Privacy-Preserving Age Verification via Selective Data Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for proving user information, such as age verification, often compromise privacy by revealing unnecessary personal information, as they require presenting valid identity documents that contain additional sensitive data.
Innovation Solution
A method involving a requester device, server, and verifier device that generates and verifies proof of user information using requester authentication data and transaction identifying data, ensuring that only the requested information is shared without disclosing other personal details, utilizing secure elements like SIM cards or eUICC for secure data processing and communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a user presents an identity document to prove age, then age verification is achieved, but other personal information is exposed
Solution Approach 1:
The patent extracts only the necessary attribute (age) from the complete identity document and presents it in isolation through a structured proof format. The verification system retrieves and validates only the specific age information without exposing other personal details contained in the original document, thereby achieving selective information disclosure.
Solution Approach 2:
The identity verification process is segmented into distinct components: the original identity document, the extraction of specific age information, the generation of a structured proof containing only age and verification metadata, and the final verification step. This segmentation allows the age attribute to be separated and validated independently from other personal information.
2Loss of information
If a digital proof system is implemented, then privacy is preserved, but system complexity increases
Solution Approach 1:
The patent introduces a server as an intermediary component that mediates between the user's identity document and the verification system. The server stores authentication data, generates structured proofs, and validates verification requests, thereby managing the complexity centrally rather than distributing it across multiple client devices.
Solution Approach 2:
Instead of requiring the original identity document to be physically present or digitally scanned, the system creates a standardized copy or representation of the age verification proof. This structured proof contains only the necessary age information in a predetermined format, eliminating the need to handle or store the complete original document.
3Ease of operation
If traditional identity document presentation is used, then verification is simple, but privacy security is compromised
Solution Approach 1:
The patent changes the parameter of information disclosure from complete document presentation to selective attribute presentation. Instead of transmitting or displaying the entire identity document, the system transforms the verification process to output only the age parameter in a structured format, fundamentally altering what information is revealed during verification.
Solution Approach 2:
Rather than having the user actively present their identity document to the verifier, the system inverts the process by having the server generate and provide a structured proof of age verification. This reversal eliminates the need for the user to physically or digitally hand over their complete identity document, thereby preserving privacy while maintaining verification integrity.
Data Source
Figure 1~2
AI summary
The invention relates to a method 20 for proving at least one piece of user information. According to the invention, the method comprises the following steps. A requester device 12 sends to a server 18 a first message 22 including a request for proving at least one piece of user 11 information and data identifying a requester. The server generates 24 requester authentication data and associated data identifying a transaction. The server generates 26 a proof of user information using the at least one piece of user information and the requester authentication data. The server sends to the requester device a second message 28 including, as a request response, the proof of user information and the associated data identifying the transaction. A verifier device 12 sends to the server a third message 214 including a request for getting authentication data associated with data identifying a transaction and the associated data identifying the transaction. The server sends to the verifier device a fourth message 218 including, as a request response, authentication data associated with the data identifying the transaction. The verifier device or a verifier 19 authenticates the at least one piece of user information only if the received authentication data matches the requester authentication data. The invention also relates to corresponding requester device, verifier device and server.