IP Library Granted Patent US 12,739,121
Granted Patent B2
US 12,739,121 · App. 18/674,400 · Granted Sep 15, 2026

Privacy-preserving identity attribute verification using policy tokens

Inventors: Kim Ritter Wagner (Sunnyvale, CA); Sunpreet Singh Arora (Union City, CA); Gaven James Watson (Palo Alto, CA); Mihai Christodorescu (Belmont, CA); Shashank Agrawal (Sunnyvale, CA)
Assignee: Visa International Service Association
H04L9/3213H04L9/0825H04L9/0866H04L9/3221H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,121
App. No.
18/674,400
Filed
May 24, 2024
Granted
Sep 15, 2026
Kind
B2
Examiner
KORSAK, OLEG
Art Unit
2492
USPC
726/9
Abstract

Methods and systems for privacy-preserving identity attribute verification are presented. During an interaction between a relying entity and a user, a relying entity computer can transmit a policy token to a user device. The policy token may indicate the information needed by the relying entity in order to perform the interaction. The user device can verify the policy token, then use the policy token in conjunction with an identity token to generate a zero-knowledge proof. The user device may transmit the zero-knowledge proof to an identity service provider computer. The identity service provider computer may verify the zero-knowledge proof, then generate a verification message. The identity service provider computer may sign the verification message and transmit the signed verification message to the relying entity computer. The relying entity computer may verify the verification message and complete the interaction with the user.

Claims (45)

1 . A method comprising:

providing, by a relying party computer to a user device, a policy token, wherein the user device generates a zero-knowledge proof using the policy token and a set of identity attributes stored on the user device and transmits the zero-knowledge proof to an identity service provider computer, which verifies the zero-knowledge proof and generates a verification message;

receiving, by the relying party computer, the verification message; and

performing, by the relying party computer, an interaction with the user device based on the verification message.

2 . The method of claim 1 , wherein the policy token is cryptographically signed using a private key corresponding to a token server computer, and wherein the user device verifies the policy token using a public key corresponding to the token server computer.

3 . The method of claim 1 , further comprising:

receiving, by the relying party computer from the identity service provider computer, the policy token.

4 . The method of claim 1 , further comprising:

transmitting, by the relying party computer to the user device, a nonce along with the policy token; and

receiving, by the relying party computer from the identity service provider computer, the nonce in the verification message.

5 . The method of claim 4 , wherein the nonce and a verification result in the verification message are signed using a secret key of the identity service provider computer.

6 . The method of claim 5 , further comprising:

verifying, by the relying party computer, the signed nonce and the verification result in the verification message with a public key corresponding to the secret key.

7 . The method of claim 1 , wherein the zero-knowledge proof is used to verify that a user of the user device is of a certain age.

8 . The method of claim 1 , wherein the identity service provider computer verifies the zero-knowledge proof using two sub-verifiers.

9 . The method of claim 1 , wherein the policy token is provided by the relying party computer to the user device via NFC or a QR code.

10 . The method of claim 1 , wherein the policy token comprises one or more predicates, wherein each predicate corresponds to one or more identity attributes from the set of identity attributes, and wherein the zero-knowledge proof corresponds to the one or more predicates and the set of identity attributes.

11 . A relying party computer comprising:

a processor; and

a non-transitory computer readable medium coupled to the processor, the non-transitory computer readable medium comprising code, executable by the processor, for implementing a method comprising:

providing, to a user device, a policy token, wherein the user device generates a zero-knowledge proof using the policy token and a set of identity attributes stored on the user device and transmits the zero-knowledge proof to an identity service provider computer, which verifies the zero-knowledge proof and generates a verification message;

receiving the verification message; and

performing, by the relying party computer, an interaction with the user device based on the verification message.

12 . The relying party computer of claim 11 , wherein the policy token is cryptographically signed using a private key corresponding to a token server computer.

13 . The relying party computer of claim 11 , wherein the method further comprises:

receiving, by the relying party computer from the identity service provider computer, the policy token.

14 . The relying party computer of claim 11 , wherein the method further comprises:

transmitting, by the relying party computer to the user device, a nonce along with the policy token; and

receiving, by the relying party computer from the identity service provider computer, the nonce in the verification message.

