IP Library Granted Patent US 12,401,509
Granted Patent B2
US 12,401,509 · App. 17/793,901 · Granted Aug 26, 2025

Issuing verifiable pairwise claims

Inventor: Kim Cameron (Toronto, CA)
Assignee: Microsoft Technology Licensing, LLC
H04L9/3073H04L9/0825H04L9/3236H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,509
App. No.
17/793,901
Granted
Aug 26, 2025
Kind
B2
Abstract

Generating a verifiable pairwise claim. Receiving a request for issuing a verifiable claim that is associated with a subject entity and is verifiable by one or more verifying entities. The request includes at least an encrypted portion using a particular type of encryptography. Verifying that the subject entity is associated with a subject of the verifiable claim based on decrypting the encrypted portion using the particular type of cryptography. In response to verifying that the subject entity is associated with the subject of the verifiable claim, issuing the verifiable claim that is structured to be verifiable only by the one or more verifying entities.

Claims (72)

1. A computing system for issuing and managing verifiable claims, comprising:

one or more processors; and

one or more computer-readable media having thereon computer-executable instructions that are executable by the one or more processors to cause the computing system to:

receive a first request for issuing a first pairwise verifiable claim that is associated with a subject entity and that is verifiable by a first verifying entity, the first request including at least an encrypted portion using a particular type of cryptography;

based on receiving the first request:

verify that the subject entity is a subject of the first pairwise verifiable claim based on decrypting the encrypted portion using the particular type of cryptography; and

in response to verifying that the subject entity is the subject of the first pairwise verifiable claim, issue the first pairwise verifiable claim to the first verifying entity, including encrypting the first pairwise verifiable claim using a first cryptographic public key uniquely associated with the first verifying entity, allowing decryption solely by a first private key of the first verifying entity;

receive a second request for issuing a second pairwise verifiable claim associated with the subject entity, and that is verifiable by a second verifying entity, the second request including at least an encrypted portion using a particular type of cryptography; and

based on receiving the second request:

verify the subject entity as the subject of the second pairwise verifiable claim based on decrypting the encrypted portion using the particular type of cryptography; and

in response to verifying that the subject entity is the subject of the second pairwise verifiable claim, issue the second pairwise verifiable claim to the second verifying entity, including encrypting the second pairwise verifiable claim using a second cryptographic public key uniquely associated with the second verifying entity, allowing decryption solely by a second private key of the second verifying entity,

wherein the first pairwise verifiable claim and the second pairwise verifiable claim are issued to their respective verifying entities using a same decentralized identifier (DID) of the subject entity.

2. The computing system of claim 1 , wherein the computer-executable instructions are also executable by the one or more processors to cause the computing system to:

impose a condition for accessing a verifiable claim; and

when a requesting entity requests for accessing the verifiable claim, determine whether the condition is met.

3. The computing system of claim 2 , wherein the computer-executable instructions are also executable by the one or more processors to cause the computing system to:

in response to a determination that the condition is met, send the verifiable claim to the subject entity; and

cause the subject entity to pass on the verifiable claim to the requesting entity.

4. The computing system of claim 2 , wherein the computer-executable instructions are also executable by the one or more processors to cause the computing system to:

in response to a determination that the condition is met, send the verifiable claim to the requesting entity directly.

5. The computing system of claim 2 , wherein:

the condition includes verifying that an identity of the requesting entity is one of one or more predetermined verifying entities.

6. The computing system of claim 5 , wherein:

at least one verifying entity is associated with a decentralized identifier (DID), and

verifying the identity of the requesting entity includes verifying that the requesting entity is a holder of the DID.

7. The computing system of claim 2 , wherein the condition comprises receiving an amount of anonymous digital asset.

8. The computing system of claim 2 , wherein the condition comprises a predetermined number of times that the verifiable claim is allowed to be accessed and/or an expiration time for allowing the verifiable claim to be accessed.

