Distributed identity management for a decentralized platform
Patent Information
- Authority / Receiving Office
- TW · TW
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-02-20
- Publication Date
- 2023-10-16
Smart Images

Figure TWG2TA000929741_001 
Figure TWG2TA000929741_002 
Figure TWG2TA000929741_003
Abstract
Description
[Technical Field]
[0001] This invention relates to a distributed identity (DID) management system for a decentralized platform. [Previous Technology]
[0002] Conventionally, digital information and computation are subject to a conventional central server architecture managed and controlled by a third-party central authority (e.g., whether using a client-server model or a personal device). More specifically, the third-party central authority (e.g., a centralized, privately controlled service provider) can access, read, and review digital information created and provided by users, and manipulate and control user identity and corresponding user behavior (requiring user authentication and verification).
[0003] For example, a third-party central authority requires verifiable user identity to provide selective access to corresponding digital information or to verify ownership of that digital information. Typically, the third-party central authority uses a central server, database, and / or other directory service to perform user authentication and verification. More specifically, the third-party central authority utilizes a single source of control within a central server, database, and / or other directory service through a central list, table, or database containing all user identification (UID) information for each user.
[0004] This single source of control is a major security vulnerability for third-party central authorities and, consequently, users. This single source of control also limits the ability of third-party central authorities to provide anonymity to users. However, despite these concerns, third-party central authorities can still manipulate, censor, aggregate, control, and monetize users' digital information.
[0005] Users want control over their digital information. Users also want security and anonymity for their UID information. Currently, there is no architecture that can provide a decentralized mechanism for sharing digital information to achieve this user control. [Summary of the Invention]
[0006] A method implemented by an engine to manage the distributed identities of users of a decentralized platform. The engine is executed by a processor within the decentralized platform. The method includes generating a cryptographically secure and reusable distributed identity for an owner, which obfuscates the owner's identity and associates the cryptographically secure and reusable distributed identity with a blockchain of the decentralized platform. The method includes the engine controlling access to digital information and services of such users of the decentralized platform via an owner authorization process. Such digital information and services are associated with the cryptographically secure and reusable distributed identity. The method described herein can be implemented as a system, device, apparatus, and / or computer program product.
Implementation Method
[0014] This application claims priority to U.S. Provisional Application No. 63 / 319,992, filed on March 15, 2022, the entire contents of which are incorporated herein by reference.
[0015] This paper discloses a distributed identity (DID) management method for a decentralized platform. Through DID management, the decentralized platform can support at least private and autonomous social media activities, as well as security, privacy, personal data, and computational rules.
[0016] According to one or more embodiments, DID management and security, privacy, personal data, and computational rules must be embedded in processor executable code or software within the program operation and processing hardware of a decentralized platform. For ease of explanation, this document describes an engine in relation to DID management and such security, privacy, personal data, and computational rules.
[0017] Figure 1 illustrates method 100 according to one or more embodiments. Method 100 generally illustrates operation via DID management of an engine.
[0018] Method 100 begins at block 110, where the engine generates a cryptographically secure and reusable DID that obfuscates the identity of one of the owners. For example, the engine enables a user to create and own a cryptographically secure and reusable DID (referred to as DID in this document for brevity). Each DID is independent, anonymous (i.e., obfuscates an identity), and securely manages all UID information and services for a specific user. Each DID can be a password hash of a username, so that the engine and the decentralized platform are unaware of any identity information.
[0019] At block 130, the engine associates the DID with one of the decentralized platforms' blockchains. The blockchain guarantees the fidelity and security of the DID, the decentralized platform, the engine, and the data, providing trust between decentralized platform nodes without requiring a third-party central authority. One or more advantages, technical effects, and / or benefits of the engine's DID may include eliminating the need for a central server, database, and / or other directory services of a third-party central authority.
[0020] At block 150, the engine gates access, such as access to nodes of a decentralized platform. According to one or more embodiments, the engine gates access to digital information and services for users of the decentralized platform. The digital information and services are associated with a cryptographically secure and reusable distributed identity. According to one or more embodiments, for gated access, the engine implements an owner authorization process (also known as a reverse authorization process), which contrasts with and is a technical improvement upon conventional Web2 and Web3 authorization procedures, in which an identity provider maintains a private key trusted by a third-party central authority. The owner authorization process is a user-controlled procedure that supports inviting other users to participate in private social media activities.
[0021] One or more advantages, technological effects, and / or benefits of DID can be included in a decentralized platform that enables user anonymity and control without any third-party central authority. Therefore, the engine specifically utilizes and transforms decentralized platforms to realize / implement private social media activities that are currently unavailable in conventional central server architectures.
[0022] Figure 2 illustrates one embodiment of an architecture 200 (also referred to as a decentralized platform). Typically, architecture 200 provides a node-based decentralized platform that implements local data retention. Although a single element is shown in Figure 2, such a single element represents a plurality of such elements. Architecture 200 includes an engine 201, a device 202, computing platforms 203 and 204, a server 205, a network 206, and a service 207, each of which may represent a node within architecture 200.