15 . The relying party computer of claim 11 , wherein the policy token is provided by the relying party computer to the user device via NFC or a QR code.

16 . The relying party computer of claim 11 , wherein the policy token comprises one or more predicates, wherein each predicate corresponds to one or more identity attributes from the set of identity attributes, and wherein the zero-knowledge proof corresponds to the one or more predicates and the set of identity attributes.

17 . A system comprising:

a relying party computer comprising

a processor, and

a non-transitory computer readable medium coupled to the processor, the non-transitory computer readable medium comprising code, executable by the processor, for implementing a method comprising

providing, to a user device, a policy token, wherein the user device generates a zero-knowledge proof using the policy token and a set of identity attributes stored on the user device and transmits the zero-knowledge proof to an identity service provider computer, which verifies the zero-knowledge proof and generates a verification message,

receiving the verification message, and

performing, by the relying party computer, an interaction with the user device based on the verification message; and

the user device.

18 . The system of claim 17 , further comprising:

the identity service provider computer.

19 . The system of claim 17 , wherein the method further comprises:

transmitting, by the relying party computer to the user device, a nonce along with the policy token; and

receiving, by the relying party computer from the identity service provider computer, the nonce in the verification message.

20 . The system of claim 17 , wherein the policy token comprises one or more predicates, wherein each predicate corresponds to one or more identity attributes from the set of identity attributes, and wherein the zero-knowledge proof corresponds to the one or more predicates and the set of identity attributes.

