IP Library › Granted Patent US 12,015,720
Granted Patent B2
US 12,015,720 · App. 18/044,544 · Granted Jun 18, 2024

Integrating identity tokens and privacy-preserving identity attribute attestations into interactions

Inventors: Kim Wagner (Sunnyvale, CA); Brian Sullivan (Amersham, GB); Dinah Sloan (San Jose, CA); Hao Ngo (San Jose, CA); Gaven James Watson (Palo Alto, CA); Sunpreet Singh Arora (San Jose, CA); Saikrishna Badrinarayanan (Fremont, CA); Srinivasan Raghuraman (Cambridge, MA)
Assignee: Visa International Service Association
H04L9/3255H04L9/3066H04L9/3218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,015,720
App. No.
18/044,544
Granted
Jun 18, 2024
Kind
B2
Abstract

A method is disclosed. The method comprises receiving, by an identity network computer, a query set including a plurality of test identity attributes. After receiving the query set, the identity network computer may retrieve derivatives of identity attributes associated with a user, and an encrypted trapdoor, then compute an obscured query set using the query set, and optionally the derivatives of identity attributes. The identity network computer may transmit the obscured query set (i) and the encrypted trapdoor to a user device associated with the user, which generates and transmits a first modified trapdoor and the obscured query set to a relying party computer, or (ii) and a second modified trapdoor to the relying party computer. The relying party computer may thereafter use the obscured query set, and the first modified trapdoor or the second modified trapdoor, to determine if the identity attributes is a member of the query set.

Claims (28)

1. A method comprising:

receiving, by an identity network computer, a query set comprising a plurality of test identity attributes;

retrieving, by the identity network computer, one or more derivatives of one or more identity attributes associated with a user, and an encrypted trapdoor;

computing, by the identity network computer, an obscured query set using the query set, and the one or more derivatives of the one or more identity attributes associated with the user; and

transmitting, by the identity network computer, the obscured query set and the encrypted trapdoor to a user device associated with the user, which transmits a first modified trapdoor and the obscured query set to a relying party computer,

wherein the relying party computer uses the obscured query set, and the first modified trapdoor, to determine if the one or more the identity attributes of the one or more derivatives of the identity attributes is a member of the query set associated with the obscured query set.

2. The method of claim 1 , wherein the obscured query set is computed using a public key encryption with equality testing scheme.

3. The method of claim 1 , wherein the first modified trapdoor is a secret key.

4. The method of claim 1 , wherein the relying party computer uses a decrypt to zero function of an El-Gamal encryption scheme to determine if the one or more the identity attributes of the one or more derivatives of the identity attributes is a member of the query set associated with the obscured query set.

5. The method of claim 1 , wherein the query set comprises a range of ages or dates.

6. The method of claim 1 , wherein the one or more derivatives of one or more identity attributes associated with the user are encrypted identity attributes associated with the user.

7. The method of claim 1 , wherein the one or more derivatives of one or more identity attributes associated with the user are encrypted identity attributes received by the identity network computer from an identity provider computer.

8. The method of claim 1 , wherein after the relying party computer determines the one or more the identity attributes of the one or more derivatives of the identity attributes is a member of the query set associated with the obscured query set, a relying party operating the relying party computer provides access to a resource to the user.

9. The method of claim 1 , wherein the encrypted trapdoor is formed by an identity provider computer using a user public key associated with the user device.

10. The method of claim 1 , wherein the one or more derivatives of one or more identity attributes associated with the user are formed using one or more identity attributes associated with the user, and a nonce.

11. The method of claim 1 , wherein the obscured query set is formed by encrypting the plurality of test identity attributes of the query set with an ephemeral public key associated with the user device and permuting the encrypted test identity attributes of the query set.

12. The method of claim 1 , wherein the user device is a mobile phone.

13. An identity network computer comprising:

a processor; and

a non-transitory computer readable medium comprising instructions executable by the processor to perform operations including:

receiving, by the identity network computer, a query set comprising a plurality of test identity attributes;

retrieving, by the identity network computer, one or more derivatives of one or more identity attributes associated with a user, and an encrypted trapdoor;

computing, by the identity network computer, an obscured query set using the query set, and the one or more derivatives of the one or more identity attributes associated with the user; and

transmitting, by the identity network computer, the obscured query set and the encrypted trapdoor to a user device associated with the user, which transmits a first modified trapdoor and the obscured query set to a relying party computer,

wherein the relying party computer uses the obscured query set, and the first modified trapdoor, to determine if the one or more the identity attributes of the one or more derivatives of the identity attributes is a member of the query set associated with the obscured query set.

14. The identity network computer of claim 13 , wherein the obscured query set is computed using a public key encryption with equality testing scheme.

15. The identity network computer of claim 13 , wherein the first modified trapdoor is a secret key.

16. The identity network computer of claim 13 , wherein the encrypted trapdoor is formed by an identity provider computer using a user public key associated with the user device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2023
From: WAGNER, KIM; SULLIVAN, BRIAN; SLOAN, DINAH; NGO, HAO; WATSON, GAVEN JAMES; ARORA, SUNPREET SINGH; BADRINARAYANAN, SAIKRISHNA; RAGHURAMAN, SRINIVASAN
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 062968/0430 →
Continuity (3)
Provisional Application 63241495 · Sep 7, 2021
Provisional Application 63115475 · Nov 18, 2020
Related Publication 20230275766A1 · Aug 31, 2023
Cited By (1)
US 12,613,991