9. The computing system of claim 2 , wherein the computer-executable instructions are also executable by the one or more processors to cause the computing system to encrypt the verifiable claim by one or more keys to create an encrypted verifiable claim.

10. The computing system of claim 9 , wherein the one or more keys includes a public key of a verifying entity, so that the encrypted verifiable claim can only be decrypted by a private key of the verifying sentity.

11. The computing system of claim 9 , wherein the computer-executable instructions are also executable by the one or more processors to cause the computing system to:

the encrypted verifiable claim to the subject entity; and

cause the subject entity to pass on the verifiable claim to a verifying entity.

12. The computing system of claim 9 , wherein the computer-executable instructions are also executable by the one or more processors to cause the computing system to:

receive a request for accessing the encrypted verifiable claim from a requesting entity;

determine whether the condition is met; and

in response to a determination that the condition is met, cause the requesting entity to receive the one or more keys.

13. The computing system of claim 1 , wherein the computer-executable instructions are also executable by the one or more processors to cause the computing system to:

impose a second condition for issuing the verifiable claim; and

when a request for issuing the verifiable claim is received, determine whether the second condition is met.

14. In a computing system that includes one or more processors, a method comprising:

receiving a first request for issuing a first pairwise verifiable claim that is associated with a subject entity and that is verifiable by a first verifying sentity, the first request including at least an encrypted portion using a particular type of cryptography;

based on receiving the first request:

verifying that the subject entity is a subject of the first pairwise verifiable claim based on decrypting the encrypted portion using the particular type of cryptography; and

in response to verifying that the subject entity is the subject of the first pairwise verifiable claim, issuing the first pairwise verifiable claim to the first verifying entity, including encrypting the first pairwise verifiable claim using a first cryptographic public key uniquely associated with the first verifying entity, allowing decryption solely by a first private key of the first verifying entity;

receive a second request for issuing a second pairwise verifiable claim associated with the subject entity, and that is verifiable by a second verifying entity, the second request including at least an encrypted portion using a particular type of cryptography; and

based on receiving the second request:

verify the subject entity as the subject of the second pairwise verifiable claim based on decrypting the encrypted portion using the particular type of cryptography; and

in response to verifying that the subject entity is the subject of the second pairwise verifiable claim, issue the second pairwise verifiable claim to the second verifying entity, including encrypting the second pairwise verifiable claim using a second cryptographic public key uniquely associated with the second verifying entity, allowing decryption solely by a second private key of the second verifying entity,

wherein the first pairwise verifiable claim and the second pairwise verifiable claim are issued to their respective verifying entities using a same decentralized identifier (DID) of the subject entity.

15. The method of claim 14 , further comprising:

imposing a condition for accessing a verifiable claim; and

when a requesting entity requests for accessing the verifiable claim, determining whether the condition is met.

16. The method of claim 15 , further comprising:

in response to a determination that the condition is met, sending the verifiable claim to the subject entity; and

causing the subject entity to pass on the verifiable claim to the requesting entity.

17. The method of claim 15 , further comprising:

in response to a determination that the condition is met, sending the verifiable claim to the requesting entity directly.

18. The method of claim 15 , wherein:

the condition includes verifying that an identity of the requesting entity is one of one or more predetermined verifying entities.

19. The method of claim 18 , wherein:

at least one verifying entity is associated with a decentralized identifier (DID), and

verifying the identity of the requesting entity includes verifying that the requesting entity is a holder of the DID.

20. A computer-readable physical storage medium having stored thereon computer-executable instructions that are structured such that, when executed by one or more processors, the computer-executable instructions cause a computing system to at least:

receive a first request for issuing a first pairwise verifiable claim that is associated with a subject entity and that is verifiable by a first verifying entity, the first request including at least an encrypted portion using a particular type of cryptography;

based on receiving the first request:

verify that the subject entity is a subject of the first pairwise verifiable claim based on decrypting the encrypted portion using the particular type of cryptography; and

