Distributed file system for managing permissioned access to records

Inventors

Jonak, Sumita T.Schroeder, Steven J.Philbrick, Ashley RaineKrebs, Emily Kathleen

Assignees

United Services Automobile Association USAA

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-12682990-B1

Patent

Publication Date

2026-07-14

Expiration Date


Abstract

The distributed file system includes a blockchain node with one or more records recorded in a blockchain of the blockchain node by a series of immutable transactions. More specifically, the blockchain node receives a request to permit access to a record by a service provider. The blockchain node is further configured to determine a geofenced area associated with the service provider, the geofenced area being an area encompassing a geographic location associated with the service provider, and to determine a location of the mobile device associated with the record based on the request. When the blockchain node determines that the mobile device is within the geofenced area associated with the service provider, the blockchain node sends a biometric confirmation request to the mobile device to permit the service provider access to the record.

Core Innovation

A distributed file system uses a blockchain node that stores one or more records associated with a user by a series of immutable transactions. A service provider requests permission to permit access to a record, and the request comprises a record identifier associated with the record, an indication of a location of the service provider, and an indication of a mobile device associated with an owner of the record. The system identifies the record stored in the blockchain based on the record identifier and determines a geofenced area associated with the service provider based on the indication of the location of the service provider.

The system queries a location of the mobile device and determines that the mobile device is within the geofenced area associated with the service provider. In response to entry of the mobile device in the geofenced area, the system identifies the mobile device as being associated with the user based on a handshake between the mobile device and the service provider with an application running and active on the mobile device to facilitate user interaction with a communication network of the service provider. The system then sends a biometric confirmation request to the mobile device to permit the service provider access to the record based upon determining that the mobile device is within the geofenced area and identifying that the mobile device is associated with the user.

Upon receiving the biometric confirmation from the mobile device, the system determines validation of the request to permit access to the record, where the validation comprises receiving the biometric confirmation within a specified time period, and transmits the record or a reference to the record from the blockchain to a service provider device associated with the service provider according to permission information associated with the record. The system can also receive updated location information and determine that the mobile device is outside the geographic location associated with the service provider, deny access by the service provider, and transmit a notification to the service provider that the request has been denied. Permission information can include ephemeral permissions that expire by time, expiration upon a pre-determined number of instances/uses, or expiration upon geofence exit, and the system can transmit and revoke access accordingly.

Claims Coverage

The partial content includes three independent claims. Across the independent claims, the inventive coverage centers on geofencing-based verification of a user-associated mobile device combined with biometric confirmation before transmitting a blockchain-stored record or a reference to a service provider according to permission information.

Blockchain-based geofenced permission request with biometric confirmation

Receiving, at a blockchain node of a distributed file system comprising one or more records associated with a user, a request to permit access to a record by a service provider with a record identifier, an indication of a location of the service provider, and an indication of a mobile device; determining a geofenced area associated with the service provider; querying a location of the mobile device; determining the mobile device is within the geofenced area; identifying the mobile device as being associated with the user based on a handshake with an application running and active; sending a biometric confirmation request to the mobile device; receiving biometric confirmation and validating receipt within a specified time period; and transmitting the record or a reference from the blockchain to the service provider device according to permission information associated with the record.

Distributed file system with denial and notification upon geofence exit

A distributed file system comprising a blockchain node with one or more user-associated records stored in a blockchain by immutable transactions, and a processor configured to: receive a request to permit access with a record identifier, location of the service provider, and indication of a mobile device; identify the record based on the record identifier; determine a geofenced area associated with the service provider; query the location of the mobile device and determine it is within the geofenced area; identify the mobile device as associated with the user based on a handshake with an application running and active; send a biometric confirmation request and receive biometric confirmation; transmit the record or a reference according to permission information; receive an updated request and receive updated location information; determine the mobile device is outside the geographic location; deny access to the record or reference; and transmit a notification to the service provider that the request has been denied.

Machine-readable medium for time-limited access and revocation

A tangible, non-transitory, machine-readable medium comprising instructions which, when executed, cause at least one processor to: receive at a blockchain node a request to permit access with a record identifier, location of the service provider, and indication of a mobile device; identify the record stored in the blockchain; determine a geofenced area and determine the mobile device is within it; identify the mobile device as being associated with the user based on a handshake with an application running and active; transmit a biometric confirmation request and receive biometric confirmation; upon receiving biometric confirmation, transmit the record or a reference from the blockchain according to permission information; determine that a pre-determined amount of time has passed; and revoke access by the service provider to the record or the reference.

Across the independent claims, access to blockchain-stored, user-associated records is granted only after geofenced validation of a user-associated mobile device and completion of biometric confirmation, and access can be denied with notification or revoked when the mobile device leaves the geographic location or when time-based permission validation expires.

Stated Advantages

Not explicitly described in patent.

Documented Applications

Not explicitly described in patent.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.