[0023] Engine 201 may be hardware, software, or a combination thereof. As shown in the figure, engine 201 may be software operating within server 205. Typically, engine 201 may be stored as a software component, module, instruction, or the like in a memory (e.g., a system memory 221) for execution by a processor (e.g., a processor 222). According to one or more embodiments, engine 201 may be software (e.g., an application) implemented through one or more different examples 201A, 201B, 201C, and 201D. Therefore, engine 201 is described in detail as a dashed box 201A to illustrate the scalability and portability of engine 201 within architecture 200 (e.g., engine 201 may be implemented through one or more different examples 201, 201A, 201B, 201C, and 201D, which may further communicate with each other). As an example, engine 201 can be implemented as service 207, which provides at least a public form of the blockchain of architecture 200. The blockchain of architecture 200 can guarantee the authenticity and security of architecture 200, local data storage, and the identity of users / devices / servers / nodes, and generate trust between nodes without the need for a third-party central authority.
[0024] According to one or more embodiments, engine 201 implements one practical use of the blockchain of architecture 200 to realize a social network (i.e., sharing pictures, stories, messages, etc.). More specifically, engine 201A running in device 202, engine 201 running server 205, and service 207 uniquely employ public and private key pairs to encrypt and protect the identity of users / devices / servers / nodes and regulate the authorization of user / device / server / node logins. For example, various instances 201, 201A, 201B, 201C, and 201D of engine 201 (such as) establish peer connections within architecture 200 by using the blockchain of architecture 200 to build and provide social media experiences without a known central server architecture. More specifically, to form architecture 200 (e.g., a decentralized platform), a first instance 201 may reside on server 205 (e.g., a server instance of a dedicated server), a second instance 201A may reside on device 202 (e.g., a mobile instance or terminal application on a mobile phone), and a third instance 201D may reside on device 206 (e.g., service 207), and the first, second, and third instances 201, 201A, and 201D may work together to build and deliver social media experiences (e.g., a three-part contribution program). The operation of engine 201 is further described herein.
[0025] Devices 202, computing platforms 203 and 204, and server 205 may be any combination of software and / or hardware that individually or collectively stores, executes, and implements the engine 201 and its functions. Furthermore, devices 202, computing platforms 203 and 204, and server 205 may each be a node (e.g., a communication endpoint) of an electronic computer framework (e.g., a decentralized platform shown as architecture 200) that includes and / or employs any number and combination of computing devices and networks utilizing various communication technologies, as described herein. Devices 202, computing platforms 203 and 204, and server 205 are easily scalable, extendable, and modular, possessing the ability to change to different services or reconfigure certain features independently of other services. Examples of devices 202, computing platforms 203 and 204, and server 205 may include (but are not limited to) a fixed / standalone device, a base station, a desktop / laptop computer, a smartphone, a smartwatch, a tablet computer, or other devices configured to communicate across network 206. Therefore, devices 202, computing platforms 203 and 204, and server 205 can be programmable to execute computer instructions regarding engine 201.
[0026] As an example, server 205 includes system memory 221 and processor 222 connected via a system bus 223 that is also connected to a adapter 224. Typically, system memory 221 can be any non-transitory tangible medium, such as magnetic, optical, or electronic memory (e.g., any suitable volatile and / or non-volatile memory, such as random access memory or a hard disk drive). System memory 221 stores computer instructions executed by processor 222. Processor 222 can be any central processing unit, graphics processing unit, microprocessor, field-programmable array, or the like capable of executing computer instructions. System bus 223 enables internal communication between system memory 221, processor 222, and adapter 224. Adapter 224 may include a separate transmitter, a separate receiver, and / or an integrated transmitter / receiver to enable external communication from server 205 via network 206 and / or directly to device 202. System memory 221 may contain / store a database 225 and / or software (e.g., engine 201). Database 225 may be a database (e.g., an SQL database) and / or another storage facility. System memory 221, processor 222, and system bus 223 are representative of the components of devices 202 and computing platforms 203 and 204, although they are not repeated here for efficiency and simplicity.
[0027] As an example, device 202 may include a control device 227 and a display 228 (or other input / output element). The control device 227 (such as a computer mouse, a keyboard, a touchpad, a touch screen, a keypad, or the like) may be further coupled to device 202 for input (e.g., one or more inputs may be provided by a user). Display 228 is configured to provide one or more UIs or GUIs that may be generated and provided by engine 201 when the user interacts with device 305. Examples of display 341 may include (but are not limited to) a plasma, a liquid crystal display (LCD), a light-emitting diode (LED), a field-emitting display (FED), an organic light-emitting diode (OLED) display, a flexible OLED display, a flexible substrate display, a projection display, a 4K display, a high-resolution (HD) display, a Retina© display, a lateral electric field effect (IPS) display, or the like. Display 228 can be configured to use resistive, capacitive, surface acoustic wave (SAW) capacitor, infrared, optical imaging, dispersive signal technology, acoustic impulse recognition, suppressed total internal reflection, or similar touch, three-dimensional (3D) touch, multi-input touch, or multi-touch display, as understood by those skilled in the art regarding input / output (I / O). Control devices 227 and display 228 are representative of the components of computing platforms 203 and 204 and server 205, although they are not repeated here for efficiency and simplicity.
