Integration method based on a certification authority for decentralized identity systems based on selective disclosure
The certification authority integrates centralized and decentralized information into authentication certificates, addressing the need for 'Third Party' involvement in decentralized identity systems by creating enhanced certificates that include SD-JWTs, preserving the 'Third Party's operational status.
Patent Information
- Application Number
- PCT/IT2024/050109
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-29
- Filing Date
- 2024-05-29
- Publication Date
- 2025-09-04
AI Technical Summary
Existing decentralized identity systems require a 'Third Party' to assume responsibilities typically handled by a certification authority, necessitating changes in their behavior and interface.
A certification authority integrates centralized and decentralized information into a new authentication or signature certificate, transforming SD-JWTs into additional fields without altering the 'Third Party's behavior or interface.
Enables the creation of enhanced authentication or signature certificates that incorporate multiple SD-JWTs, maintaining the 'Third Party's existing operational integrity.
Smart Images

Figure IT2024050109_04092025_PF_FP_ABST
Abstract
Description
[0001] INTEGRATION METHOD BASED ON A CERTIFICATION
[0002] AUTHORITY FOR DECENTRALIZED IDENTITY SYSTEMS BASED
[0003] ON SELECTIVE DISCLOSURE
[0004] The present invention refers to an integration method based on a certification authority for decentralized identity systems using a Selective Disclosure JSON (JavaScript Object Notation) Web Token (SD-JWT) .
[0005] In particular, the invention concerns the preparation of a new authentication or signature certificate by a certification authority, starting from an authentication certificate to which information stored in at least one SD-JWT that refers to the same are an integrated subject of the authentication certificate.
[0006] In the integration method according to the invention, the certification authority constructs a new authentication or signature certificate that integrates centralized information (of the authentication certificate) and decentralized information (SD-JWT) which is transformed into further fields of the new certi ficate of authentication .
[0007] Patent document GB2598096 is known and concerns the authentication of users using Distributed
[0008] Identity Documents ( DIDs ) , also known as decentrali zed identi fication documents , which are based on Sel f-Sovereign Identities ( SS I s ) .
[0009] This popular document describes systems and methods for creating distributed identities for users that can be used to authenticate with services and protect user data and data items .
[0010] Patent document GB2598096 discloses an authentication method in which it is the responsibility of a " Third Party" to analyse the truthfulness and validity of the DID ( since it is the " Third Party" that resolves the DID) .
[0011] The main limitation of this well-known authentication method is that it requires the "Third Party" to change its profile of responsibility by taking on tasks that are typically performed by the certi fication authority .
[0012] Obj ect of the present invention is solving the aforementioned prior art problems by providing an integration method based on a certi fication authority for decentrali zed identity systems that does not require the " Third Party / Service Provider" to change its behaviour and its interface , letting it continue to process only authentication certi ficates , while the certi fication authority builds an authentication certi ficate that integrates centrali zed information of the authentication certi ficate and decentrali zed information ( SD-JWT ) that are trans formed into additional fields of the authentication certi ficate .
[0013] Another obj ect of the present invention is building an authentication or signature certi ficate that integrates information relating to multiple SD-JWTs into the same authentication or signature certi ficate .
[0014] The above and other obj ects and advantages of the invention, as will appear from the following description, are achieved with an integration method based on a certi fication authority for decentrali zed identity systems such as the one claimed in the independent claim . Preferred embodiments and non-trivial variations of the present invention are the subj ect matter of the dependent claims .
[0015] The method of the present invention can advantageously be implemented through a computer program comprising program coding means for implementing one or more steps of the method when such program is executed on a computer . The scope of protection extends to such computer program and also to computer-readable media containing a recorded message , such computer-readable media including program coding means for implementing one or more steps of the method when such program is executed on a computer .
[0016] It is understood that the attached claims form an integral part of this description .
[0017] It will be immediately obvious that countless variations and modi fications can be made to what i s described ( for example relating to shape , dimensions , arrangements and parts with equivalent functionality) without departing from the scope of the invention as appears from the attached claims .
[0018] The present invention will be better described by a preferred embodiment thereof , provided as a non-limiting example , with reference to the attached drawings , in which :
[0019] Figure 1 shows a block diagram of an integration method based on a certi fication authority for decentrali zed identity systems according to the present invention.
