IP Library › Granted Patent US 12,309,303
Granted Patent B2
US 12,309,303 · App. 17/769,758 · Granted May 20, 2025

Verification requirement document for credential verification

Inventors: Chiahsin Li (San Jose, CA); Andrew Tully (Santa Clara, CA)
Assignee: TBCASOFT, INC.
H04L9/50H04L9/3218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,303
App. No.
17/769,758
Granted
May 20, 2025
Kind
B2
Abstract

The present disclosure is directed to a method and related apparatus and computer readable medium for credential verification using verification requirement document (VRD). A VRD credential verification ecosystem may include but is not limited to a VRD administration system, a first credential management system, a second credential management system, a VRD issuing device, a verifier device, a distributed VRD transaction consensus network, and a distributed credential management transaction consensus network with necessary communication among them.

Claims (37)

1. A method for a first credential management system using a verification requirement document (VRD) stored on a distributed VRD transaction consensus network to request credential verification of a credential owner, the method comprising:

(a) when receiving a VRD ID of the VRD and a credential owner identifier from a verifier device, the first credential management system sending the VRD ID to the distributed VRD transaction consensus network to retrieve the VRD, and sending the VRD and the credential owner identifier to a second credential management system, wherein the VRD includes at least one attribute, at least one predicate, or both at least one attribute and at least one predicate with a requirement defining at least one type of credential for verifying each of the at least one attribute and each of the at least one predicate specified in the VRD.

2. The method of claim 1 , further comprising:

(b) the first credential management system receiving a proof from the second credential management system and confirming if the proof satisfies the requirement associated with each of the at least one attribute and the at least one predicate specified in the VRD;

(c) when each requirement is satisfied, the first credential management system sending the proof and at least one of the at least one attribute and the at least one predicate specified in the VRD to a distributed credential management transaction consensus network for validation;

(d) upon receiving a verification response from the distributed credential management transaction consensus network, the first credential management system sending a credential verification result to the verifier device.

3. The method of claim 2 , further comprising: the second credential management system selecting at least one credential of the credential owner, which satisfies the requirement of each of the at least one attribute and the at least one predicate specified in the VRD, sending each of the at least one attribute and the at least one predicate specified in the VRD and a credential identifier of each of the at least one selected credential to the distributed credential management transaction consensus network, and sending the proof received from the distributed credential management transaction consensus network to the first credential management system.

4. The method of claim 2 , wherein the VRD has fields of VRD ID, VRD name, at least one of the at least one attribute and the at least one predicate, and DID of the VRD issuer.

5. The method as claimed in claim 4 , wherein each of the at least one attribute includes a corresponding requirement, an attribute name, and a reveal option, and the corresponding requirement defines the at least one type of credential of the credential owner and includes at least one search condition.

6. The method as claimed in claim 5 , wherein the at least one search condition comprises multiple search conditions that are combined by an OR Boolean operator.

7. The method as claimed in claim 5 , wherein when the reveal option of the at least one attribute specified in the VRD permits reveal, the proof includes a value or content of the at least one attribute.

8. The method as claimed in claim 5 , wherein when the reveal option of the at least one attribute specified in the VRD permits reveal, the verification result includes a value or content of the at least one attribute.

9. The method as claimed in claim 2 , wherein each of the at least one predicate specified in the VRD includes a corresponding requirement, a predicate name, a predicate character, a predicate attribute, a predicate value, and a predicate type, the corresponding requirement defines the at least one type of credential of the credential owner and includes at least one search condition.

10. The method as claimed in claim 9 , wherein the at least one search condition comprises multiple search conditions that are combined by an OR Boolean operator.

11. The method as claimed in claim 2 , wherein the proof includes a zero-knowledge proof corresponding to each of the at least one attribute and the at least one predicate specified in the VRD for verifying that the selected is valid and non-revoked.

12. The method of claim 1 , wherein the credential owner identifier comprises a credential owner ID and an identifier of the second credential management system associated with the credential owner.

13. The method as claimed in claim 1 , wherein the distributed VRD transaction consensus network and the distributed credential management transaction consensus network are blockchains.

14. The method as claimed in claim 1 , wherein the distributed VRD transaction consensus network and the distributed credential management transaction consensus network are separated networks.

15. The method as claimed in claim 1 , wherein the distributed VRD transaction consensus network is integrated into the distributed credential management transaction consensus network.

16. A distributed verification requirement document (VRD) transaction consensus network maintaining a distributed VRD ledger, the network comprises:

a VRD administration system provided by a VRD administer;

a first VRD management node provided by a first VRD operator;

a second VRD management node provided by a second VRD operator;

wherein a VRD administration system, the first VRD management node, and the second VRD administration are communicatively connected;

wherein after a VRD transaction is validated by a predetermined consensus of the distributed VRD transaction consensus network, the VRD transaction is published to the distributed VRD ledger, and the VRD transaction is one of VRD operator registering transaction, VRD operator revoking transaction, VRD issuer registering transaction, VRD issuer revoking transaction, VRD registering transaction, VRD revoking transaction, and VRD retrieving transaction; and

wherein the distributed VRD ledger records multiple VRDs and each VRD has fields of VRD ID, VRD name, at least one of at least one attribute and at least one predicate, and DID of the VRD issuer.