[0028] Network 206 may be a wired network, a wireless network, or include one or more wired and wireless networks. According to one embodiment, network 206 may be a short-range network (e.g., a local area network (LAN) or a personal area network (PAN)). Information can be transmitted between devices 202, computing platforms 203 and 204, and server 205 via network 206 using any of a variety of short-range wireless communication protocols (such as Bluetooth, Wi-Fi, Zigbee, Z-Wave, Near Field Communication (NFC), Overband, Zigbee, or Infrared (IR)). According to one embodiment, network 206 may be an intranet, a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a direct connection or a series of connections, a cellular telephone network, or any other network or medium that facilitates communication between devices 202, computing platforms 203 and 204, and server 205. Information can be transmitted via network 206 using any of the various long-range wireless communication protocols (e.g., TCP / IP, HTTP, 3G, 4G / LTE, or 5G / New Wireless). It should be noted that network 206 can be wired using Ethernet, Universal Serial Bus (USB), RJ-11, or any other wired connection, and wireless using Wi-Fi, WiMAX, Bluetooth, infrared, cellular, satellite, or any other wireless connection method.
[0029] Network 206 may include one or more additional nodes 230 and service 207. Each node 230 of network 206 serves as a communication endpoint facilitating the decentralized platform provided by architecture 200. Service 207 may provide anchored operation and support, rather than control, to a specific type of node 230 of the decentralized platform provided by architecture 200. For example, service 207 may support a portion of the blockchain of architecture 200. Typically, a blockchain is a distributed database used to maintain the security and decentralized record of transactions, and is shared among nodes 230, service 207, device 202, computing platforms 203 and 204, and server 205 of architecture 200.
[0030] According to one or more embodiments, architecture 200 includes distributed identity (DID) management. DID management allows users to create DIDs that are cryptographically secure and reusable. DID management enables the created DIDs to be associated with the blockchain of architecture 200. That is, each DID can independently, anonymously, and securely manage all digital information and services of a specific user / device / server / node. For example, server 205 and engine 201 collaborate with service 207 in the blockchain to provide DID management. DID management can obfuscate the identity of server 205 to support private and autonomous social media activities within architecture 200, as well as other security, privacy, personal data, and computational requirements of engine 201. DID management can obfuscate the identity of a user to support private and autonomous social media activities within a decentralized platform.
[0031] Each DID may contain a public-private key combination (i.e., a public key and a private key). A public key may be a cryptographic element that anyone can use to encrypt and / or sign data. A copy of the public key may be shared on other parts of architecture 200, such as with the blockchain of service 207. A private key may be a cryptographic element that can be used individually to encrypt and / or sign data. For example, data encrypted using the public key can only be decrypted using the private key. As shown in Figure 2, the DID of server 205 enables engine 201 to store keys 241, 242, 243, and 244 in storage 225. Additional keys 245 and 246 may exist within architecture 200.
[0032] According to one or more embodiments, server 205 is implemented as a physical server (i.e., a decentralized platform) of architecture 200. For example, server 205 may be a dedicated server, such as a physical unit purchased and managed locally by a user. As another example, server 205 and its operation may be implemented / contained in another unit (i.e., or extended beyond any dedicated server), such as in a USB flash drive.
[0033] For example, a user / customer purchases a server 205 (i.e., a dedicated server) that is created for server 205 upon going online and contains a DID with one of a public key 241 and a private key 242, and a DID created for the user / customer that contains one of a public key 243 and a private key 244. The user / customer uses device 202 (i.e., a mobile phone) to download the second item 201A (i.e., a terminal application) of engine 201 to configure server 205. Configuring server 205 includes enabling the user to name server 205 (create a username), which is then used for the DID of server 205. When viewing server 205, the user / customer only sees the username on display 228. In the background, the terminal application with server 205 establishes an association for the user / customer to exclusively control server 205. Public data (e.g., a copy 241.c of the public key 241) is stored in the blockchain, and the end application receives a copy 242.c of the private key 242 of the server's DID. Furthermore, if a user / client wishes to share access to server 205, they can send an invitation to seamlessly share a copy 241.c of the public key 241 in the background. Consequently, the user / client will never know that they are using the blockchain and the public-private key architecture.
[0034] According to one or more embodiments, architecture 200 may include a private cloud. Subsequently, server 205 may also be virtualized in the private cloud. Engine 201 implements a decentralized platform (i.e., architecture 200) by configuring server 205 (e.g., a dedicated server or a software-based dedicated server) and / or the private cloud.
