System for authenticating verified personal credentials
Inventors
Mishra, Prateek • Villavicencio, Frank • Mohammad, Merajuddin
Assignees
Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
A method, apparatus, system, and computer program product are provided for managing the usage of verified credentials. An issuer of credentials receives a request from a person for a credential. The issuer identifies the credential from information that is controlled by the issuer. The issuer identifies a decentralized identifier (DID) record for an audit engine from a blockchain network. The DID record for the audit engine includes a public key of that is associated with the audit engine. The issuer identifies a DID record for the person from the blockchain network. The DID record for the person includes a public key that is associated with the person. The issuer generates an encrypted credential by encrypting the credential and the DID record for the person based on the public key associated with the audit engine. The issuer sends the encrypted credential to the person.
Core Innovation
The described system manages usage of verified credentials in which a computer system receives a request from a person for a credential of the person and generates the credential from information controlled by an issuer. The issuer-controlled information and the credential are linked to decentralized identifiers used to coordinate credential delivery and later authentication.
The computer system identifies a first decentralized identifier record for an audit engine from a blockchain, where the first decentralized identifier record includes a public key of a cryptographic key pair associated with the audit engine. The computer system also identifies a second decentralized identifier record for the person from the blockchain, where the second decentralized identifier record is within the first decentralized identifier record and includes a public key of a cryptographic key pair associated with the person.
The computer system generates an encrypted credential by encrypting the credential and the second decentralized identifier record for the person based on the public key associated with the audit engine, and sends the encrypted credential to the person. The audit engine is associated with credential manifests and produces audit logs or records tied to the credential manifests, and relying parties receive the encrypted credential and obtain verification and decryption or credential resolution using keys referenced by the credential and the issuer identity on the manifest.
The audit logs enable issuer invoicing for per-use while preserving privacy in that the issuer cannot track relying-party identity or credential usage.
Claims Coverage
The partial content identifies three independent claims: clm-00001, clm-00008, and clm-00015. Across these independent claims, the inventive features consistently combine blockchain-based decentralized identifier records for an audit engine and a person with encryption of a credential for the person using the audit engine public key.
Managing usage of verified credentials with blockchain-based audit-engine and person DID records
Receiving a request from a person for a credential of the person; generating the credential from information controlled by an issuer; identifying a first decentralized identifier record for an audit engine from a blockchain including a public key associated with the audit engine; identifying a second decentralized identifier record for the person from the blockchain within the first decentralized identifier record including a public key associated with the person; generating an encrypted credential by encrypting the credential and the second decentralized identifier record for the person based on the public key associated with the audit engine; and sending the encrypted credential to the person.
Credential management system with encrypted credential based on audit-engine public key
A credential management system where an issuer receives a request from a person for credential of the person; generates the credential of the person from information controlled by the issuer; identifies a first decentralized identifier record for an audit engine from a blockchain including a public key of a cryptographic key pair associated with the audit engine; identifies a second decentralized identifier record for the person from the blockchain within the first decentralized identifier record including a public key of a cryptographic key pair associated with the person; generates an encrypted credential by encrypting the credential of the person and the second decentralized identifier record for the person based on the public key associated with the audit engine; and sends the encrypted credential to the person.
Computer program product performing encrypted credential delivery using audit-engine and person DID records
A computer program product comprising computer readable storage media with program instructions to cause a computer system to perform receiving a request from a person for credential of the person; generating the credential from information controlled by an issuer; identifying a first decentralized identifier record for an audit engine from a blockchain including a public key associated with the audit engine; identifying a second decentralized identifier record for the person from the blockchain within the first decentralized identifier record including a public key associated with the person; generating an encrypted credential by encrypting the credential and the second decentralized identifier record for the person based on the public key associated with the audit engine; and sending the encrypted credential to the person.
All independent claims are directed to managing usage of verified credentials by generating an issuer-controlled credential, associating the audit engine and the person with blockchain decentralized identifier records containing public keys, encrypting the credential and the person’s decentralized identifier record based on the audit engine public key, and sending the encrypted credential to the person.
Stated Advantages
Preserves privacy by preventing the issuer from tracking relying-party identity or credential usage.
Documented Applications
Managing usage of verified credentials in a blockchain-based credential management/authentication exchange involving a person, an issuer, a relying party, and an audit engine, including audit logs enabling issuer invoicing for per-use while preserving privacy.
Interested in licensing this patent?