17. The network as claimed in claim 16 , wherein the VRD operator registering transaction comprises public key and DID of a VRD operator, and DID and signature of a VRD administer to publish a VRD operator.

18. The network as claimed in claim 16 , wherein the VRD operator revoking transaction comprises DID of a VRD operator, and DID and signature of a VRD administer who registered the VRD operator to revoke the VRD operator.

19. The network as claimed in claim 16 , wherein the VRD issuer registering transaction comprises public key and DID of a VRD issuer, and DID and signature of a VRD operator to publish the VRD issuer.

20. The network as claimed in claim 16 , wherein the VRD issuer revoking transaction includes DID of a VRD issuer, and DID and signature of a VRD operator who registered the VRD issuer to revoke the VRD issuer.

21. The network as claimed in claim 16 , wherein the VRD registering transaction has fields of VRD ID, VRD name, at least one of at least one attribute and at least one predicate, and DID and signature of a VRD issuer.

22. The network as claimed in claim 21 , wherein each of the at least one attribute specified in the VRD registering transaction includes a corresponding requirement, an attribute name, and a reveal option, and the corresponding requirement defines the at least one type of credential of the credential owner and includes at least one search condition.

23. The network as claimed in claim 22 , wherein the at least one search condition comprises multiple search conditions that are combined by an OR Boolean operator.

24. The network as claimed in claim 21 , wherein each of the at least one predicate specified in the VRD registering transaction includes a corresponding requirement, a predicate name, a predicate character, a predicate attribute, a predicate value, and a predicate type, and the corresponding requirement defines the at least one type of credential of the credential owner and includes at least one search condition.

25. The network as claimed in claim 24 , wherein the at least one search condition comprises multiple search conditions that are combined by an OR Boolean operator.

26. The network as claimed in claim 16 , wherein the VRD revoking transaction has fields of signature and DID of a VRD issuer that registered a VRD, and ID of the registered VRD.

27. The network as claimed in claim 16 , wherein the distributed VRD transaction consensus network is a blockchain.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2022
From: LI, CHIAHSIN; TULLY, ANDREW
To: TBCASOFT, INC.
Reel/Frame 059703/0307 →
Continuity (2)
Provisional Application 62923471 · Oct 18, 2019
Related Publication 20220294653A1 · Sep 15, 2022
References Cited (22)
US 20110289403A1 · McDonald · 2011 [cited by applicant]
US 20140281525A1 · Acar et al. · 2014 [cited by applicant]
US 20150244690A1 · Mossbarger · 2015 [cited by applicant]
US 20160239653A1 · Loughlin-Mchugh et al. · 2016 [cited by applicant]
US 20170230375A1 · Kurian · 2017 [cited by applicant]
US 20180083771A1 · Bonnell · 2018 [cited by applicant]
US 20180268151A1 · Cuomo et al. · 2018 [cited by applicant]
US 20180270065A1 · Brown et al. · 2018 [cited by applicant]
US 20190158298A1 · Muftic · 2019 [cited by applicant]
US 20190305949A1 · Hamel et al. · 2019 [cited by applicant]
CN 105264819A · 2016 [cited by applicant]
CN 105264819B · 2019 [cited by applicant]
CN 109446842A · 2019 [cited by applicant]
JP 2002163395A · 2002 [cited by applicant]
JP 2008228089A · 2008 [cited by applicant]
TW 201947482A · 2019 [cited by applicant]
TW 202029690A · 2020 [cited by applicant]
TW 202036345A · 2020 [cited by applicant]
Taiwan Intellectual Property Office mailed Search Report along with Reference List on Jul. 7, 2022, in Taiwan application No. 109141616, filed on Aug. 10, 2021. [cited by applicant]
Schanzenbach, M. et at. ZKlaims: Privacy-Preserving Attribute-Based Credentials Using Non-interactive Zero-knowledge Techniques. arXiv preprint arXiv:190709579(pp. 1-8). Jul. 22, 2019[retrieved on Dec. 15, 2020]. Retrie… [cited by applicant]
Wang, D. (editor) Technical Report FG DLT D5.1 Outlook on Distributed Ledger Technologies. ITU-T Focus Group on Application of Distributed Ledger Technology, International Telecommunication Union. Aug. 23, 2019. [retrie… [cited by applicant]
International Search Report and Written Opinion mailed on Jan. 25, 2021 in International Patent Application No. PCT/US2020/056388, filed on Oct. 19, 2020. [cited by applicant]
Cited By (1)
US 12,613,991