[0035] Regarding the operation of engine 201 (for example, the system memory 221 of server 205 stores the instructions of engine 201 for execution by processor 222). Typically, after executing the instructions of engine 201, server 205 can locally privatize data storage and user behavior to eliminate the need for third-party central management or third-party data storage (e.g., thereby enabling users to create, distribute, and consume their digital information and services within architecture 200). More specifically, repository 225 can locally store digital information and services, models, neural networks, machine learning, artificial intelligence, automation, documents, entities, confidence metrics, images, clips, hashes, videos, frames, source data, source code, etc., for access by engine 201. Then, engine 201 can locally create, distribute, and consume digital information and services using models, neural networks, machine learning, artificial intelligence, etc. Therefore, Engine 201 can provide a framework / mechanism for automatically implementing a decentralized server approach (i.e., Architecture 200) or as part of it.
[0036] As a further example, the scope and operation of Engine 201 can be described relative to a social media experience that uses a software-based dedicated server (i.e., Server 205) to containerize and share digital information and services in a decentralized manner. Engine 201 may be implemented / included on various commuting platforms, including Internet of Things (IoT) devices, dedicated local hardware and mobile devices, and virtualized versions in one or more cloud computing providers. Accordingly, Engine 201 implements a decentralized platform through its operation to support private and autonomous social media activities (e.g., digital information and services) through security, privacy, personal data and computing provisions. Operations 251, 252, 253, 254, 255 and 256 represent examples of such security, privacy, personal data and computing provisions, but Engine 201 is not limited thereto.
[0037] Regarding operation 251, engine 201 can enable a user (e.g., the owner of server 205) to control a social media experience by providing machine learning and / or artificial intelligence (ML / AI). The ML / AI of engine 201 can provide a social media experience, such as automatic suggestions for nodes 230, storage 225, and connections. The ML / AI of engine 201 can provide a social media experience by automatically organizing digital information, providing notifications to other users, and encrypting user interactions / communications. The ML / AI of engine 201 can provide a social media experience by designing personalized interactions, evoking emotions based on digital information and connections, and driving stronger and deeper relationships within connections. The ML / AI of engine 201 can provide a social media experience by automatically setting permissions. Figures 3 and 4 illustrate the ML / AI of engine 201.
[0038] Figure 3 illustrates a system 300 according to one or more embodiments. System 300 includes data 310 (e.g., digital information and services), a machine 320, a model 330, a result 340, and (underlying) hardware 350. Figure 4 illustrates a system 400 (e.g., a neural network) and a method 401 performed in system 400 according to one or more embodiments. System 400 operates to support the implementation of the ML / AI algorithms described herein (e.g., implemented by engine 201). System 400 may be implemented in hardware (such as machine 320 and / or hardware 350 of Figure 3). Where appropriate, for ease of understanding, reference may be made to other figures to describe Figures 3 to 4. For example, machine 310 and model 330 may represent the state of engine 201 of Figure 2 (e.g., the ML / AI algorithm therein), and hardware 350 may also represent server 205 of Figure 2.
[0039] Generally, the ML / AI algorithm of system 300 (e.g., implemented by engine 201 of FIG2) uses data 310 to operate relative to hardware 350 to train machine 320, build model 330, and predict results 340. For example, machine 320 operates as a controller or data collection associated with and / or associated with hardware 350. Data 310 may be ongoing data or output data associated with hardware 350. Data 310 may also include currently collected data, historical data, or other data from hardware 350 and may be associated with hardware 350. Machine 320 may divide data 310 into one or more subsets. In addition, machine 320 (such as) trains relative to hardware 350. This training may also include analysis and correlation of one of the collected data 310. According to another embodiment, training machine 320 may include self-training performed by engine 201 of FIG2 using one or more subsets. Furthermore, model 330 is built upon data 310 associated with hardware 350. Building model 330 may involve seeking physical hardware or software modeling, algorithmic modeling, and / or similar methods to represent the collected and trained data 310 (or a subset thereof). In some cases, the construction of model 330 is part of the self-training operation of machine 320. Model 330 can be configured to model the operation of hardware 350 and the data 310 collected from hardware 350 to predict the outcome 340 achieved by hardware 350. The predicted outcome 340 (of model 330 associated with hardware 350) can utilize a trained model 330. Therefore, using the predicted outcome 340, machine 320, model 330, and hardware 350 can be configured accordingly.
