Auxiliary Credential for Granular Attribute Revocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing credential systems lack efficient mechanisms for revoking individual attributes within cryptographic credentials, requiring complete revocation of credentials and not allowing for granular control over attribute validity, which can be cumbersome and inefficient.

Innovation Solution

A method and system that utilize an auxiliary credential, bound to the attribute credential, to certify the validity status of each attribute, allowing for individual attribute revocation and validation, enabling flexible and efficient authorization processes without requiring the re-issue of the entire credential.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a credential is completely revoked to remove invalid attributes, then security is maintained, but operational flexibility and efficiency deteriorate due to loss of valid attributes

Engineering Contradiction:
Improvecredential securityVSAvoidattribute revocation flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the credential into two distinct components: the attribute credential containing the attributes, and the auxiliary credential containing the validity status of each attribute. This segmentation allows the system to revoke or validate individual attributes without affecting the entire credential, thus maintaining security while improving operational flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The auxiliary credential acts as an intermediary between the attribute credential and the verifier. It provides the validity status information without requiring the verifier to interact directly with the revocation authority, enabling efficient verification while maintaining security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complete credential re-issue is performed to restore valid attributes after revocation, then credential integrity is maintained, but time and operational efficiency worsen

Engineering Contradiction:
Improvecredential integrityVSAvoidcredential re-issue time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by issuing the auxiliary credential that pre-certifies the validity status of attributes. When attributes need to be restored, only the auxiliary credential needs to be updated rather than re-issuing the entire attribute credential, significantly reducing the time and operations required.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By segmenting the credential system into attribute credential and auxiliary credential components, the patent enables independent updating of the auxiliary credential to restore attribute validity without requiring complete credential re-issuance, thus maintaining integrity while reducing time loss.

Inventive Principle:
Principle #1Segmentation

3Reliability

If verifiers continuously check revocation information to ensure credential validity, then security is improved, but communication overhead and system complexity worsen

Engineering Contradiction:
Improvecredential validity verificationVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The auxiliary credential serves as an intermediary that embeds revocation information directly within the credential structure. Verifiers can check validity by examining the auxiliary credential locally without needing to continuously communicate with the revocation authority, reducing communication overhead and system complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10833873B2Credential-based authorization
Publication Date: 2020.11.10 WORKDAY INC
  • US10833873B2 patent drawing
  • US10833873B2 patent drawing
  • US10833873B2 patent drawing

AI summary

Methods and systems are provided for demonstrating authorization to access a resource to a verifier computer controlling access to the resource. The method comprises, at a user computer, storing an attribute credential certifying a set of attributes; and communicating with a revocation authority computer to obtain an auxiliary credential, bound to the attribute credential, certifying a validity status for each attribute in the attribute credential. The method further comprises, at the user computer, communicating with the verifier computer to prove possession of the attribute credential and the auxiliary credential such that the verifier computer can determine whether at least one attribute in the attribute credential, certified as valid by the auxiliary credential, satisfies an access condition for the resource.