user and a payment account associated with the user. The device contains one or more membership certificate chains, comprising multiple certificates, wherein a membership provider certificate is signed by a private key associated with a membership root certificate authority, and wherein a member certificate is signed by a private key associated with the membership provider certificate. The member certificate includes member attributes regarding the user, such as member benefit information. The device may optionally include data which is signed by a private key stored on the device and associated with the member certificate. The device also includes a payment certificate chain, comprising multiple certificates, wherein a payment provider certificate is signed by a private key associated with a payment root certificate authority, and wherein a payment certificate is signed by a private key associated with the payment provider certificate. The payment certificate includes payment attributes regarding the user, such as a payment account.
“A user may present the multi-purpose device to a service provider in order to prove membership benefits. The service provider may authenticate the device by verifying the signatures in the membership certificate chain. The service provider may also read from the device member benefit information associated with the user. The service provider may calculate a final billing amount based on the member benefit information, and bill the user for the amount using the payment attributes stored on the multi-purpose device. As a result, the service provider is assured of the authenticity of the user and the member attributes, and can quickly determine the amount to be billed to the user. The user is made aware of the final cost of a service at the time they present the device to the service provider.
“One embodiment of the invention discloses a computer implemented method for verifying benefits associated with a multi-purpose device, comprising: electronically receiving, at a terminal, a member certificate comprising member attributes from a multi-purpose device, wherein the member certificate is signed by a membership provider certificate authority associated with a payment processing network; digitally verifying the contents of the member certificate; and determining from the member attributes member benefit information for a member.
“One embodiment of the invention discloses a computer-implemented method for providing certificates to a membership provider and payment provider, comprising: electronically receiving, from a membership provider server computer, a membership provider public key and a first request to generate a membership provider certificate; generating the membership certificate using the membership provider public key and a first private key, wherein the membership provider certificate is stored on a device; electronically receiving, from an payment provider server computer, a payment provider public key and a second request to generate a payment provider certificate; and generating the payment provider certificate using the payment provider public key and a second private key, wherein the payment provider certificate is stored on the device.”
The claims supplied by the inventors are:
“1. A method comprising: electronically receiving, by a certificate authority, from a membership provider server computer, a membership provider public key and a first request to generate a membership provider certificate; defining, by the certificate authority, one or more data fields based on one or more characteristics of a membership provider; generating, by the certificate authority, the membership provider certificate including the one or more defined data fields, using the membership provider public key and a membership root private key, wherein the membership provider certificate is stored on a multi-purpose device to enable access while offline; assigning, by the certificate authority, the membership provider certificate to the membership provider server computer for signing member certificates; electronically receiving, by the certificate authority from a payment provider server computer, a payment provider public key and a second request to generate a payment provider certificate; generating, the certificate authority, the payment provider certificate using the payment provider public key and a payment root private key, wherein the payment provider certificate is stored on the multi-purpose device; and assigning, by the certificate authority, the payment provider certificate to the payment provider server computer for signing payment provider certificates.
“2. The method according to claim 1, wherein the membership provider certificate is generated by a first server computer belonging to the certificate authority.
“3. The method according to claim 1, wherein the payment provider certificate is generated by a second server computer belonging to the certificate authority.
“4. The method according to claim 1, wherein the membership provider certificate represents an identity of a membership provider certificate authority for signing and issuing the member certificates.
“5. The method according to claim 1, wherein the payment provider certificate represents an identity of a payment provider.
“6. The method according to claim 1, further comprising, maintaining, by the certificate authority, a database of payment provider certificates and membership provider certificates issued by the certificate authority.
“7. The method according to claim 1, wherein the certificate authority issues certificates to one or more payment providers and one or more membership providers.
“8. The method according to claim 7, wherein a certificate is an electronic document or data file that binds a public key with data associated with an identity by using a digital signature.
“9. The method according to claim 1, wherein the first request is encrypted and includes proof of identity of the membership provider server computer.
“10. The method according to claim 1, wherein the second request is encrypted and includes proof of identity of the payment provider server computer.
“11. The method according to claim 1, wherein the membership root private key and the payment root private key are a same private key.
“12. The method according to claim 1, wherein member attributes stored on the multi-purpose device are used to determine member benefit information for a member and to determine a payment balance based on at least one transaction for the member and at least one benefit associated with a membership.
“13. The method according to claim 12, wherein the member attributes comprise medical benefits information and the membership provider server computer is a medical insurance provider server computer.
“14. The method according to claim 12, wherein the payment provider certificate stored on the multi-purpose device is used to issue a payment certificate, wherein the payment certificate comprises payment attributes for processing the payment balance.
“15. A certificate authority comprising: a first server computer comprising a first processor; and a first non-transitory computer-readable storage medium, comprising code executable by the first processor for implementing a first method comprising: receiving, at the first server computer, a membership provider public key and a first request to generate a membership provider certificate; defining, by the certificate authority, one or more data fields based on one or more characteristics of a membership provider; generating the membership provider certificate including the one or more defined data fields, by the first server computer, using the membership provider public key and a membership root private key, wherein the membership provider certificate is stored on a multi-purpose device to enable access while offline; assigning, by the certificate authority, the membership provider certificate to the first server computer for signing member certificates; a second server computer comprising a second processor; and a second non-transitory computer-readable storage medium, comprising code executable by the second processor for implementing a second method comprising: receiving, at the second server computer, a payment provider public key and a second request to generate a payment provider certificate; generating the payment provider certificate, by the second server computer, using the payment provider public key and a payment root private key, wherein the payment provider certificate is stored on the multi-purpose device; and assigning, by the certificate authority, the payment provider certificate to the second server computer for signing payment provider certificates.
“16. The certificate authority according to claim 15, wherein the first request is encrypted and includes proof of identity of the first server computer.
“17. The certificate authority according to claim 15, wherein the second request is encrypted and includes proof of identity of the second server computer.
“18. The certificate authority according to claim 15, wherein member attributes stored on the multi-purpose device are used for determining member benefit information for a member and determining a payment balance based on at least one transaction for the member and at least one benefit associated with a membership.
“19. The certificate authority of claim 18, wherein the member attributes is medical benefits information provided by a medical insurance provider.
“20. The certificate authority of claim 18, wherein the payment provider certificate stored on the multi-purpose device is used to issue a payment certificate, wherein the payment certificate comprises payment attributes for the member used for processing the payment balance.”
For more information, see this patent: Hurry, Simon. Multi-purpose device having multiple certificates including member certificate.
(Our reports deliver fact-based news of research and discoveries from around the world.)
“Methods And Systems For Evaluating Medical Insurance Data In Smart City Based On The Internet Of Things” in Patent Application Approval Process (USPTO 20230377048): Chengdu Qinchuan Iot Technology Co. Ltd.
Patent Issued for Risk management system with internet of things (USPTO 11823575): Allstate Insurance Company
Advisor News
Annuity News
Health/Employee Benefits News
Life Insurance News