Template-based distributed certificate issuance in a multi-tenant environment

US10979418B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10979418-B2
Application numberUS-201916540942-A
CountryUS
Kind codeB2
Filing dateAug 14, 2019
Priority dateJul 12, 2016
Publication dateApr 13, 2021
Grant dateApr 13, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

One example method may include generating a template transaction certificate by one or more entities which verify proof of ownership of attributes incorporated into the template transaction certificate, and generating one or more operational transaction certificates by the one or more entities which verified proof of ownership of the template transaction certificate.

First claim

Opening claim text (preview).

What is claimed is: 1. A method, comprising: receiving a request for tokens from an entity; determining that the entity is permitted to receive tokens based on reputation data of the entity compiled from a series of transactions on a blockchain; generating a template transaction certificate for one or more entities based on encrypted one or more attributes of the one or more entities included in the template transaction certificate to verify proof of ownership of the one or more attributes, the template transaction certificate comprising a field for storing entity reputation data, and issuing one or more tokens for validating corresponding ones of transactions recorded in a distributed database, each of the one or more tokens including an operational transaction certificate generated based on the template transaction certificate and verifying proof of ownership of the one or more attributes of the one or more entities performing corresponding ones of the transactions. 2. The method of claim 1 , further comprising: performing a refresh operation to obtain the one or more attributes; and retrieving the one or more attributes associated with one or more users responsive to the refresh operation being performed. 3. The method of claim 1 , wherein the one or more attributes are retrieved from an attribute certificate authority. 4. The method of claim 3 , further comprising responsive to retrieving the one or more attributes, returning an attribute certificate comprising an enrollment public key from an enrollment certificate acquired via the attribute certificate authority. 5. The method of claim 1 , wherein at least one of the template transaction certificate or the operational transaction certificates correspond to different levels of an audit tree, the audit tree to be used by entities with different jurisdictions or levels of privacy to decrypt and recover the one or more attributes. 6. The method of claim 1 , further comprising: verifying a template transaction certificate signature of the template transaction certificate; and generating one or more keys to access template transaction certificate attribute information associated with the one or more attributes. 7. The method of claim 6 , further comprising: concatenating a timestamp, a random value and a counter with the template transaction certificate; and signing the template transaction certificate using a private key. 8. An apparatus, comprising: a processor configured to receive a request for tokens from an entity, determine that the entity is permitted to receive tokens based on reputation data of the entity compiled from a series of transactions on a blockchain, generate a template transaction certificate for one or more entities based on encrypted one or more attributes of the one or more entities included in the template transaction certificate to verify proof of ownership of the one or more attributes, the template transaction certificate comprising a field for storing entity reputation data, and issue one or more tokens for validation of corresponding ones of transactions recorded in a distributed database, each of the one or more tokens including an operational transaction certificate generated based on the template transaction certificate and which verifies proof of ownership of the one or more attributes of the one or more entities performing corresponding ones of the transactions. 9. The apparatus of claim 8 , wherein the processor is further configured to perform a refresh operation to obtain the one or more attributes, and retrieve the one or more attributes associated with one or more users responsive to the refresh operation being performed. 10. The apparatus of claim 8 , wherein the one or more attributes are retrieved from an attribute certificate authority. 11. The apparatus of claim 10 , wherein the processor is further configured to responsive to the one or more attributes being retrieved, return an attribute certificate comprising an enrollment public key from an enrollment certificate acquired via the attribute certificate authority. 12. The apparatus of claim 8 , wherein at least one of the template transaction certificate or the operational transaction certificates correspond to different levels of an audit tree, the audit tree to be used by entities with different jurisdictions or levels of privacy to decrypt and recover the one or more attributes. 13. The apparatus of claim 8 , wherein the processor is further configured to verify a template transaction certificate signature of the template transaction certificate, and generate one or more keys to access template transaction certificate attribute information associated with the one or more attributes. 14. The apparatus of claim 13 , wherein the processor is further configured to concatenate a timestamp, a random value and a counter with the template transaction certificate, and sign the template transaction certificate using a private key. 15. A non-transitory computer readable storage medium configured to store instructions that when executed cause a processor to perform: receiving a request for tokens from an entity; determining that the entity is permitted to receive tokens based on reputation data of the entity compiled from a series of transactions on a blockchain; generating a template transaction certificate for one or more entities based on encrypted one or more attributes of the one or more entities included in the template transaction certificate to verify proof of ownership of the one or more attributes, the template transaction certificate comprising a field for storing entity reputation data, and issuing one or more tokens for validating corresponding ones of the transactions recorded in a distributed database, each of the one or more tokens including an operational transaction certificate generated based on the template transaction certificate and verifying proof of ownership of the one or more attributes of the one or more entities performing corresponding ones of the transactions. 16. The non-transitory computer readable storage medium of claim 15 , wherein the processor is further configured to perform: performing a refresh operation to obtain the one or more attributes; and retrieving the one or more attributes associated with one or more users responsive to the refresh operation being performed. 17. The non-transitory computer readable storage medium of claim 15 , wherein the one or more attributes are retrieved from an attribute certificate authority. 18. The non-transitory computer readable storage medium of claim 17 , wherein the processor is further configured to perform responsive to retrieving the one or more attributes, returning an attribute certificate comprising an enrollment public key from an enrollment certificate acquired via the attribute certificate authority. 19. The non-transitory computer readable storage medium of claim 15 , wherein at least one of the template transaction certificate or the operational transaction certificates correspond to different levels of an audit tree, the audit tree to be used by entities with different jurisdictions or levels of privacy to decrypt and recover the one or more attributes. 20. The non-transitory computer readable storage medium of claim 15 , wherein the processor is further configured to perform: verifying a template transaction certificate signature of the template transaction certificate; generating one or more keys to access template transaction certificate attribute

Assignees

Inventors

Classifications

  • using hash chains, e.g. blockchains or hash trees · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • using tree structure or hierarchical structure · CPC title

  • Financial cryptography, e.g. electronic payment or e-cash · CPC title

  • using a third party · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10979418B2 cover?
One example method may include generating a template transaction certificate by one or more entities which verify proof of ownership of attributes incorporated into the template transaction certificate, and generating one or more operational transaction certificates by the one or more entities which verified proof of ownership of the template transaction certificate.
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L63/0823. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 13 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 7 related publications on this page (citations in our corpus or others sharing the same primary CPC).