IP Library › Granted Patent US 11,082,226
Granted Patent B2
US 11,082,226 · App. 16/294,646 · Granted Aug 3, 2021

Zero-knowledge identity verification in a distributed computing system

Inventors: Hal Scott Hildebrand (Moss Beach, CA); Prithvi Krishnan Padmanabhan (San Ramon, CA)
Assignee: Salesforce.com, Inc.
H04L9/3218H04L9/0618H04L9/3239H04L67/1061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,082,226
App. No.
16/294,646
Granted
Aug 3, 2021
Kind
B2
Abstract

For each data value associated with a data object, a respective object value identification query message that includes the data value may be sent to each of a plurality of identity nodes via a network. For each of the data values, a respective object value identification response message that includes a respective network identifier corresponding with the respective data value may be received. A local identifier may be determined based on the object value identification response messages, and a response query message including the local identifier may be transmitted.

Claims (31)

1. A method comprising:

receiving via a communications interface a request to identify a data object that includes a first plurality of data values;

for each of the first plurality of data values, transmitting a respective object value identification query message that includes the data value to each of a plurality of identity nodes via a gossip communication protocol defining a peer-to-peer procedure for transmitting information among the plurality of identity nodes;

for each of the first plurality of data values, receiving a respective object value identification response message that includes a respective network identifier corresponding with the respective data value, wherein the respective network identifier is stored in a trust ledger shared among the plurality of identity nodes, the respective network identifier being associated in the trust ledger with a respective second one or more data values;

determining via a processor a local identifier based on the object value identification response messages, wherein the local identifier is selected by identifying a designated network identifier as the most common network identifier among the object value identification response messages; and

transmitting a query response message including the local identifier via the communications interface.

2. The method recited in claim 1 , wherein determining the local identifier further comprises querying a correspondence table using the designated network identifier, the correspondence table identifying a plurality of correspondence relationships between local identifiers and network identifiers.

3. The method recited in claim 1 , wherein determining the local identifier further comprises creating the local identifier when it is determined that the designated network identifier does not correspond to an existing local identifier.

4. The method recited in claim 1 , wherein each of the respective network identifiers is determined by consensus among the plurality of identity nodes.

5. The method recited in claim 1 , wherein the data object is associated with a data object schema, the data object schema identifying one or more data fields associated with an instance of the data object schema, each of the first plurality of data values corresponding with a respective one of the data fields.

6. The method recited in claim 1 , wherein the second one or more data values are hashed prior to storage in the trust ledger, the trust ledger capable of being queried to determine any network identifiers associated with a designated hashed data value.

7. The method recited in claim 1 , wherein the trust ledger is implemented as a merkle tree.

8. The method recited in claim 1 , wherein the trust ledger is implemented as a blockchain.

9. A database system implemented via a server system comprising:

a communications interface operable to:

receive a request to identify a data object that includes a first plurality of data values,

for each of the first plurality of data values, transmit a respective object value identification query message that includes the data value to each of a plurality of identity nodes via a gossip communication protocol defining a peer-to-peer procedure for transmitting information among the plurality of identity nodes, and

for each of the first plurality of data values, receive a respective object value identification response message that includes a respective network identifier corresponding with the respective data value, wherein the respective network identifier is stored in a trust ledger shared among the plurality of identity nodes, the respective network identifier being associated in the trust ledger with a respective second one or more data values; and

a processor operable to:

determine a local identifier based on the object value identification response messages, wherein the local identifier is selected by identifying a designated network identifier as the most common network identifier among the object value identification response messages, and

instruct the communications interface to transmit a query response message including the local identifier via the communications interface.

10. The database system recited in claim 9 , wherein determining the local identifier comprises querying a correspondence table using the designated network identifier, the correspondence table identify a plurality of correspondence relationships between local identifiers and network identifiers.

11. The database system recited in claim 9 , wherein each of the respective network identifiers is determined by consensus among the plurality of identity nodes.

12. A computer program product comprising computer-readable program code capable of being executed by one or more processors when retrieved from a non-transitory computer-readable medium, the program code configurable to cause:

processing a request received via a communications interface to identify a data object that includes a first plurality of data values;

for each of the first plurality of data values, transmitting a respective object value identification query message that includes the data value to each of a plurality of identity nodes via a gossip communication protocol defining a peer-to-peer procedure for transmitting information among the plurality of identity nodes;

for each of the first plurality of data values, receiving a respective object value identification response message that includes a respective network identifier corresponding with the respective data value, wherein the respective network identifier is stored in a trust ledger shared among the plurality of identity nodes, the respective network identifier being associated in the trust ledger with a respective second one or more data values;

determining via a processor a local identifier based on the object value identification response messages, wherein the local identifier is selected by identifying a designated network identifier as the most common network identifier among the object value identification response messages; and

transmitting a query response message including the local identifier via the communications interface.

13. The computer program product recited in claim 12 , wherein determining the local identifier comprises querying a correspondence table using the designated network identifier, the correspondence table identify a plurality of correspondence relationships between local identifiers and network identifiers.

14. The computer program product recited in claim 12 , wherein each of the respective network identifiers is determined by consensus among the plurality of identity nodes.

Assignments (2)
CHANGE OF NAME Recorded Aug 4, 2026
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 076118/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2019
From: HILDEBRAND, HAL SCOTT; PADMANABHAN, PRITHVI KRISHNAN
To: SALESFORCE.COM, INC.
Reel/Frame 048603/0199 →
Continuity (1)
Related Publication 20200287718A1 · Sep 10, 2020
Cited By (10)
US 12,354,089 US 12,380,430 US 12,469,077 US 12,526,155 US 12,632,442 US 12,645,674 US 12,670,151 US 12,688,196 US 12,730,822 US 12,737,348