Multifaceted Assertion Directory for Trustworthy Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack a convenient and reliable method for obtaining and managing multifaceted assertions about subjects, particularly in scenarios where connections to the subjects are not available, leading to potential trust issues due to compromised issuers and limited confidence in assertion validity.
Innovation Solution
A method involving a multifaceted assertion directory system that allows obtaining and managing assertions through a network of assertion directory access servers, where assertions can be verified and signed by multiple entities, including issuers and subjects, to ensure trustworthiness and appropriateness for relying parties.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a relying party uses a traditional trust list to verify assertions, then the verification process is straightforward, but the risk of accepting incorrect assertions from compromised issuers increases due to the large size of the trust list
Solution Approach 1:
The patent segments the trust verification process by introducing a specific assertion issuer identifier that narrows down the trust validation scope. Instead of checking against the entire large trust list, the system divides the verification into targeted checks against specific identified issuers, making the process both easier and more reliable.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of a specific assertion issuer identifier that acts as a mediator between the relying party and the trust list. This identifier guides the verification process to the correct issuer without requiring the relying party to search through the entire trust list, thereby simplifying operation while maintaining reliability.
2Reliability
If a relying party obtains assertions from multiple sources, then the confidence in assertion validity increases, but the complexity of managing and verifying these assertions increases
Solution Approach 1:
The patent creates a universal assertion directory system that can handle multiple assertion sources and types through a unified interface. The system provides multi-functional capabilities including assertion registration, storage, discovery, and verification across diverse sources, thereby increasing confidence without proportionally increasing management complexity.
Solution Approach 2:
The assertion directory serves as an intermediary that centralizes the management of assertions from multiple sources. It provides a unified access point that simplifies the complexity of handling multiple assertion sources while maintaining the ability to verify assertions with high confidence through centralized control and coordination.
3Ease of operation
If a subject publishes its certificate in a standard location as DANE does, then the relying party can easily discover it, but the system still lacks mechanisms to verify that the published certificate is the one the subject intends for use
Solution Approach 1:
The patent implements a feedback mechanism where the subject can register assertions in the assertion directory and control what assertions are published and how they are verified. This feedback loop allows the subject to provide information about which certificates and assertions are intended for use, enabling easy discovery while ensuring authenticity through subject-controlled registration and verification processes.
Data Source
AI summary
A method of providing one or more assertions about a subject is provided. The method includes obtaining, at an assertion directory access server and over a network, a first assertion about a first attribute of the subject from a first assertion issuer; obtaining, at the assertion directory access server and over a network, a second assertion about a second attribute of the subject from a second assertion issuer; and providing, from the assertion directory access server, the first assertion and the second assertion to an assertion directory authority server over a network.


