Integration method based on a certification authority for decentralized identity systems
The certification authority integrates centralized and decentralized information into authentication certificates, addressing the need for enhanced authentication without altering the 'Third Party's behavior, thus improving decentralized identity system efficiency.
Patent Information
- Application Number
- PCT/IT2025/050030
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-29
- Filing Date
- 2025-02-12
- Publication Date
- 2025-09-04
AI Technical Summary
Existing decentralized identity systems require the 'Third Party' to assume responsibilities typically handled by a certification authority, necessitating changes in their behavior and interface.
A certification authority integrates centralized and decentralized information into a new authentication certificate without altering the 'Third Party's behavior or interface, incorporating Verifiable Credentials (VC) and Distributed Identity Documents (DID) into the certificate fields.
Enables the creation of an authentication certificate that integrates multiple credentials without requiring the 'Third Party' to change their processes, maintaining existing functionality while enhancing authentication capabilities.
Smart Images

Figure IT2025050030_04092025_PF_FP_ABST
Abstract
Description
[0001] INTEGRATION METHOD BASED ON A CERTIFICATION
[0002] AUTHORITY FOR DECENTRALIZED IDENTITY SYSTEMS
[0003] The present invention refers to an integration method based on a certification authority for decentralized identity systems that use Verifiable Credentials (VC) and Decentralized Identifiers, in particular Distributed Identity Documents (DID) .
[0004] In particular, the invention concerns the preparation of a new authentication certificate by a certification authority, starting from an authentication certificate which integrates information stored in at least one Verifiable Credential (VC) and possibly associated with at least one Distributed Identity Document (DID) that refers to the same subject as the authentication certificate .
[0005] In the integration method according to the invention, the certification authority constructs a new authentication certificate that integrates centralized information (of the authentication certificate) and decentralized information (VC and DID) which is trans formed into further fields of the new authentication certi ficate .
[0006] Patent document GB2598096 is known and relates to the authentication of users using distributed identity documents ( DIDs ) , also known as decentrali zed identi fication documents , which are based on sel f-sovereign identities ( SS I s ) .
[0007] This popular document describes systems and methods for creating distributed identities for users that can be used to authenticate with services and protect user data and data items .
[0008] Patent document GB2598096 describes an authentication method wherein it is the responsibility of a " Third Party" to analyse the truthfulness and validity of the DID ( since it is the " Third Party" that resolves the DID) .
[0009] The main limitation of this well-known authentication method is that it requires the "Third Party" to change its profile of responsibility by taking on tasks that are typically performed by the certi fication authority .
[0010] Document KR-A-2022 0112013 describes a prior art integration method .
[0011] Obj ect of the present invention is solving the aforementioned prior art problems by providing an integration method based on a certi fication authority for decentrali zed identity systems that does not require the " Third Party / Service Provider" to change its behaviour and its interface , letting it continue to process only authentication certi ficates , while the certi fication authority builds an authentication certi ficate that integrates centrali zed information from the authentication certi ficate and decentrali zed information (VC and DID) which is trans formed into further fields of the certi ficate of authentication .
[0012] Another obj ect of the present invention is building an authentication certi ficate that integrates information relating to multiple Veri fiable Credentials and Distributed Identity Documents (VCs and DIDs ) into the same authentication certi ficate .
[0013] The above and other obj ects and advantages of the invention, as will appear from the following description, are achieved with an integration method based on a certi fication authority for decentrali zed identity systems such as the one described in the independent claim . Preferred embodiments and non-trivial variants of the present invention form the subj ect of the dependent claims .
[0014] The method of the present invention can advantageously be implemented through a computer program comprising program coding means for implementing one or more steps of the method when such program is executed on a computer . The scope of protection extends to such computer program and also to computer-readable media containing a recorded message , such computer-readable media including program coding means for implementing one or more steps of the method when such program is executed on a computer .
[0015] It is understood that the attached claims form an integral part of this description .
[0016] It will be immediately obvious that countless variations and modi fications can be made to what i s described ( for example relating to shape , dimensions , arrangements and parts with equivalent functionality) without departing from the scope of the invention as appears from the attached claims .
[0017] The present invention will be better described by a preferred embodiment thereof , provided by way of example and not by way of limitation, with reference to the attached drawings , wherein :
[0018] Figure 1 shows a block diagram of an integration method based on a certification authority for decentralized identity systems according to the present invention.
