IP Library › Granted Patent US 10,742,411
Granted Patent B2
US 10,742,411 · App. 15/994,893 · Granted Aug 11, 2020

Generating and managing decentralized identifiers

Inventors: Ankur Patel (Sammamish, WA); Daniel James Buchner (Los Gatos, CA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L9/0894G06F16/24578G06F16/907G06F16/9014G06F21/33G06F21/45G06F21/6218G06Q20/3674G06Q20/3821G06Q20/3829H04L9/0637H04L9/083H04L9/0869H04L9/0891H04L9/14H04L9/30H04L9/321H04L9/3236H04L9/3239H04L9/3247H04L63/08H04L63/102H04L63/20G06F2221/2131G06F2221/2141H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,742,411
App. No.
15/994,893
Granted
Aug 11, 2020
Kind
B2
Abstract

The generation and management of decentralized identifiers of an entity. A decentralized identifier of a particular entity is recorded. Then, upon determining that the particular entity is granting a permission to another entity, the permission is signed based on the recorded decentralized identifier. As one example, the permission may be signed by a private key of the decentralized identifier. The permission may be verified upon request by authenticating the signed permission being associated with the recorded decentralized identifier; and authorizing the other entity to act upon the data depending on the authentication. As an example only, the authentication may occur using a public key associated with the recorded decentralized identifier.

Claims (42)

1. A computing system comprising:

one or more processors; and

one or more hardware storage devices having thereon computer-executable instructions that are structured such that, when executed by the one or more processors, cause the computing system to generate and manage decentralized identifiers of an entity by causing the computing system to perform operations comprising:

recording a decentralized identifier of a first entity that points to a decentralized identifier document, the decentralized identifier document being associated with the first entity and comprising data associated with the first entity including a signature of a separate entity, the signature certifying a transaction between the first entity and the separate entity;

determining that the first entity is granting a permission to a second entity to verify the transaction between the first entity and the separate entity, the permission defining a scope of data associated with the first entity and an associated permitted use of that scope of data;

signing the permission using a private key of the recorded decentralized identifier;

receiving a request from the second entity to act upon the data associated with the first entity to access the signature of the separate entity to verify the transaction between the first entity and the separate entity;

authenticating the signed permission using a public key of the recorded decentralized identifier; and

depending on the authentication, authorizing the second entity to act upon the data to access the signature of the separate entity to verify the transaction between the first entity and the separate entity.

2. The computing system of claim 1 , wherein the private key is stored off-line.

3. The computing system in accordance with claim 1 , wherein the permission is changed in response to the first entity.

4. The computing system in accordance with claim 1 , wherein the granted permission is revoked in response to the first entity.

5. The computing system of claim 1 , wherein the operations further comprise:

generating a new decentralized identifier;

associating the new decentralized identifier with the first entity; and

recording the new decentralized identifier.

6. The computing system of claim 1 , wherein the permission defining a scope of data comprises a permission to read data associated with the particular entity.

7. The computing system of claim 1 , wherein the second entity is associated with another decentralized identifier.

8. The computing system of claim 1 , wherein the decentralized identifier is recorded in a distributed ledger.

9. The computing system of claim 1 , wherein the associated permitted use of the scope of data is specified by the first entity.

10. The computing system of claim 1 , wherein the associated permitted use of the scope of data includes two or more predetermined use options that are provided to a permissions application for the first entity to choose from.

11. The computing system of claim 1 , wherein the decentralized identifier comprises a human-readable identifier.

12. The computing system of claim 11 , wherein the human-readable identifier comprises a photo.

13. The computing system of claim 1 , wherein the decentralized identifier is recorded by being stored on a device of the first entity.

14. The computing system of claim 1 , wherein the decentralized identifier is recorded by being stored in a cloud store.

15. The computing system of claim 1 , wherein the recording of the decentralized identifier is encrypted.

16. The computing system in accordance with claim 1 , wherein determining that the first entity is granting a permission to a second entity to verify the transaction between the first entity and the separate entity includes recording a second decentralized identifier of the first entity that points to a second decentralized identifier document, the second decentralized identifier document being associated with the first entity and comprising a permission entry that grants permission to the second entity to access the signature of the separate entity.

17. The computing system in accordance with claim 16 , wherein the second decentralized identifier document also includes the signature of the separate entity, and wherein authorizing the second entity to access the signature of the separate entity includes retrieving the second decentralized identifier document.

18. A method for generating and managing decentralized identifiers of an entity, the method comprising:

recording a decentralized identifier of a first entity that points to a decentralized identifier document, the decentralized identifier document being associated with the first entity and comprising data associated with the first entity including a signature of a separate entity, the signature certifying a transaction between the first entity and the separate entity;

determining that the first entity is granting a permission to a second entity to verify the transaction between the first entity and the separate entity, the permission defining a scope of data associated with the first entity and an associated permitted use of that scope of data;

signing the permission using a private key of the recorded decentralized identifier;

receiving a request from the second entity to act upon the data associated with the first entity to access the signature of the separate entity to verify the transaction between the first entity and the separate entity;

authenticating the signed permission using a public key of the recorded decentralized identifier; and

depending on the authentication, authorizing the second entity to act upon the data to access the signature of the separate entity to verify the transaction between the first entity and the separate entity.

19. A computer program product comprising one or more hardware storage devices having thereon computer-executable instructions that are structured such that, when executed by one or more processors of a computing system, cause the computing system to generate and manage decentralized identifiers of an entity by causing the computing system to perform operations comprising:

recording a decentralized identifier of a first entity that points to a decentralized identifier document, the decentralized identifier document being associated with the first entity and comprising data associated with the first entity including a signature of a separate entity, the signature certifying a transaction between the first entity and the separate entity;

determining that the first entity is granting a permission to a second entity to verify the transaction between the first entity and the separate entity, the permission defining a scope of data associated with the first entity and an associated permitted use of that scope of data;

signing the permission using a private key of the recorded decentralized identifier;

receiving a request from the second entity to act upon the data associated with the first entity to access the signature of the separate entity to verify the transaction between the first entity and the separate entity;

authenticating the signed permission using a public key of the recorded decentralized identifier; and

depending on the authentication, authorizing the second entity to act upon the data to access the signature of the separate entity to verify the transaction between the first entity and the separate entity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2018
From: PATEL, ANKUR; BUCHNER, DANIEL JAMES
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 046716/0849 →
Continuity (3)
Provisional Application 62620300 · Jan 22, 2018
Provisional Application 62626564 · Feb 5, 2018
Related Publication 20190230092A1 · Jul 25, 2019
Cited By (3)
US 12,368,601 US 12,375,283 US 12,683,802