IP Library Granted Patent US 11,811,742
Granted Patent B2
US 11,811,742 · App. 17/460,860 · Granted Nov 7, 2023

Methods, systems, and media for recovering identity information in verifiable claims-based systems

Inventors: David Stein (New York, NY); John Wittrock (Brooklyn, NY)
Assignee: Google LLC
H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,811,742
App. No.
17/460,860
Granted
Nov 7, 2023
Kind
B2
Abstract

Methods, systems, and media for recovering identity information in verifiable claims-based systems are provided. In some embodiments, the method comprises: determining that a graph of interdependencies between a plurality of issuers and a plurality of claims for a holder is to be reconstructed; restoring a root credential; transmitting a plurality of messages that are each signed with the root credential to a plurality of backup providers, wherein each of the plurality of backup providers has a portion of the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder stored in a storage device; receiving a plurality of graph portions from at least a portion of the plurality of backup providers in response to each of the portion of the plurality of backup providers determining that the root credential is a correct root credential corresponding to the holder; and reconstructing the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder using the plurality of received graph portions.

Claims (45)

1. A method for restoring user credentials, the method comprising:

receiving, using a hardware processor of a computing device, a request to locally restore a digital wallet of a holder associated with a digital wallet application executing on the computing device; and

restoring, using the hardware processor, the digital wallet by:

restoring a root credential;

transmitting a plurality of messages that are each signed with the root credential to a plurality of backup providers, wherein each of the plurality of backup providers has a portion of a graph of interdependencies, wherein the graph of interdependencies is between a plurality of issuers and a plurality of claims for the holder and wherein the graph of interdependencies is unable to be reconstructed from the portion;

receiving a plurality of graph portions from at least a portion of the plurality of backup providers in response to each of the portion of the plurality of backup providers determining that the root credential is a correct root credential corresponding to the holder; and

reconstructing the graph of interdependencies using the plurality of received graph portions.

2. The method of claim 1 , further comprising:

transmitting a request to each of the plurality of issuers in the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder, wherein the request includes at least one claim from the plurality of claims for the holder.

3. The method of claim 2 , further comprising:

receiving, from an issuer device, derived credentials relating to a reissued verifiable claim; and

restoring a claim in the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder with the reissued verifiable claim.

4. The method of claim 1 , wherein each of the plurality of claims is data demonstrating a property signed by an issuer.

5. The method of claim 1 , wherein the plurality of issuers include a subset of root issuers and a subset of depending issuers, wherein each of the subset of root issuers requires a demonstration of identity by the holder, and wherein each of the subset of depending issuers generates and provides a reissued verifiable claim without user action.

6. The method of claim 1 , wherein the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder is reconstructed by tracing dependency chains in a backwards direction from a depending issuer from the plurality of issuers.

7. The method of claim 1 , wherein the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder is reconstructed by tracing dependency chains in a forward direction from a root issuer from the plurality of issuers.

8. The method of claim 1 , wherein each of the plurality of messages that is signed with the root credential is combined with user-specific information.

9. The method of claim 8 , wherein the user-specific information is biometric data.

10. The method of claim 8 , wherein the user-specific information is a user-provided password.

11. A system for restoring user credentials, the system comprising:

a hardware processor of a computing device that is configured to:

receive a request to locally restore a digital wallet of a holder associated with a digital wallet application executing on the computing device; and

restore the digital wallet by:

restoring a root credential;

transmitting a plurality of messages that are each signed with the root credential to a plurality of backup providers, wherein each of the plurality of backup providers has a portion of a graph of interdependencies, wherein the graph of interdependencies is between a plurality of issuers and a plurality of claims for the holder stored in a storage device and wherein the graph of interdependencies is unable to be reconstructed from the portion;

receiving a plurality of graph portions from at least a portion of the plurality of backup providers in response to each of the portion of the plurality of backup providers determining that the root credential is a correct root credential corresponding to the holder; and

reconstructing the graph of interdependencies using the plurality of received graph portions.

12. The system of claim 11 , wherein the hardware processor is further configured to transmit a request to each of the plurality of issuers in the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder, wherein the request includes at least one claim from the plurality of claims for the holder.

13. The system of claim 12 , wherein the hardware processor is further configured to:

receive, from an issuer device, derived credentials relating to a reissued verifiable claim; and

restore a claim in the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder with the reissued verifiable claim.

14. The system of claim 11 , wherein each of the plurality of claims is data demonstrating a property signed by an issuer.

15. The system of claim 11 , wherein the plurality of issuers include a subset of root issuers and a subset of depending issuers, wherein each of the subset of root issuers requires a demonstration of identity by the holder, and wherein each of the subset of depending issuers generates and provides a reissued verifiable claim without user action.

16. The system of claim 11 , wherein the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder is reconstructed by tracing dependency chains in a backwards direction from a depending issuer from the plurality of issuers.

17. The system of claim 11 , wherein the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder is reconstructed by tracing dependency chains in a forward direction from a root issuer from the plurality of issuers.

18. The system of claim 11 , wherein each of the plurality of messages that is signed with the root credential is combined with user-specific information.

19. The system of claim 18 , wherein the user-specific information is biometric data.

20. The system of claim 18 , wherein the user-specific information is a user-provided password.

21. A non-transitory computer-readable medium containing computer executable instructions that, when executed by a processor, cause the processor to perform a method for restoring user credentials, the method comprising:

receiving, using the processor, a request to locally restore a digital wallet of a holder associated with a digital wallet application executing on the computing device; and

restoring, using the processor, the digital wallet by:

restoring a root credential;

transmitting a plurality of messages that are each signed with the root credential to a plurality of backup providers, wherein each of the plurality of backup providers has a portion of a graph of interdependencies, wherein the graph of interdependencies is between a plurality of issuers and a plurality of claims for the holder and wherein the graph of interdependencies is unable to be reconstructed from the portion;

receiving a plurality of graph portions from at least a portion of the plurality of backup providers in response to each of the portion of the plurality of backup providers determining that the root credential is a correct root credential corresponding to the holder; and

reconstructing the graph of interdependencies using the plurality of received graph portions.

Assignments (1)
CONFIRMATORY ASSIGNMENT Recorded Nov 21, 2022
From: SIDEWALK LABS LLC
To: GOOGLE LLC
Reel/Frame 061972/0510 →
Continuity (3)
Continuation 16704602 · Dec 5, 2019
Provisional Application 62775887 · Dec 5, 2018
Related Publication 20210392126A1 · Dec 16, 2021