in response to verifying that the subject entity is the subject of the first pairwise verifiable claim, issue the first pairwise verifiable claim to the first verifying entity, including encrypting the first pairwise verifiable claim using a first cryptographic public key uniquely associated with the first verifying entity, allowing decryption solely by a first private key of the first verifying entity;

receive a second request for issuing a second pairwise verifiable claim associated with the subject entity, and that is verifiable by a second verifying entity, the second request including at least an encrypted portion using a particular type of cryptography; and

based on receiving the second request:

verify the subject entity as the subject of the second pairwise verifiable claim based on decrypting the encrypted portion using the particular type of cryptography; and

in response to verifying that the subject entity is the subject of the second pairwise verifiable claim, issue the second pairwise verifiable claim to the second verifying entity, including encrypting the second pairwise verifiable claim using a second cryptographic public key uniquely associated with the second verifying entity, allowing decryption solely by a second private key of the second verifying entity,

wherein the first pairwise verifiable claim and the second pairwise verifiable claim are issued to their respective verifying entities using a same decentralized identifier (DID) of the subject entity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2022
From: CAMERON, KIM
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 061002/0844 →
Priority Claims (1)
LU LU101620 · Jan 30, 2020 · national
Continuity (1)
Related Publication 20230050460A1 · Feb 16, 2023
References Cited (29)
US 10938562B2 · Liu · 2021 [cited by examiner]
US 11050572B2 · Steele · 2021 [cited by examiner]
US 11245524B2 · Murdoch · 2022 [cited by examiner]
US 20190222424A1 · Lindemann · 2019 [cited by applicant]
US 20190229909A1 · Patel · 2019 [cited by examiner]
US 20200042958A1 · Soundararajan · 2020 [cited by examiner]
US 20200127828A1 · Liu · 2020 [cited by examiner]
US 20200127847A1 · Yang · 2020 [cited by examiner]
US 20200145209A1 · Yang · 2020 [cited by examiner]
US 20200211099A1 · Smith · 2020 [cited by examiner]
US 20200313897A1 · Heath · 2020 [cited by examiner]
US 20200401734A1 · Murdoch · 2020 [cited by examiner]
US 20200403795A1 · Murdoch · 2020 [cited by examiner]
US 20210126785A1 · Liu · 2021 [cited by examiner]
US 20210314293A1 · Soundararajan · 2021 [cited by examiner]
US 20220385475A1 · Murdoch · 2022 [cited by examiner]
US 20230050460A1 · Cameron · 2023 [cited by examiner]
US 20230177174A1 · Murdoch · 2023 [cited by examiner]
CN 106254069A · 2016 [cited by applicant]
CN 110224837A · 2019 [cited by applicant]
WO 2019179533A2 · 2019 [cited by applicant]
Aydar, et al., “Towards a Blockchain based digital identity verification, record attestation and record sharing system”, In Repository of arXiv:1906.09791v1, Jun. 24, 2019, 25 Pages. [cited by applicant]
Barbir, et al., “Updated text of draft Recommendation ITUT X.1252 Baseline identity management terms and definitions”, In Telecommunication Standardization Sector of ITU, Jan. 2019, 27 Pages. [cited by applicant]
“Search Report and Written Opinion Issued in Luxembourg Patent Application No. LU101620”, Mailed Date: Sep. 18, 2020, 11 Pages. [cited by applicant]
Muhle, et al., “A Survey on Essential Components of a Self-Sovereign Identity”, In Repository of arXiv:1807.06346v1, Jul. 17, 2018, 7 Pages. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US21/015498”, Mailed Date: Apr. 23, 2021, 13 Pages. [cited by applicant]
First Examination Report Received for Indian Application No. 202217039801, mailed on Apr. 16, 2025, 06 Pages. [cited by applicant]
Aydar, et al., “Towards a Blockchain based digital identity verification, record attestation and record sharing system”, arXiv:1906.09791v1, Jun. 24, 2019, 26 pages. [cited by applicant]
First Office Action Received for Chinese Application No. 202180012037.4, mailed on May 20, 2025, 18 pages. (English translation Provided). [cited by applicant]