[0040] Therefore, for the operation of system 300 relative to hardware 350, data 310 is used to train machine 320, build model 330, and predict results 340, wherein the ML / AI algorithm may include a neural network. Generally speaking, a neural network is a network or circuit of neurons, or in a modern sense, an artificial neural network (ANN) composed of artificial neurons, nodes, or cells. For example, an ANN involves a network of processing elements (artificial neurons) that can exhibit complex global behavior determined by the connections between processing elements and element parameters. In more practical terms, neural networks can be used to model complex relationships between inputs and outputs or to model or make decisions based on nonlinear statistical data patterns found in the data. Therefore, ANNs can be used for predictive modeling and adaptive control applications while being trained on a dataset. It should be noted that self-learning derived from experience can occur within an ANN, which can draw conclusions from a complex and seemingly unrelated set of information. The practicality of artificial neural network models lies in the fact that they can be used to infer a function through self-observation and also use that function. According to one or more embodiments, the neural network may implement a deep neural network, a long short-term memory neural network architecture, a convolutional neural network (CNN) architecture, or the like. The neural network may be relative to several layers, several connections (e.g., encoder / decoder connections), a regularization technique (e.g., dropout); and an optimized feature configuration.
[0041] In one instance operation, engine 201 of FIG2 includes data 310 collected from hardware 350. In system 400, an input layer 410 is represented by a plurality of inputs (e.g., inputs 412 and 414 of FIG4). Relative to block 420 of method 401, input layer 410 receives inputs 412 and 414. Inputs 412 and 414 may contain digital information and services or other dates from storage 225. At block 425 of method 401, system 400 encodes inputs 412 and 414 using any portion of the data 310 (e.g., datasets and predictions generated by system 300) to produce a latent representation or data encoding. The latent representation includes one or more intermediate data representations derived from the plurality of inputs. According to one or more embodiments, the latent representation is generated by one of the engines 201 of FIG2 by an element-initiated function (e.g., a sigmoid function or a rectified linear unit). As shown in Figure 4, inputs 412 and 414 are provided to a hidden layer 430, which is depicted as containing nodes 432, 434, 436, and 438. System 400 performs processing via the hidden layer 430 containing nodes 432, 434, 436, and 438 to exhibit complex global behavior determined by the connections between processing elements and element parameters. Therefore, the transition between layers 410 and 430 can be viewed as an encoder stage that receives inputs 412 and 414 and transfers them to a deep neural network (within layer 430) to learn some smaller representations of the inputs (e.g., a derived latent representation). This encoding provides a dimension reduction for inputs 412 and 414. Dimension reduction is a procedure that reduces the number of random variables considered (inputs 412 and 414) by obtaining a set of principal variables. For example, dimensionality reduction can be a feature extraction process that transforms data (e.g., inputs 412 and 414) from a high-dimensional space (e.g., 10 dimensions or more) to a lower-dimensional space (e.g., 2 to 3 dimensions). The technical effects and benefits of dimensionality reduction include reducing the time and storage space requirements of data 310, improving the visualization of data 310, and improving parameter interpretation for machine learning. This data transformation can be linear or non-linear. The receiving (block 420) and encoding (block 425) operations can be viewed as a data preparation portion of a multi-step data manipulation performed by engine 201. At block 445 of method 410, system 400 decodes the latent representation. The decoding stage acquires the encoder output (e.g., the resulting latent representation) and attempts to reconstruct some form of inputs 412 and 414 using another deep neural network. Accordingly, nodes 432, 434, 436, and 438 are combined to produce an output 452 in output layer 450, as shown in block 460 of method 410. That is, the output layer 450 reconstructs the inputs 412 and 414 in a reduced dimension but without interference, anomalous products and noise.
[0042] Regarding operation 252, engine 201 may provide a social media experience through different platforms / modes / options for computation and / or storage, such as a fixed / standalone device, a base station, a desktop / laptop computer, a smartphone, a smartwatch, a tablet, a USB flash drive, or other devices. Accordingly, the social media experience includes providing one or more interfaces (e.g., a user interface or UI) for user-friendly interaction with engine 201.
[0043] Regarding operation 253, engine 201 can enable a user (e.g., the owner of server 205) to control a social media experience by providing configuration control over digital information and services. Examples of configuration control over digital information and services include setting permissions. Permissions may include configurations for accessing and sharing pictures and stories. Permissions may include configurations for messaging, patterns for dividing social networks by invitation, etc. One or more advantages, technical effects, and / or benefits of this configuration control of engine 201 may include providing private data sharing only to authorized users who can access digital information and services.
[0044] According to one or more embodiments, engine 201 provides configuration control over digital information and services by establishing a DID and configuration file. Turning to Figure 5, a method 500 according to one or more embodiments is illustrated. Method 500 typically illustrates DID management operations by engine 201 (e.g., establishing a DID and configuration file), such as logging in a user by establishing a DID.
[0045] Method 500 begins at block 510, where engine 201 receives a username and password. Engine 201 may receive the username and password from a user or other organization. At block 520, engine 201 generates a seed. At block 530, engine 201 generates a DID with one of the seeds. The DID can independently, anonymously, and securely manage all UID information for a specific user. In this manner, data is passed to engine 201 that returns a DID. According to one or more embodiments, a DID is generated without identification information, such that the username is attached to the DID and the DID is encrypted on the user device (e.g., device 202).
