IP Library › Granted Patent US 12,259,960
Granted Patent B2
US 12,259,960 · App. 17/922,295 · Granted Mar 25, 2025

Derived child verifiable credential with selective claims

Inventors: Brandon Murdoch (Reading, GB); Ankur Patel (Sammamish, WA); Nithya Ganesh (Redmond, WA); Ronald John Kamiel Eurphrasia Bjones (Dilbeek, BE)
Assignee: Microsoft Technology Licensing, LLC
G06F21/36G06F21/62
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,259,960
App. No.
17/922,295
Granted
Mar 25, 2025
Kind
B2
Abstract

Permitting a claims holder to get a limited verifiable credential leveraging off of a previously-issued verifiable credential. This is done by having the limited verifiable credential include only a selected subset of the verifiable claims present within the previously-issued verifiable credential. The limited verifiable credential may then be exposed to a relying entity computing system so that the relying entity computing system can verify any of the selected subset of verifiable claims, but not verifiable claims that are outside of the selected subset of verifiable claims.

Claims (38)

1. A computing system for acquiring and using a verifiable credential so as to restrict access to one or more verifiable claims of another verifiable credential, the computing system comprising:

one or more processors; and

one or more hardware storage devices that store instructions that are executable by the one or more processors to cause the computing system to:

obtain a child verifiable credential that is derived from a parent verifiable credential and that includes a subset of verifiable claims that are in the parent verifiable credential, wherein the child verifiable credential is associated with usage data comprising an identity of a relying party to which the child verifiable credential was last exposed, wherein the subset of verifiable claims are represented by a data structure that includes a property name and a value for at least some verifiable claims in the subset of verifiable claims, and wherein obtaining the child verifiable credential includes:

selecting the subset of verifiable claims from the parent verifiable credential;

causing a request to be transmitted to a claims issuer computing system for the child verifiable credential that includes the selected subset of verifiable claims to be generated from the parent verifiable credential; and

detecting receipt of the requested child verifiable credential; and

expose the received child verifiable credential to a relying entity computing system so that the relying entity computing system can verify any of the selected subset of verifiable claims.

2. The computing system of claim 1 , at least one of the subset of verifiable claims having a subject referenced by a decentralized identifier.

3. The computing system of claim 1 , wherein the instructions are further executable to cause the computing system to:

use the data structure to cause a visual representation to be displayed to a user, the visual representation representing the property name and the value for each of the subset of verifiable claims.

4. The computing system of claim 3 , the visual representation comprising a human readable visual representation of the property name and the value for each of the subset of verifiable claims.

5. The computing system of claim 4 , wherein a first value for a first property name includes a location that points to a second value for the first property name.

6. The computing system of claim 1 , wherein the instructions are further executable to cause the computing system to:

use the data structure to cause a visual representation to be displayed to a user, the visual representation representing the property name and the value for each of the subset of verifiable claims, the visual representation comprising a human readable visual representation of the property name and the value for each of the subset of verifiable claims.

7. The computing system of claim 3 , the visual representation comprising a bar code or quick response (QR) code representation of instructions for verifying one or more of the verifiable claims.

8. The computing system of claim 3 , wherein selecting the subset of verifiable claims occurs in response to detecting predetermined user interaction with the visual representation.

9. The computing system of claim 8 , wherein the child verifiable credential is associated with usage data, and wherein the usage data comprises frequency with which the child verifiable credential is exposed to relying party computing systems.

10. The computing system of claim 8 , wherein the child verifiable credential is associated with usage data, and wherein the usage data comprises a time that the child verifiable credential was last exposed.

11. The computing system of claim 3 , the data structure further comprising usage data about the data structure.

12. The computing system of claim 1 , wherein the parent verifiable credential includes a plurality of verifiable claims, which includes the subset of verifiable claims, and wherein each verifiable claim in the plurality of verifiable claims includes a corresponding proof instruction that is usable to verify that said each verifiable claim has not been tampered.