[0019] Referring to the Figure, a preferred embodiment of a certification authority-based integration method for decentralized identity systems is illustrated and described; the method comprises the following steps:
[0020] - a step 101 of acquisition of input data by the certification authority, wherein the data relating to an authentication certificate, preferably of the X.509 type, and the data relating to at least one Verifiable Credential (VC) are acquired, each VC being able to refer to at least one Distributed Identity Document (DID) ;
[0021] - a step 102 for verifying the validity of the authentication certificate (preferably of the X.509 type) : in the event of a negative verification, the execution ends 103 with an error message;
[0022] - in case of positive verification, moving on to a step 104 of construction of a new authentication certificate (preferably of type X.509) considering all the relevant information present in the input authentication certificate
[0023] (preferably of the X.509 type) ; a step 105 wherein one of the input
[0024] Verifiable Credentials (VC) is considered;
[0025] - a step 106 for verifying that the Verifiable Credential (VC) refers to the same subject as the authentication certificate (preferably of the X.509 type) ; preferably said verification step 106 includes a first sub-step of verifying the identity of the subject to which the Verifiable Credential (VC) refers, carried out considering any Distributed Identity Documents (DID) contained therein, and a second sub-step of verifying that the identity of the subject to whom the Verifiable Credential (VC) refers is the same as that present in the authentication certificate (preferably of the X.509 type) ;
[0026] - in the event of a positive outcome of the step 106 of verifying that the Verifiable Credential (VC) refers to the same subject as the authentication certificate (preferably of the X.509 type) , moving on to a step 107 of verifying the validity of the Verifiable Credential (VC) both on the basis of the internal contents of the Verifiable Credential (VC) and of any Distributed Identity Documents (DID) reported in the Verifiable Credential itself. Said verification step 107 includes a first sub-step of verifying the validity of the VC and the DID with respect to their validity period, a second sub-step of verifying that an updated DID referring to the same subject has not been issued by the same issuing authority (Issuing Authority) and a third sub-step of verification that the keys with which the VC or DID was signed have not been revoked or expired. In the event of a negative outcome of the step 106 of verifying that the VC and the DID refer to the same subject as the authentication certificate and / or in the event of a negative outcome of the step 107 of verifying the validity of the Verifiable Credential (VC) or of the Verification Document Distributed Identity (DID) , moving on to a step 111 of verifying the presence of other Verifiable Credentials (VC) to be processed;
[0027] - in the event of a positive outcome of the step 107 of verifying the validity of the Verifiable Credential (VC) and any Distributed Identity Documents (DID) associated therewith, there is a step 108 of determining which information reported in the Verifiable Credential (VC) and in the Distributed Identity Document (DID) are relevant to identify roles, attributions, qualifications and powers of the subject indicated by the authentication certificate (preferably of the X .509 type) ; a step 109 of conversion of the relevant information reported in the Verifiable Credential (VC) and in the Distributed Identity Document (DID) associated therewith in a series of fields of the authentication certificate (preferably of the X.509 type) ;
[0028] - a step 110 of adding the fields referred to in step 109 preceding the new authentication certificate (preferably of the X.509 type) ;
[0029] - a step 111 of verifying the presence of other Verifiable Credentials (VC) to be processed: in the event of a positive outcome of the verification step 111, returning to step 105 wherein one of the input Verifiable Credentials (VC) is considered and continuing with the subsequent steps described above,
[0030] - in the event of a negative outcome of the step 111 of verifying the presence of other Verifiable Credentials (VC) to be processed, there is an output step 112 with the issuing of the new authentication certificate (preferably of the X.509 type) including the relevant information reported in at least one input Verifiable Credential (VC) which are inserted in a series of fields of the new authentication certificate (preferably of the X.509 type) .
[0031] Below, an example of a usage scenario of the integration method based on a certificate authority for decentralized identity systems of the invention is described: a) A person wants to sign a contract; b) To do this, he / she identifies himself / herself electronically with his / her Electronic Identity Card (CIE) , which contains an X.509 authentication certificate (centralized) ; c) To sign, the person must demonstrate, for example, that he / her is registered with the medical association; d) The person has this attestation, but in the form of a Verifiable Credential (VC) that he / she received from the medical association; this Verifiable Credential refers to a Distributed Identity Document (DID) which contains further information relevant to determining the validity of this certification; e) The person authenticates with a certifying authority (to which he / she can present the CIE) also presenting the VC; f) The certifying authority verifies that the VC refers to the same person who authenticated and that he / her is valid, also by verifying the information reported in the DID associated with the VC; g) In this case, the certifying authority creates a new X.509 authentication certificate, wherein in addition to the information coming from the Electronic Identity Card there is further information certifying that the person is a doctor; h) The person uses this certificate to sign, as a doctor (for example a report or a legal report) ; i) To put this signature, the signature system managed the X.509 authentication certificate produced by the certification authority, maintaining its already existing functional interface (and not having to know or discover anything about the VCs or DIDs) ; j) The produced X.509 authentication certificate can comprise an information that has a limited length, that can be used only once, or similar use restrictions (because the person could be a doctor, but could lose such role in the future , to remain with this example ) ; k) In any case , when the certi fying authority learns that the person is no longer a doctor, it can revoke the X . 509 produced with this additional information .
[0032] Advantageously, the integration method based on a certi fication authority for decentrali zed identity systems according to the invention does not require the " Third Party / Service Provider" to change its behaviour and its interface , leaving it to continue to process exclusively authentication certi ficates , leaving the Certification Authority the task of building an authentication certi ficate that integrates centrali zed information from the authentication certi ficate and decentrali zed information ( DID) .
[0033] Another advantage of the present invention is that it allows the creation of an authentication certi ficate that integrates information relating to multiple Veri fiable Credentials (VC ) in the same authentication certi ficate .
