IP Library Granted Patent US 12,155,767
Granted Patent B2
US 12,155,767 · App. 17/410,932 · Granted Nov 26, 2024

Zero-knowledge identity verification in a distributed computing system

Inventors: Hal Scott Hildebrand (Moss Beach, CA); Prithvi Krishnan Padmanabhan (San Francisco, CA)
Assignee: Salesforce, Inc.
H04L9/3218H04L9/0618H04L9/3239H04L67/1061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,155,767
App. No.
17/410,932
Granted
Nov 26, 2024
Kind
B2
Abstract

A request to identify a data value may be received via a network at a designated one of a plurality of identity nodes. A query that includes the data value may be transmitted to an identity service associated with the designated identity node. A response message from the identity service may include one or more designated network identifiers corresponding with the data value. The designated identity node may communicate with the plurality of identity nodes to identify a plurality of network identifiers corresponding with the data value. A trust ledger may be updated to include a correspondence between a selected one of the network identifiers and the data value.

Claims (33)

1. A computing system comprising:

a designated identity process implemented on a processor, the designated identity process configured to receive a request to identify a designated data object that includes a plurality of data values;

a communication interface configured to:

share the plurality of data values among a plurality of remote identity nodes via one or more query messages transmitted over the internet via a gossip communication protocol that conceals from the remote identity nodes that the computing system originated the one or more query messages and that conceals from the remote identity nodes that the plurality of data values are each associated with the designated data object,

receive from the plurality of remote identity nodes one or more response messages transmitted over the internet via the gossip communication protocol, the response messages identifying a plurality of network identifiers each corresponding with one or more of the plurality of data values, two or more of the plurality of network identifiers conflicting; and

a trust connector configured to store in a trust ledger a hash value corresponding with one or more of the plurality of data values in association with a designated network identifier selected by consensus among the plurality of network identifiers to resolve the conflicting network identifiers.

2. The computing system recited in claim 1 , wherein the peer-to-peer communication protocol conceals from the remote identity nodes that the plurality of data values are each associated with the designated data object.

3. The computing system recited in claim 1 , wherein the designated identity process is one of a plurality of identity processes included in the computing system, and wherein the computing system further includes a load balancer configured to balance query requests among the plurality of identity processes.

4. The computing system recited in claim 1 , further comprising:

a match query interface configured to receive a query response from the designated identity process identifying the designated network identifier.

5. The computing system recited in claim 4 , wherein the match query interface is configured to determine a designated local identifier based on the designated network identifier, the computing system maintaining a correspondence table associating a plurality of network identifiers with a corresponding plurality of local identifiers.

6. The computing system recited in claim 5 , wherein the designated local identifier identifies the designated data object with the computing system.

7. The computing system recited in claim 1 , the computing system further comprising:

a query cache recording communications with the remote identity nodes, the query cache including the one or more query messages and the one or more response messages.

8. The computing system recited in claim 1 , the computing system further comprising:

A query domain-specific language processor configured to translate queries between a first language common to the remote identity nodes and a second language used within the computing system.

9. The computing system recited in claim 1 , wherein the trust ledger is shared among the plurality of remote identity nodes.

10. The computing system recited in claim 1 , wherein the trust ledger is a blockchain.

11. The computing system recited in claim 1 , wherein the trust ledger is a merkle tree.

12. The computing system recited in claim 1 , wherein the computing system is an on-demand computing services environment configured to provide on-demand computing services to a plurality of entities via the internet.

13. The computing system recited in claim 12 , wherein the on-demand computing services include on-demand database services implemented via a multitenant database system that stores data associated with a plurality of tenants that include the plurality of entities.

14. A method comprising:

receiving at a designated identity process implemented on a processor a request to identify a designated data object that includes a plurality of data values;

sharing the plurality of data values among a plurality of remote identity nodes via one or more query messages transmitted over the Internet via a gossip communication protocol through a communication interface, the gossip communication protocol concealing from the remote identity nodes a computing system that originated the one or more query messages and concealing from the remote identity nodes that the plurality of data values are each associated with the designated data object;

receiving from the plurality of remote identity nodes one or more response messages transmitted over the internet via the gossip communication protocol, the response messages identifying a plurality of network identifiers each corresponding with one or more of the plurality of data values, two or more of the plurality of network identifiers conflicting; and

storing in a trust ledger a hash value corresponding with one or more of the plurality of data values in association with a designated network identifier selected by consensus among the plurality of network identifiers to resolve the conflicting network identifiers.

15. The method recited in claim 14 , the method further comprising:

determining a designated local identifier based on the designated network identifier by accessing a correspondence table associating a plurality of network identifiers with a corresponding plurality of local identifiers.

16. One or more non-transitory computer readable media having instructions stored thereon for performing a method, the method comprising:

receiving at a designated identity process implemented on a processor a request to identify a designated data object that includes a plurality of data values;

sharing the plurality of data values among a plurality of remote identity nodes via one or more query messages transmitted over the Internet via a gossip communication protocol through a communication interface, the gossip communication protocol concealing from the remote identity nodes a computing system that originated the one or more query messages and concealing from the remote identity nodes that the plurality of data values are each associated with the designated data object;

receiving from the plurality of remote identity nodes one or more response messages transmitted over the internet via the gossip communication protocol, the response messages identifying a plurality of network identifiers each corresponding with one or more of the plurality of data values, two or more of the plurality of network identifiers conflicting; and

storing in a trust ledger a hash value corresponding with one or more of the plurality of data values in association with a designated network identifier selected by consensus among the plurality of network identifiers to resolve the conflicting network identifiers.

Assignments (2)
CHANGE OF NAME Recorded Oct 4, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069133/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2021
From: HILDEBRAND, HAL SCOTT; PADMANABHAN, PRITHVI KRISHNAN
To: SALESFORCE.COM, INC.
Reel/Frame 057277/0030 →
Continuity (2)
Continuation 16294654 · Mar 6, 2019
Related Publication 20210385087A1 · Dec 9, 2021