Multifaceted Assertion Directory for Trustworthy Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a convenient and reliable method for obtaining and managing multifaceted assertions about subjects, particularly in scenarios where connections to the subjects are not available, leading to potential trust issues due to compromised issuers and limited confidence in assertion validity.

Innovation Solution

A method involving a multifaceted assertion directory system that allows obtaining and managing assertions through a network of assertion directory access servers, where assertions can be verified and signed by multiple entities, including issuers and subjects, to ensure trustworthiness and appropriateness for relying parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a relying party uses a traditional trust list to verify assertions, then the verification process is straightforward, but the risk of accepting incorrect assertions from compromised issuers increases due to the large size of the trust list

Engineering Contradiction:
Improveassertion verification processVSAvoidtrustworthiness of assertion
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the trust verification process by introducing a specific assertion issuer identifier that narrows down the trust validation scope. Instead of checking against the entire large trust list, the system divides the verification into targeted checks against specific identified issuers, making the process both easier and more reliable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a specific assertion issuer identifier that acts as a mediator between the relying party and the trust list. This identifier guides the verification process to the correct issuer without requiring the relying party to search through the entire trust list, thereby simplifying operation while maintaining reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a relying party obtains assertions from multiple sources, then the confidence in assertion validity increases, but the complexity of managing and verifying these assertions increases

Engineering Contradiction:
Improveconfidence in assertion validityVSAvoidassertion management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal assertion directory system that can handle multiple assertion sources and types through a unified interface. The system provides multi-functional capabilities including assertion registration, storage, discovery, and verification across diverse sources, thereby increasing confidence without proportionally increasing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The assertion directory serves as an intermediary that centralizes the management of assertions from multiple sources. It provides a unified access point that simplifies the complexity of handling multiple assertion sources while maintaining the ability to verify assertions with high confidence through centralized control and coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a subject publishes its certificate in a standard location as DANE does, then the relying party can easily discover it, but the system still lacks mechanisms to verify that the published certificate is the one the subject intends for use

Engineering Contradiction:
Improvecertificate discovery processVSAvoidcertificate authenticity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the subject can register assertions in the assertion directory and control what assertions are published and how they are verified. This feedback loop allows the subject to provide information about which certificates and assertions are intended for use, enabling easy discovery while ensuring authenticity through subject-controlled registration and verification processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10033535B2Multifaceted assertion directory system
Publication Date: 2018.07.24 VERISIGN INC
  • US10033535B2 patent drawing
  • US10033535B2 patent drawing
  • US10033535B2 patent drawing

AI summary

A method of providing one or more assertions about a subject is provided. The method includes obtaining, at an assertion directory access server and over a network, a first assertion about a first attribute of the subject from a first assertion issuer; obtaining, at the assertion directory access server and over a network, a second assertion about a second attribute of the subject from a second assertion issuer; and providing, from the assertion directory access server, the first assertion and the second assertion to an assertion directory authority server over a network.