[0034] Preferred embodiments of the invention have been described, but naturally it is susceptible to further modi fications and variations within the same inventive idea . In particular, numerous variations and modi fications functionally equivalent to the previous ones , which fall within the scope of the invention as highlighted in the attached claims , will be immediately evident to those skilled in the art .
Claims
CLAIMS1. Integration method based on a certification authority for decentralized identity systems, comprising the following steps:- a step (101) of acquisition of input data by the certification authority, wherein the data relating to an authentication certificate and the data relating to at least one Verifiable Credential (VC) are acquired;- a step (102) to verify the validity of the authentication certificate: in the event of a negative verification, the execution ends (103) with an error message;- in case of positive verification, moving on to a step (104) of construction of a new authentication certificate considering all the relevant information present in the input authentication certificate; a step (105) wherein one of the input Verifiable Credentials (VC) is considered; a step (106) to verify that the input Verifiable Credential (VC) refers to the same subject as the authentication certificate;- in the event of a positive outcome of the verification step (106) , moving on to a step (107)of verifying the validity of the Verifiable Credential (VC) ;- in the event of a positive outcome of the step (107) of verifying the validity of the Verifiable Credential (VC) , there is a step (108) of determining which information reported in the Verifiable Credential (VC) is relevant for identifying roles, attributions, qualifications and powers of the person indicated by the authentication certificate; a step (109) of converting the relevant information reported in the Verifiable Credential (VC) into a series of fields of the authentication certificate;- a step (110) of adding the fields referred to in step (109) previous to the new authentication certificate;- a step (111) to verify the presence of other Verifiable Credentials (VC) to be processed,- in the event of a negative outcome of the step (111) of verifying the presence of other Verifiable Credentials (VC) to be processed, there is an output step (112) with the issuing of the new authentication certificate including the relevant information reported in the Verifiable Credential(VC) which are inserted in a series of fields of the new authentication certificate.
2. Integration method based on a certification authority for decentralized identity systems according to claim 1, characterized in that, in the event of a negative outcome of the verification step (106) that the Verifiable Credential (VC) refers to the same subject of the authentication certificate and / or in the event of a negative outcome of the step (107) of verifying the validity of the Verifiable Credential (VC) , it comprises the step of moving on to the step (111) of verifying the presence of other Verifiable Credentials (VC) to be processed.
3. Integration method based on a certification authority for decentralized identity systems according to claim 1 or 2, characterized in that, in case of a positive outcome of the verification step (111) , returning to the step (105) wherein one of the input Verifiable Credentials (VC) are considered and continuing with the subsequent steps described in the previous claims.
4. Integration method based on a certification authority for decentralized identity systems according to any of the previous claims,characterized in that said step (106) of verification that the input Verifiable Credential (VC) refers to the same subject as the authentication certificate includes a first substep of verifying the identity of the subject to whom the Verifiable Credential (VC) refers and a second sub-step of verifying that the identity of the subject to whom the Verifiable Credential (VC) refers is the same one present in the authentication certificate.
5. Integration method based on a certification authority for decentralized identity systems according to any of the previous claims, characterized in that, in the step (101) of acquisition of the input data by the certification authority, each Verifiable Credential (VC) refers to at least one distributed identity document (DID) and characterized in that said step (107) of verifying the validity of the Verifiable Credential (VC) is performed on the basis both of the internal contents of the Verifiable Credential (VC) and of the Distributed Identity Document (DID) reported in the Verifiable Credential itself, wherein in step (108) it is determined which information reported in the Verifiable Credential (VC) and in theDistributed Identity Document (DID) are relevant and in step (109) there is the conversion of the relevant information reported in the Verifiable Credential (VC) and in at least one Distributed Identity Document (DID) associated therewith.
6. Integration method based on a certification authority for decentralized identity systems according to claim 5, characterized in that said step (107) of verifying the validity of the Verifiable Credential (VC) includes a first substep of verifying the validity of the Verifiable Credential (VC) on the basis of its validity period, a second sub-step of verification that an updated distributed identity document (DID) referring to the same subject has not been issued by the same issuing authority and a third sub-step of verification that the keys with which the Verifiable Credential (VC) and / or the distributed identity document (DID) associated therewith was signed have not been revoked or expired.
7. Integration method based on a certification authority for decentralized identity systems according to claim 5 or 6, characterized in that said verification step (106) includes a first substep of verifying the identity of the subject towhich the Verifiable Credential (VC) refers, which is performed considering the Distributed Identity Documents (DID) contained therein.
8. Integration method based on a certification authority for decentralized identity systems according to any of the previous claims, characterized in that the authentication certificate is an X.509 type certificate.
9. A computer program comprising computer program coding means adapted to perform all the steps of the method of claims 1 to 8 when said program is executed on a computer.
10. A computer readable medium on which a program is recorded, said computer readable medium comprising computer program coding means adapted to perform all the steps of the method of claims 1 to 8 when said program is executed on a computer.
Citation Information
Patent Citations
Method for authenticating using distributed identities
GB2598096A
Method for purifying vinyl acetate
KR1020240033400A
Cited By
Dynamically verifying authenticity and validity of credentials
US12659168B2