Continuity (2)
Continuation 16928367 · Jul 14, 2020
Related Publication 20240313971A1 · Sep 19, 2024
References Cited (64)
US 10505733B2 · Rowe et al. · 2019 [cited by applicant]
US 10692085B2 · Zagarese et al. · 2020 [cited by applicant]
US 10915890B2 · Douglas et al. · 2021 [cited by applicant]
US 11121873B2 · Schmaltz · 2021 [cited by examiner]
US 11212102B2 · Ortiz et al. · 2021 [cited by applicant]
US 11716617B2 · Wentz · 2023 [cited by examiner]
US 12028455B2 · Wagner · 2024 [cited by examiner]
US 12242652B2 · Buck · 2025 [cited by examiner]
US 20070192619A1 · Gifford et al. · 2007 [cited by applicant]
US 20080229383A1 · Buss et al. · 2008 [cited by applicant]
US 20080289020A1 · Cameron et al. · 2008 [cited by applicant]
US 20100199089A1 · Vysogorets et al. · 2010 [cited by applicant]
US 20110202991A1 · Paquin et al. · 2011 [cited by applicant]
US 20110296512A1 · Dietrich et al. · 2011 [cited by applicant]
US 20130014207A1 · Hodgkinson et al. · 2013 [cited by applicant]
US 20130036456A1 · Boysen et al. · 2013 [cited by applicant]
US 20130276087A1 · Bjones et al. · 2013 [cited by applicant]
US 20130276131A1 · Bjones · 2013 [cited by examiner]
US 20150058950A1 · Miu · 2015 [cited by applicant]
US 20170250972A1 · Ronda et al. · 2017 [cited by applicant]
US 20180165781A1 · Rodriguez et al. · 2018 [cited by applicant]
US 20180173906A1 · Rodriguez et al. · 2018 [cited by applicant]
US 20180181964A1 · Zagarese et al. · 2018 [cited by applicant]
US 20180189780A1 · Douglas et al. · 2018 [cited by applicant]
US 20190097802A1 · Rowe et al. · 2019 [cited by applicant]
US 20190149524A1 · Bankston et al. · 2019 [cited by applicant]
US 20190158487A1 · Hayes et al. · 2019 [cited by applicant]
US 20190164151A1 · Doney et al. · 2019 [cited by applicant]
US 20190372993A1 · Dunjic et al. · 2019 [cited by applicant]
US 20200014537A1 · Ortiz et al. · 2020 [cited by applicant]
US 20200067907A1 · Avetisov et al. · 2020 [cited by applicant]
US 20200084036A1 · Rowe et al. · 2020 [cited by applicant]
US 20200162251A1 · Wentz · 2020 [cited by applicant]
US 20200169879A1 · Linton et al. · 2020 [cited by applicant]
US 20200186352A1 · Arora et al. · 2020 [cited by applicant]
US 20200220870A1 · Wagner et al. · 2020 [cited by applicant]
US 20200259652A1 · Schmaltz, III et al. · 2020 [cited by applicant]
US 20200280550A1 · Lindemann et al. · 2020 [cited by applicant]
US 20210065267A1 · Smith et al. · 2021 [cited by applicant]
US 20210320799A1 · Bankston · 2021 [cited by applicant]
US 20210326426A1 · Bouse · 2021 [cited by applicant]
US 20220174494A1 · Richardson · 2022 [cited by examiner]
JP 2019503541A · 2019 [cited by applicant]
WO 2019217936A1 · 2019 [cited by applicant]
Camenisch et al., (Concepts and Languages for Privacy-Preserving Attribute-Based Authentication, IFIP AICT 396, p. 34â52, 2013) (Year: 2013). [cited by examiner]
U.S. Appl. No. 16/928,367 , “Advisory Action”, Dec. 15, 2022, 4 pages. [cited by applicant]
U.S. Appl. No. 16/928,367 , “Final Office Action”, Oct. 7, 2022, 40 pages. [cited by applicant]
U.S. Appl. No. 16/928,367 , “Final Office Action”, Dec. 8, 2023, 44 pages. [cited by applicant]
U.S. Appl. No. 16/928,367 , “First Action Interview Office Action Summary”, Jul. 13, 2022, 9 pages. [cited by applicant]
U.S. Appl. No. 16/928,367 , “First Action Interview Pilot Program Pre-Interview Communication”, Jun. 10, 2022, 5 pages. [cited by applicant]
U.S. Appl. No. 16/928,367 , “Non-Final Office Action”, May 11, 2023, 42 pages. [cited by applicant]
U.S. Appl. No. 16/928,367 , “Notice of Allowance”, Feb. 26, 2024, 5 pages. [cited by applicant]
Almaden et al., “Specification of the Identity Mixer Cryptographic Library”, XP093100983, Available online at: https://dominoweb.draco.res.IBM.com/reports/rz3730_revised.pdf, Apr. 29, 2010, pp. 1-48. [cited by applicant]
Bemmann et al., “Fully-Featured Anonymous Credentials with Reputation System”, Image, Video and Signal Processing, XP059173221, Sep. 5, 2018, pp. 1-22. [cited by applicant]
Ben-Sasson , “Succinct Non-Interactive Zero-knowledge for a von Neumann Architecture”, Cryptology ePrint Archive, Report 2013/879, 2013, 37 pages. [cited by applicant]
Camenisch et al., “Concepts and Languages for Privacy-Preserving Attribute-Based Authentication”, Policies and Research in Identity Management, vol. 396, XP055122746, Jan. 1, 2013, 18 pages. [cited by applicant]
De La Piedra , “Integration of Hardware Tokens in the Idemix Library”, International Association for Cryptologic Research, XP061016876, Sep. 3, 2014, 17 pages. [cited by applicant]
EP21842395.2 , “Extended European Search Report”, Nov. 29, 2023, 10 pages. [cited by applicant]
Gennaro et al., “Quadratic Span Programs and Succinct NIZKs without PCPs”, EUROCRYPT, Originally Published as Cryptology ePrint Archive, Report 2012/215, 2013, 59 pages. [cited by applicant]
Parno et al., “Pinocchio: Nearly Practical Verifiable Computation”, Communications of the ACM, vol. 59, No. 2, May 19-22, 2013, 16 pages. [cited by applicant]
PCT/US2021/041314 , “International Preliminary Report on Patentability”, Jan. 26, 2023, 7 pages. [cited by applicant]
PCT/US2021/041314 , “International Search Report and Written Opinion”, Oct. 26, 2021, 13 pages. [cited by applicant]
Application No. EP21842395.2 , Office Action, Mailed On Apr. 9, 2026, 7 pages. [cited by applicant]
Application No. CN202180049517.8, Office Action, Mailed On Jun. 19, 2026, 10 pages. [cited by applicant]