EP3424176B1

Systems and methods for distributed data sharing with asynchronous third-party attestation

Abstract

This record has no abstract on file.

EP3424176B1, drawing sheet 1
Sheet 1 of 21

Term

10.4 yearsleft in the term

Expires 27 February 2037.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

14 claims: 10 independent, 4 dependent

  1. 1
    A method (800) of distributed data verification in a distributed network between a relying party server (310) and a client device (330) using a first attestation server (350) and a second attestation server (350), the method carried out by the client device (330) and comprising:receiving (805), at the client device (330), a relying party request from the relying party server (310), the relying party request comprising a relying party profile identifier, an attested data item request, and a relying party proof that enables verification of the relying party request;verifying the relying party request based on the relying party proof, wherein verification of the relying party profile comprises: retrieving (810) a relying party profile based on the relying party profile identifier, extracting (815) a verification component from the relying party profile;and verifying (820) the relying party proof using the verification component;and when verification of the relying party request is successful: determining (830, 835) that an attested data item and at least one additional attested data item can fulfill the attested data item request;when the attested data item request can be fulfilled, retrieving (840) the attested data item, and an attestation corresponding to the attested data item from a local data store;determining that the at least one additional attested data item is not initially available;transmitting a request for the at least one additional attested data item to the second attestation server;receiving a response to the request from the second attestation server, the response comprising the at least one additional attested data item and the the at least one additional attestation;storing the at least one additional attested data item and the at least one additional attestation in the local data store, wherein the attestation comprises a cryptographically-generated proof that the attested data item was verified by the first attestation server (350), and wherein the additional attestation comprises an additional cryptographically-generated proof that the at least one additional attested data item was verified by the second attestation server (350);generating (855) a response, the response comprising the attested data item, the additional attested data item, the attestation and the at least one additional attestation;and transmitting (855) the response to the relying party server (310).
  2. 4
    The method of any one of claims 1 to 3, further comprising:determining that the attested data item is not initially available;transmitting a request for the attested data item to the first attestation server;receiving a response to the request from the first attestation server, the response comprising the attested data item and the attestation;and storing the attested data item and the attestation in a data store.
  3. 5
    The method of any one of claims 1 to 4, wherein the relying party request comprises a processing agent identifier, the method further comprising:determining a processing agent associated with the processing agent identifier;providing the response to the client device;and providing an indication of the processing agent to the client device to enable the client device to forward the response to the processing agent.
  4. 6
    The method of any one of claims 1 to 5, further comprising, prior to generating the response, authenticating a user of the client device, wherein the authentication is performed via the client device or via an authentication server.
  5. 7
    The method of any one of claims 1 to 6, further comprising:receiving a second relying party request from a second relying party server;verifying the relying party request;determining that the attested data item can fulfill the second relying party request;retrieving the attested data item and the attestation corresponding to the attested data item;generating a second response, the second response comprising the attested data item and the attestation;and transmitting the second response to the second relying party server.
  6. 8
    The method of any one of claims 1 to 7, wherein the relying party request comprises a policy identifier, the method further comprising retrieving at least one policy based on the policy identifier, wherein determining whether the attested data item can fulfill the attested data item request is based on the at least one policy.
  7. 9
    The method of any one of claims 1 to 8, wherein the relying party request further comprises a non-attested data item request, and wherein the response comprises a non-attested data item, the method further comprising generating the non-attested data item.
  8. 10
    A non-transitory computer readable medium storing computer executable instructions which, when executed by a computer processor, cause the computer processor to carry out the method of any one of claims 1 to 9.
  9. 11
    A method (1100) of distributed data verification in a distributed network between a relying party server (310) and a client device (330) using a first attestation server (350) and a second attestation server (350), the method carried out by the relying party server (310) and comprising:determining (1105) a relying party profile identifier and at least one attested data item to be requested;generating (1115) a relying party request, the relying party request comprising the relying party profile identifier, an attested data item request, and a relying party proof that enables verification of the relying party request;transmitting (1120) the relying party request from the relying party server to the client device;receiving (1125) a response to the relying party request from the client device, the response comprising an attested data item corresponding to the attested data item request, at least one additional attested data item, an attestation corresponding to the attested data item, and an additional attestation corresponding to the at least one additional attested data item, wherein the attestation comprises a cryptographically-generated proof that the attested data item was verified by the first attestation server, wherein the additional attestation comprises a cryptographically-generated proof that the at least one additional attested data item was verified by the second attestation server.
  10. 14
    A non-transitory computer readable medium storing computer executable instructions which, when executed by a computer processor, cause the computer processor to carry out the method of any one of claims 11 to 13.