IP Library › Granted Patent US 12,316,778
Granted Patent B2
US 12,316,778 · App. 17/653,117 · Granted May 27, 2025

Privacy-preserving user certificates

Inventors: Alessandro Sorniotti (Zurich, CH); Elli Androulaki (Zurich, CH); Ilie Circiumaru (Zurich, CH); Jesus Diaz Vico (Madrid, ES); Marko Vukolić (Zurich, CH)
Assignee: International Business Machines Corporation
H04L9/3263G06F21/36G06F21/6245H04L9/3236H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,778
App. No.
17/653,117
Granted
May 27, 2025
Kind
B2
Abstract

A method, system, and computer program product are disclosed. The method includes separating a user certificate into a private component and a non-private component. The method further includes storing the non-private component in a database and providing a pointer to the non-private component stored in the database.

Claims (48)

1. A method, comprising:

issuing a digitally-signed assertion, the issuing comprising:

receiving user data;

separating the user data into a private component and a non-private component, wherein the separating comprises:

determining, based on a size of an area, an amount of the user data that can be encoded in the area; and

selecting, from the user data, data for the private component based on the determined amount and a categorization of the user data;

encoding the private component and a nonce in the area as a barcode;

separately from the barcode, storing the non-private component and a digital signature in a database; and

generating a user certificate comprising the barcode and a pointer to the non-private component in the database.

2. The method of claim 1 , wherein the issuing further comprises deriving the pointer deterministically from the private component.

3. The method of claim 2 , wherein the pointer is derived by means of a cryptographic hash of the private component.

4. The method of claim 1 , wherein the barcode is a 2-dimensional barcode.

5. The method of claim 1 , wherein the database is embodied as a centralized storage or a decentralized storage.

6. The method of claim 1 , wherein the private component comprises data selected from the group consisting of personally identifiable information and demographics data.

7. The method of claim 1 , wherein the non-private component comprises data selected from the group consisting of an issuer identity, and non-personally identifiable information.

8. The method of claim 1 , the issuing further comprising augmenting the non-private component with verification data of a proof system, wherein the proof system is configured to enable a verifier of the user certificate to prove knowledge of at least a subset of the private component corresponding to the pointer.

9. The method of claim 1 , wherein the pointer can be derived from the private component by a verification device, and wherein the verification device can submit the pointer to an access software that, in response, provides the non-private component.

10. The method of claim 9 , wherein the access software provides the non-private component only upon verification of a proof demonstrating knowledge of at least a subset of the private component.

11. The method of claim 10 , wherein the proof comprises a zero-knowledge proof.

12. The method of claim 1 , wherein the categorization of the user data is based on whether or not the data is personal identifying information.

13. The method of claim 1 , wherein the issuing further comprises:

estimating a minimum entropy of the data selected for the private component; and

determining a size of a nonce field for the nonce in the private component based on the minimum entropy.

14. The method of claim 1 , wherein the issuing further comprises computing the digital signature based on the user data and the nonce.

15. A system, comprising:

a memory; and

a processor communicatively coupled to the memory, wherein the processor is configured to perform a method of issuing a digitally-signed assertion, the method comprising:

receiving user data;

computing a digital signature on the user data and a nonce;

separating the user data into a private component and a non-private component, wherein the separating comprises:

determining, based on a size of an area, an amount of the user data that can be encoded in the area; and

selecting, from the user data, data for the private component based on the determined amount and a categorization of the user data;

encoding the private component and the nonce in the area as a barcode;

separately from the barcode, storing the non-private component and the digital signature in a database; and

generating a user certificate comprising, the barcode and a pointer to the non-private component in the database.

16. The system of claim 15 , wherein the storing further comprises augmenting the non-private component with verification data of a proof system, and wherein the proof system is configured to enable a verifier of the user certificate to prove knowledge of at least a subset of the private component corresponding to the pointer.

17. The system of claim 15 , wherein the pointer can be derived from the private component by a verification device, and wherein the verification device can submit the pointer to an access software of the database that, in response, provides the non-private component.

18. The system of claim 17 , wherein the access software provides the non-private component only upon verification of a proof demonstrating knowledge of at least a subset of the private component.

19. A computer program product, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause a device to perform a method of issuing a digitally-signed assertion, the method comprising:

receiving user data;

computing a digital signature on the user data and a nonce;

separating the user data into a private component and a non-private component, wherein the separating comprises:

determining, based on a size of an area, an amount of the user data that can be encoded in the area; and

selecting, from the user data, data for the private component based on the determined amount and a categorization of the data;

encoding the private component and the nonce in the area as a barcode;

separately storing the non-private component and the digital signature in a database; and

generating a user certificate comprising the barcode and a pointer to the non-private component in the database.

20. The computer program product of claim 19 , wherein the issuing further comprises generating the pointer by hashing the private component or a subset of the private component.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2022
From: SORNIOTTI, ALESSANDRO; ANDROULAKI, ELLI; CIRCIUMARU, ILIE; DIAZ VICO, JESUS; VUKOLIC, MARKO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 059139/0611 →
Continuity (1)
Related Publication 20230283484A1 · Sep 7, 2023
References Cited (17)
US 9094379B1 · Miller · 2015 [cited by applicant]
US 20110119400A1 · Manion · 2011 [cited by examiner]
US 20130276084A1 · Canard · 2013 [cited by examiner]
US 20140254796A1 · Li · 2014 [cited by examiner]
US 20150082387A1 · Ciancio-Bunch · 2015 [cited by examiner]
US 20190192977A1 · Eatedali · 2019 [cited by examiner]
US 20200372507A1 · Liu · 2020 [cited by examiner]
US 20210152364A1 · Beecham · 2021 [cited by examiner]
US 20220393883A1 · Panchamia · 2022 [cited by examiner]
Jose Rouillard, Contextual QR Codes, 2008, IEEE, pp. 50-54 (Year: 2008). [cited by examiner]
Salahuddin Ahamed, A Secure QR Code System for Sharing Personal Confidential Information, 2019, IEEE, pp. 1-4 (Year: 2019). [cited by examiner]
Ahamed et al., “A Secure QR Code System for Sharing Personal Confidential Information,” https://www.researchgate.net/profile/Hossen-Mustafa/publication/339975365, International Conference on Computer, Communication, Che… [cited by applicant]
Buch, H., “Establishing blockchain privacy through Zero Knowledge Proof,” https://www.wipro.com/blogs/hitarshi-buch/establishing-blockchain-privacy-through-zero-knowledge-proof/, Jun. 2019, 10 pgs. [cited by applicant]
Chuang et al., “A Novel Secret Sharing Technique Using QR Code,” https://www.researchgate.net/publication/49603949, International Journal of Image Processing (IJIP), vol. (4): Issue (5), 9 pgs. [cited by applicant]
Ilaiyaraja et al., “Secured Message Transfer through QR Code Process for Document Authentication Systems,” https://www.researchgate.net/publication/331646269, International Journal of Emerging Technology in Computer Sci… [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing,” Recommendations of the National Institute of Standards and Technology, U.S. Department of Commerce, Special Publication 800-145, Sep. 2011, 7 pgs. [cited by applicant]
Rouillard, J., “Contextual QR Codes,” https://www.researchgate.net/publication/4362876, Conference Paper, Jul. 2008, 7 pgs. [cited by applicant]
Cited By (2)
US 12,712,753 US 12,731,199