Blockchain Credential Authentication Using Audit DIDs for Private Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in managing verified credentials, particularly in indirect relationships between customers and service providers, leading to authorization issues and difficulties in tracking digital identities while maintaining privacy and facilitating payment for credential usage.
Innovation Solution
A blockchain-based credential management system that uses decentralized identifiers (DIDs) and an audit engine to encrypt and manage credentials, allowing users to control their presentation and enabling payment per-use, while maintaining privacy and ensuring authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional centralized authentication systems are used to manage credentials, then authorization can be established between directly related parties, but indirect relationships among customers and providers cause undesirable authorization problems and complexity
Solution Approach 1:
The patent introduces a blockchain-based credential verification system that acts as an intermediary between indirectly related parties. The blockchain network enables service providers to verify credentials issued by third-party issuers without requiring direct relationships or complex authorization chains, resolving the contradiction by providing a neutral mediation layer.
Solution Approach 2:
The patent replaces traditional mechanical authorization systems (relying on direct contractual relationships and manual verification) with a cryptographic verification system based on blockchain technology. This substitution eliminates the need for complex authorization management in indirect relationships by using cryptographic proofs and decentralized verification.
2Reliability
If credentials are stored and managed centrally, then authentication can be performed, but user privacy is compromised and users lose control over their personal information
Solution Approach 1:
The patent segments the authentication system into separate components: credential issuance, credential storage, and credential verification. Users maintain control of their credentials in personal wallets, while verification occurs on-chain without exposing sensitive information. This segmentation allows reliable authentication while preserving user privacy and control.
Solution Approach 2:
The blockchain network serves as an intermediary that enables verification without direct access to sensitive credential data. The system uses cryptographic proofs and zero-knowledge techniques to verify credentials while keeping the actual credential information private, resolving the contradiction between authentication reliability and privacy protection.
3Productivity
If traditional credential management systems are used, then credentials can be issued and stored, but tracking user interactions is required which compromises privacy and increases complexity
Solution Approach 1:
The patent replaces traditional tracking-based credential management with a blockchain-based verification system. Instead of tracking user interactions through centralized logs, the system uses immutable blockchain records and cryptographic verification to manage credentials efficiently without compromising user privacy or requiring interaction tracking.
4Reliability
If service providers require direct relationships with customers for authorization, then security can be maintained, but flexibility in accessing services is reduced
Solution Approach 1:
The patent replaces relationship-based authorization security with cryptographic verification security. Service providers can securely verify credentials from any issuer on the blockchain network without requiring direct relationships, maintaining security through cryptographic proofs while enabling flexible service access for indirectly related parties.
Data Source
AI summary
A method, apparatus, system, and computer program product are provided for managing the usage of verified credentials. An issuer of credentials receives a request from a person for a credential. The issuer identifies the credential from information that is controlled by the issuer. The issuer identifies a decentralized identifier (DID) record for an audit engine from a blockchain network. The DID record for the audit engine includes a public key of that is associated with the audit engine. The issuer identifies a DID record for the person from the blockchain network. The DID record for the person includes a public key that is associated with the person. The issuer generates an encrypted credential by encrypting the credential and the DID record for the person based on the public key associated with the audit engine. The issuer sends the encrypted credential to the person.