13. The computing system of claim 12 , wherein at least one of the proofs is a digital signature.

14. The computing system of claim 1 , wherein the parent verifiable credential is included in a portable identity card.

15. A method for acquiring and using a child verifiable credential that includes a selected subset of verifiable claims that are present within a parent verifiable credential from which the child verifiable credential is derived, the method comprising:

obtaining a child verifiable credential that is derived from a parent verifiable credential and that includes a subset of verifiable claims that are in the parent verifiable credential, wherein the child verifiable credential is associated with usage data comprising an identity of a relying party to which the child verifiable credential was last exposed, wherein the subset of verifiable claims are represented by a data structure that includes a property name and a value for at least some verifiable claims in the subset of verifiable claims, and wherein obtaining the child verifiable credential includes:

selecting the subset of verifiable claims from the parent verifiable credential;

causing a request to be transmitted to a claims issuer computing system for the child verifiable credential that includes the selected subset of verifiable claims to be generated from the parent verifiable credential; and

detecting receipt of the requested child verifiable credential; and

exposing the received child verifiable credential to a relying entity computing system so that the relying entity computing system can verify any of the selected subset of verifiable claims.

16. The method of claim 15 , at least one of the subset of verifiable claims having a subject referenced by a decentralized identifier.

17. The method of claim 15 , the method further comprising:

using the data structure to cause a visual representation to be displayed to a user, the visual representation representing the property name and the value for each of the subset of verifiable claims.

18. One or more hardware storage devices that store instructions that are executable by one or more processors to cause the one or more processors to:

obtain a child verifiable credential that is derived from a parent verifiable credential and that includes a subset of verifiable claims that are in the parent verifiable credential, wherein the child credential is associated with usage data comprising an identity of a relying party to which the child verifiable credential was last exposed, wherein the subset of verifiable claims are represented by a data structure that includes a property name and a value for at least some verifiable claims in the subset of verifiable claims, and wherein obtaining the child verifiable credential includes:

selecting the subset of verifiable claims from the parent verifiable credential;

causing a request to be transmitted to a claims issuer computing system for the child verifiable credential that includes the selected subset of verifiable claims to be generated from the parent verifiable credential; and

detecting receipt of the requested child verifiable credential; and

expose the received child verifiable credential to a relying entity computing system so that the relying entity computing system can verify any of the selected subset of verifiable claims.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2022
From: MURDOCH, BRANDON; PATEL, ANKUR; GANESH, NITHYA; BJONES, RONALD JOHN KAMIEL EURPHRASIA
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 061618/0732 →
Priority Claims (1)
LU 101755 · Apr 28, 2020 · national
Continuity (1)
Related Publication 20230177137A1 · Jun 8, 2023
References Cited (26)
US 9300644B1 · Dubey · 2016 [cited by examiner]
US 9411892B2 · Ravid · 2016 [cited by examiner]
US 9608993B1 · Camenisch · 2017 [cited by examiner]
US 11038883B2 · Yang · 2021 [cited by examiner]
US 20040056087A1 · Bonneau, Jr. · 2004 [cited by examiner]
US 20090089870A1 · Wahl · 2009 [cited by examiner]
US 20140181927A1 · Sarkissian · 2014 [cited by examiner]
US 20140281525A1 · Acar · 2014 [cited by examiner]
US 20160352717A1 · Shewchuk · 2016 [cited by examiner]
US 20160378741A1 · Mullins · 2016 [cited by examiner]
US 20170124303A1 · Baldwin · 2017 [cited by examiner]
US 20170149563A1 · Camenisch · 2017 [cited by examiner]
US 20180189738A1 · Ramaswamy · 2018 [cited by examiner]
US 20180300217A1 · Doggett · 2018 [cited by examiner]
US 20180357562A1 · Hofman · 2018 [cited by examiner]
US 20190087829A1 · Mercury · 2019 [cited by examiner]
US 20190222424A1 · Lindemann · 2019 [cited by examiner]
US 20190230073A1 · Patel et al. · 2019 [cited by applicant]
US 20200076601A1 · Tabrizi · 2020 [cited by examiner]
US 20210036866A1 · Zolfonoon · 2021 [cited by examiner]
US 20210174914A1 · Cano · 2021 [cited by examiner]
Verifiable Credentials Data Model 1.0 (Sporny) (Year: 2019). [cited by examiner]
NPL Search History (Year: 2024). [cited by examiner]
“Search Report Issued in Luxembourg Patent Application No. LU101755”, Mailed Date: Nov. 18, 2020, 7 Pages. (MS# 407870-LU-NP). [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US21/029442”, Mailed Date: Aug. 13, 2021, 11 Pages. (MS# 407870-WO-PCT). [cited by applicant]
Communication pursuant to Article 94(3) EPC, Received for European Application No. 21726013.2, (MS# 407870-EP01-PCT) mailed on Jun. 4, 2024, 8 pages. [cited by applicant]