[0020] Referring to Figure 1, a preferred embodiment of an integration method based on a certification authority for decentralized identity systems is shown and described, which includes the following steps :
[0021] - a step 101 of acquisition of input data by the certification authority, in which data relating to an authentication certificate, preferably of the X.509 type, and data relating to at least one SD- JWT are acquired;
[0022] - a step 102 for verifying the validity of the authentication certificate (preferably of the X.509 type) : in the event of a negative verification, the execution ends 103 with an error message, in case of a positive verification, the method moves on to a step 104 of construction of a new authentication or signature certificate (preferably of the X.509 type) considering all relevant information present in the authentication certificate (preferably of the X.509 type) of inputs ,
[0023] - a step 105 in which one of the input SD-JWTs is considered, a step 106 for verifying that the SD-JWT refers to the same subject as the authentication certificate (preferably of the X.509 type) ; preferably said verification step 106 includes a first sub-step of verifying the identity of the subject to which the SD-JWT refers, performed considering any Key Binding present in the SD-JWT, and a second sub-step of verifying that the identity of the subject to whom the SD-JWT refers is the same as that present in the authentication certificate (preferably of the X.509 type) , also considering the information present within the SD- JWT,
[0024] - in the event of a positive outcome of step 106, verifying that the SD-JWT refers to the same subject as the authentication certificate (preferably of a type based on the internal contents of the SD-JWT and on any lists of revocation of validity of the SD-JWT published by the original issuer of the SD-JWT (Issuer or Issuing Authority) . Said verification step 107 includes a first sub-step of verifying the validity of the SD-JWT with respect to their validity period, a second sub-step of verifying that a revocation notice referring to the same SD-JWT has not been published by the same issuing authority (Issuer or Issuing Authority) and a third sub-step of verification that the keys with which the SD-JWT was signed have not been revoked or expired. In the event of a negative outcome of step 106, verifying that the SD-JWT refers to the same subject as the authentication certificate and / or in the event of a negative outcome of step 107, verifying the validity of the SD-JWT, the method moves on to a step 111 to verify the presence of other SD-JWTs to be processed,
[0025] - in the event of a positive outcome of step 107 of verifying the validity of the SD-JWT, there is a step 108 of determining which information reported in the SD-JWT is relevant to identify roles, attributions, qualifications and powers of the subject indicated by the certificate of authentication (preferably of the X.509 type) ,
[0026] - a step 109 of converting the relevant information reported in the SD-JWT into a series of fields of the authentication or signature certificate (preferably of the X.509 type) ,
[0027] - a step 110 of adding the fields referred to in step 109 preceding the new authentication or signature certificate (preferably of the X.509 type) , - a step 111 of verifying the presence of other SD- JWTs to be processed: in the event of a positive outcome of the verification step 111, the method returns to step 105 in which one of the input SD- JWTs is considered and continues with the subsequent steps described previously,
[0028] - in the event of a negative outcome of the step 111 of verifying the presence of other SD-JWTs, the method goes to an output step 112 with issuing of the new authentication or signature certificate (preferably of the X.509 type) including the relevant information reported in the at least one input SD-JWT which are inserted into a series of fields of the new authentication or signature certificate (preferably of the X.509 type) .
[0029] Below, an example of a usage scenario of the integration method based on a certification authority for decentralized identity systems of the invention is described: a) A person wants to sign a contract; b) To do this, the person identifies himself electronically with his Electronic Identity Card (CIE) , which contains an X.509 authentication certificate (centralized) ; c) To sign, the person must demonstrate, for example, that it is registered with a medical association; d) The person has this certification, but in the form of an SD-JWT that he received from the medical association; this SD-JWT-R contains within it relevant information to identify the person to whom it refers and to determine whether, after issuance, this SD-JWT has been revoked; e) The person authenticates with a certification authority (to which he can present an Electronic Identity Card) also presenting the SD-JWT or a subset of the fields thereof (selective disclosure) ; f) The certification authority verifies that the SD-JWT refers to the same person who authenticated and that it is valid, also by verifying the information reported in the SD-JWT; g) In this case, the certifying authority creates a new X.509 authentication or signature certificate, in which, in addition to information coming from the Electronic Identity Card there are further information certifying that the person is a doctor; h) The person uses this certificate to sign, as a doctor (for example a report or a legal report) ; i) To put this signature, the signature system managed the X.509 authentication certificate produced by the certification authority, maintaining its already existing functional interface (and not having to know or discover anything about the SD-JWT) ; j) The produced role in the coming times, to stay with the example; k) In any case, when the certifying authority learns that the person is no longer a doctor, it can revoke the X.509 produced with this additional information .
[0030] Advantageously, the integration method based on a certification authority for decentralized identity systems according to the invention does not require the "Third Party / Service Provider" to change its behaviour and its interface, leaving it to continue to process exclusively authentication or signature certificates, leaving the Certification Authority the task of building an authentication certificate that integrates centralized information from the authentication certificate and decentralized information (SD-JWT) .