[0046] At block 540, engine 201 establishes a profile relative to one of the DIDs. Engine 201 may further store / save the DID and / or the profile. According to one or more embodiments, the operation and / or storage mode of engine 201 may include username configuration, such as letter characteristics (e.g., lowercase versus uppercase), special characters, alphanumeric values, string length, and exclusions to help obfuscate identity and provide anonymity for the social media experience. According to one or more embodiments, the operation and / or storage mode of engine 201 may include password configuration to help protect the social media experience.
[0047] At block 550, engine 201 encrypts the password. The seed can also be encrypted. At block 560, engine 201 stores / saves the configuration file, DID, encryption password, and seed (e.g., an encrypted seed), as well as any keys. Engine 201 can utilize local or cloud storage. At block 570, engine 201 returns the configuration file, DID, encryption password, and seed (e.g., an encrypted seed), as well as any keys.
[0048] Regarding operation 254, engine 201 can enable a user (e.g., a physical server owner) to control the social media experience by providing configuration control to invite and manage one or more visitors allowed to view and comment on digital information and services provided by the user. One or more advantages, technical effects, and / or benefits of this configuration control of engine 201 may include providing secure, private group communication with the user. According to one or more embodiments, engine 201 may include user categories, such as owners, members, and visitors, each user category may have configurable roles and permissions associated with a specific social media experience. According to one or more embodiments, visitor management may include accepting, blocking, and / or deleting other users from accessing server 205. For example, a member or a visitor may only be invited to access the digital information and services of an owner.
[0049] Regarding operation 255, engine 201 can enable a user (e.g., the owner of a physical server) to control a social media experience by providing a crypto wallet experience. That is, engine 201 can implement and / or support one or more crypto wallets. One or more advantages, technical effects and / or benefits of one or more crypto wallets of engine 201 may include private financial transactions independent of any third-party central authority.
[0050] Regarding operation 256, engine 201 may be extensible and connectable to third-party software, such as supporting or operating with an application store or marketplace.
[0051] Turning now to Figure 6, a communication schematic 600 according to one or more embodiments. The communication schematic 600 illustrates how the engine 201 eliminates the need for third-party central management by providing a multi-step operation of digital information and services, which enables users to directly control digital information and services.
[0052] Communication schematic 600 occurs across a mobile device 601, a decentralized data network 602, and a server box 603, which can be aligned with the device 202, architecture 200, and server 205 of FIG. 2, respectively. Typically, within communication schematic 600, trust is established by invitation, thereby eliminating automatic trust through a conventional public key system. Furthermore, the operation of establishing this trust by invitation within communication schematic 600 is hidden by the user. Each of the mobile device 601, decentralized data network 602, and server box 603 has an example of an engine 201 running therein.
[0053] In the communication diagram 600, an action is taken to create a new DID for a user. The new DID identifies or points to a profile. The mobile device 601 receives different types of information from the protocol-level service engine 201. If the information is used to create a DID, the engine 201 can enable user selection or automatic generation. At arrow 610, this new DID is pushed to the decentralized data network 602. According to one or more embodiments, a DID is created on the mobile device 601 and then sent to the decentralized data network 602 for storage, and the decentralized data network 602 only returns the success / failure of storage.
[0054] At arrow 615, decentralized data network 602 returns one or more keys (e.g., a public-private key system with paired public and private keys). The one or more keys can be used to implement owner authorization processes, track ownership, receive or use cryptocurrency, etc. A public key allows others to generate strings derived from the public key and / or make payments to an address derived from the public key. A private key enables the decoding of strings or addresses. It should be noted that a private key is never stored by decentralized data network 602, while the public key is supported by decentralized data network 602. According to one or more embodiments, decentralized data network 602 only knows about one of the public keys in the public-private key system.
[0055] In response, mobile device 601 provides decentralized data network 602 with configuration file updates. In this manner, as shown by arrow 630, mobile device 601 informs decentralized data network 602 of an address (e.g., an IP address) of server box 603. Furthermore, mobile device 610 can read and / or obtain (as shown by arrow 635) information from decentralized data network 602. This information may include background data such as location information (IP address).
[0056] At arrow 640, mobile device 601 communicates with server box 603. According to one or more embodiments, mobile device 601 may request access to server box 603. According to one or more embodiments, mobile device 601 may receive an invitation that includes one authorization to access server box 603.
[0057] In response, at circle 645, server box 603 encodes a random string using a public key associated with the DID used by mobile device 601 to generate an encoded string. At arrow 655, server box 603 sends the encoded string back to mobile device 601. At circle 660, mobile device 601 decodes the encoded string using a private key associated with the DID used by mobile device 601 to generate a decoded string. At arrow 670, mobile device 601 sends the decoded string to server box 603. At point 675, server box 603 compares the decoded string with the random string. In this way, server box 603 attempts to verify that mobile device 601 is the one it represents (i.e., a tactical DID implementation for obtaining access to the environment). At arrow 680, server box 603 sends / returns a response to mobile device 601. The response can be based on a comparison of either or no, indicating an error, etc.