[0031] Another advantage of the present invention is that it allows the creation of an authentication or signature certificate that integrates information relating to multiple SD- JWTs in the same authentication or signature certificate.
Claims
CLAIMS1. Integration method based on a certification authority for decentralized identity systems, including the following steps:- a step (101) of acquisition of input data by the certification authority, in which data relating to an authentication certificate and data relating to at least one SD-JWT are acquired, a step (102) to verify the validity of the authentication certificate: in the event of a negative verification, the execution ends (103) with an error message, in case of positive verification, the method moves on to a step (104) of construction of a new authentication certificate considering all relevant information present in the input authentication certificate,- a step (105) in which one of the input SD-JWTs is considered,- a step (106) of verifying that the input SD-JWT refers to the same subject as the authentication certificate, in the event of a positive outcome of the verification step (106) , the method moves on to a step (107) of verifying the validity of the SD-JWT,- in the event of a positive outcome of the step (107) of verifying the validity of the SD-JWT, the method has a step (108) of determining which information reported in the SD-JWT is relevant to identify the roles, attributions, qualifications and powers of the subject indicated by the authentication certificate, a step (109) of converting the relevant information reported in the SD-JWT into a series of fields of the authentication or signature certificate,- a step (110) of adding the fields referred to in step (109) previous to the new authentication or signature certificate,- a step (111) to verify the presence of other SD- JWTs to be processed,- in the event of a negative outcome of the step (111) of verifying the presence of other SD-JWTs to be processed, there is an output step (112) with the issuing of the new authentication or signature certificate including the relevant information reported in the SD-JWT that are inserted into a series of fields of the new authentication certificate .
2. Integration method based on a certificationauthority for decentralized identity systems according to claim 1, characterized in that, in the event of a negative outcome of the verification step (106) , the SD-JWT refers to the same subject as the certificate authentication and / or in the event of a negative outcome of the step (107) of verifying the validity of the SD-JWT, the method moves on to the step (111) of verifying the presence of other SD-JWTs to be processed.
3. Integration method based on a certification authority for decentralized identity systems according to claim 1 or 2, characterized in that, in the event of a positive outcome of the verification step (111) , the method returns to the step (105) in which one considers one of the input SD-JWTs and continues with the subsequent steps described in the previous claims.
4. Integration method based on a certification authority for decentralized identity systems according to any of the previous claims, characterized in that said step (106) of verifying that the input SD-JWT refers to the same subject as the certificate authentication includes a first sub-step of verifying the identity of the subject to whom the SD-JWT refers and a second sub-step ofverifying that the identity of the subject to whom the SD-JWT refers is the same as that present in the authentication certificate.
5. Integration method based on a certification authority for decentralized identity systems according to any of the previous claims, characterized in that, in the step (101) of acquisition of the input data by the certification authority, each SD-JWT refers to at least one distributed identity document (DID) and characterized in that said step (107) of verifying the validity of the SD-JWT is performed both on the basis of the internal contents of the SD-JWT and of any revocation lists published by the Issuer, wherein, in step (108) , it is determined which information reported in the SD-JWT are relevant and in step (109) the conversion of the relevant information reported in the SD-JWT takes place.
6. Integration method based on a certification authority for decentralized identity systems according to claim 5, characterized in that said step (107) of verifying the validity of the SD-JWT includes a first sub-step of verifying the validity of the SD-JWT based on its validity period, a second sub-step of verifying that a revocation ofthe SD-JWT has not been issued by the same issuing authority and a third sub-step of verifying that the keys with which the SD-JWT was signed have not been revoked or expired.
7. Integration method based on a certification authority for decentralized identity systems according to claim 5 or 6, characterized in that said verification step (106) includes the first sub-step of verifying the identity of the subject to which it refers the SD-JWT which is performed considering the information contained in the SD-JWT itself .
8. Integration method based on a certification authority for decentralized identity systems according to any of the previous claims, characterized in that the authentication or signature certificate is an X.509 type certificate.
9. Computer program comprising computer program coding means adapted to perform all the steps of claims 1 to 8 when said program is executed on a computer .
10. Computer readable medium on which a program is recorded, said computer readable medium comprising computer program coding means adapted to perform all steps of claims 1 to 8 when said program isexecuted on a computer.
Citation Information
Patent Citations
Method for authenticating using distributed identities
GB2598096A
Method for purifying vinyl acetate
KR1020240033400A