[0058] According to one or more embodiments, a method is implemented by an engine to manage the distributed identities of users of a decentralized platform. The engine is executed by at least one processor within the decentralized platform. The method includes generating a cryptographically secure and reusable distributed identity for an owner that obfuscates the owner's identity and associating the cryptographically secure and reusable distributed identity with a blockchain of the decentralized platform. The method includes the engine controlling access to digital information and services of one or more users of the decentralized platform via an owner authorization process. Such digital information and services are associated with the cryptographically secure and reusable distributed identity.
[0059] According to any of the embodiments or method embodiments herein, the cryptographically secure and reusable distributed identity may contain a password hash of a username to obfuscate the user's identity.
[0060] According to any of the embodiments or method embodiments described herein, the encrypted and reusable distributed identity can independently and securely manage the owner's digital information and services.
[0061] According to any one or more embodiments or method embodiments herein, the blockchain can guarantee the fidelity and security of the cryptographically secure and reusable distributed identity.
[0062] According to any of the embodiments or method embodiments herein, the owner's authorization process may include a user control procedure that supports inviting one or more users of the decentralized platform to participate in a private social media activity.
[0063] According to any of the embodiments or method embodiments herein, the owner's authorization process may include a user control procedure that supports inviting other users to participate in private decentralized platform activities.
[0064] According to any of the embodiments or method embodiments herein, the cryptographically secure and reusable distributed identity may include a public-private key combination.
[0065] According to any of the embodiments or method embodiments herein, gate access may include assigning one or more user categories to the digital identities of such users.
[0066] According to one or more embodiments or any method embodiment herein, the one or more user categories include an owner, a member and a visitor.
[0067] According to one or more embodiments or any method embodiment herein, such digital information and services may include one or more security, privacy, personal data and computing provisions relative to the decentralized platform of the owner.
[0068] According to one or more embodiments, a decentralized platform includes at least one processor and an engine. The engine is configured to manage the distributed identities of users of the decentralized platform. The engine, executed by the at least one processor, generates a cryptographically secure and reusable distributed identity for an owner, obfuscating the owner's identity, and associates the cryptographically secure and reusable distributed identity with a blockchain of the decentralized platform. The engine, further executed by the at least one processor, gates access to digital information and services of one or more users of the decentralized platform via an owner authorization process. The digital information and services are associated with the cryptographically secure and reusable distributed identity.
[0069] According to one or more embodiments herein or any of decentralized platform embodiments, the cryptographically secure and reusable distributed identity may contain a password hash of a username to obfuscate the user’s identity.
[0070] According to one or more embodiments herein or any of the decentralized platform embodiments, the encrypted and reusable distributed identity can independently and securely manage the owner's digital information and services.
[0071] According to one or more embodiments of this document or any of the decentralized platform embodiments, the blockchain can guarantee the fidelity and security of the cryptographically secure and reusable distributed identity.
[0072] According to one or more embodiments herein or any of the decentralized platform embodiments, the owner authorization process may include a user control procedure that supports inviting one or more of the users of the decentralized platform to participate in private social media activities.
[0073] According to one or more embodiments herein or any of the decentralized platform embodiments, the owner authorization process may include a user control procedure that supports inviting other users to participate in private decentralized platform activities.
[0074] According to one or more embodiments herein or any of decentralized platform embodiments, the cryptographically secure and reusable distributed identity may contain a public-private key combination.
[0075] According to one or more embodiments herein or any of the decentralized platform embodiments, gate access may include assigning one or more user categories to the digital identities of such users.
[0076] According to one or more embodiments of this document or any of the decentralized platform embodiments, the one or more user categories include an owner, a member and a visitor.
[0077] According to any of the embodiments or decentralized platform embodiments herein, such digital information and services may include one or more security, privacy, personal data and computing provisions relative to the owner’s decentralized platform.
[0078] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. Accordingly, each block in the flowchart or block diagram may represent a module, fragment, or portion of instructions, including one or more executable instructions for implementing one or more specified logical functions. In some alternative implementations, the functions marked in the blocks may occur in a sequence other than that marked in the figures. For example, in fact, two blocks shown consecutively may be executed substantially simultaneously, or such blocks may sometimes be executed in reverse order. It will also be noted that the blocks of the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or block diagrams and / or flowcharts, may be implemented by a dedicated hardware-based system that performs a specified function or action or executes a combination of dedicated hardware and computer instructions.
[0079] Although the features and elements are described above in specific combinations, those skilled in the art will understand that each feature or element can be used alone or in combination with other features and elements. Furthermore, the methods described herein can be implemented in a computer program, software, or firmware incorporated in a computer-readable medium for execution by a computer or processor. As used herein, a computer-readable medium itself should not be construed as a transient signal, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.
[0080] Examples of computer-readable media include electrical signals (transmitted via wired or wireless connections) and computer-readable storage media. Examples of computer-readable storage media include (but are not limited to) a temporary cache memory, a semiconductor memory device, magnetic media such as internal hard disks and removable disks, magneto-optical media, optical media such as optical discs (CDs) and digital versatile discs (DVDs), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), and a memory stick. A processor associated with software can be used to implement a radio frequency transceiver for use in a terminal, base station, or any host computer.
[0081] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting. As used herein, unless the context clearly indicates otherwise, the singular forms "a" and "the" are intended to include the plural forms as well. It will be further understood that, when used in this specification, the term "comprising" specifies the presence of the stated features, integrals, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or groups thereof.
[0082] Various embodiments described herein have been presented for illustrative purposes, but are not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein has been chosen to best explain the principles of the embodiments, practical applications of technology found in the market, or technical improvements, or to enable those skilled in the art to understand the embodiments disclosed herein. [Simplified Explanation of the Diagram]
[0007] A more detailed understanding can be obtained from the following description given by way of example in conjunction with the accompanying drawings, wherein the same element symbols in the drawings indicate the same element, and wherein:
[0008] Figure 1 illustrates a method according to one or more embodiments;
[0009] Figure 2 illustrates an architecture according to one or more embodiments;
[0010] Figure 3 illustrates a system according to one or more embodiments;
[0011] Figure 4 illustrates a system and a method according to one or more embodiments;
[0012] Figure 5 illustrates a method according to one or more embodiments; and
[0013] Figure 6 illustrates a communication schematic diagram according to one or more embodiments.
Claims
1. A method for managing the distributed identities of users of a decentralized platform by an engine executed by at least one processor within the decentralized platform, the method comprising: The engine generates a cryptographically secure and reusable distributed identity for an owner that obfuscates the owner's identity. The engine associates the cryptographically secure and reusable distributed identity with one of the blockchains of the decentralized platform; and the engine, through an owner authorization process, controls access to the digital information and services of one or more users of the decentralized platform, which are associated with the cryptographically secure and reusable distributed identity.
2. The method of request item 1, wherein the cryptographically secure and reusable distributed identity includes a password hash of a username to obfuscate the user's identity.
3. The method of request item 1, wherein the encrypted, secure, and reusable distributed identity independently and securely manages the owner's digital information and services.
4. The method of request item 1, wherein the blockchain guarantees the fidelity and security of the cryptographically secure and reusable distributed identity.
5. The method of request item 1, wherein the owner authorization process includes a user control procedure that supports inviting one or more users of the decentralized platform to participate in one of the private social media activities.
6. The method of request item 1, wherein the owner authorization process includes a user control procedure that supports inviting other users to participate in private decentralized platform activities.
7. The method of request item 1, wherein the cryptographically secure and reusable distributed identity comprises a public-private key combination.
8. The method of claim 1, wherein gate access includes assigning one or more user categories to the digital identities of such users.
9. The method of request item 8, wherein the one or more user categories include an owner, a member and a visitor.
10. The method of claim 1, wherein the digital information and services include security, privacy, personal data and computational provisions relative to one or more of the decentralized platforms of the owner.
11. A decentralized platform comprising: At least one processor; And an engine configured to manage the distributed identities of users of a decentralized platform, the engine being executed by the at least one processor to: generate a cryptographically secure and reusable distributed identity for an owner that obfuscates one of the owner's identities; associate the cryptographically secure and reusable distributed identity with a blockchain of the decentralized platform; and access digital information and services of one or more of the users of the decentralized platform, such digital information and services being associated with the cryptographically secure and reusable distributed identity, via an owner authorization process gate.
12. A decentralized platform as described in Request 11, wherein the cryptographically secure and reusable distributed identity includes a password hash of a username to obfuscate the user's identity.
13. A decentralized platform as described in Request 11, wherein the cryptographically secure and reusable distributed identity independently and securely manages the owner’s digital information and services.
14. A decentralized platform as described in Request 11, wherein the blockchain guarantees the fidelity and security of the cryptographically secure and reusable distributed identity.
15. The decentralized platform as requested in item 11, wherein the owner authorization process includes a user control procedure that supports inviting one or more of the users of the decentralized platform to participate in private social media activities.
16. The decentralized platform as requested in item 11, wherein the owner authorization process includes a user control procedure that supports inviting other users to participate in private decentralized platform activities.
17. A decentralized platform as requested in item 11, wherein the cryptographically secure and reusable distributed identity comprises a public-private key combination.
18. A decentralized platform as described in claim 11, wherein gate access includes assigning one or more user categories to the digital identities of such users.
19. A decentralized platform as described in Request 18, wherein the one or more user categories include an owner, a member, and a visitor.
20. The decentralized platform as described in claim 11, wherein such digital information and services include one or more security, privacy, personal data and computing provisions relative to the owner of the decentralized platform.