Blockchain Digital Identity Management via Smart Contract and Hash Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional blockchain technology lacks an effective framework for digital identity management and permission controls within distributed network nodes, particularly in maintaining identities and permissions within blockchain entities.

Innovation Solution

Implementing a system and method for blockchain-based digital identity and permission controls, where smart contracts automatically and intelligently manage and update immutable records of digital identity and permission controls by generating and deploying encrypted digital identity records to a blockchain, using one-way cryptographic hashes and encryption keys, and associating them with smart contracts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional blockchain technology is used, then data integrity is ensured through distributed ledgers, but digital identity management and permission controls are not effectively provided

Engineering Contradiction:
Improvedata integrityVSAvoiddigital identity management capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges digital identity management functionality with the blockchain infrastructure by integrating smart contracts that automatically manage identities and permissions. The system combines the distributed ledger's data integrity features with identity frameworks, allowing blockchain entities to have maintained identities and permission controls without sacrificing the integrity guarantees provided by the distributed ledger architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Smart contracts serve as intermediaries between the blockchain's data storage capabilities and the need for identity management. These intermediary contracts automatically handle identity creation, maintenance, and permission controls, bridging the gap between simple data recording and complex identity management requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If digital identity records are stored on the blockchain, then immutability is achieved, but data privacy and security are compromised due to exposure of sensitive information

Engineering Contradiction:
ImproveimmutabilityVSAvoiddata privacy risk
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive personal information from the blockchain storage. Instead of storing actual biometric data, documents, or personal identifiers on the chain, the system stores only cryptographic hashes and references. The actual sensitive data is kept in private off-chain storage, thereby maintaining blockchain immutability while removing harmful exposure of sensitive information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates a cryptographic copy (hash) of sensitive data and stores that on the blockchain instead of the original data. This copy preserves the immutability and verification capabilities while the actual sensitive information remains in secure private storage, effectively decoupling the immutable record from the sensitive content.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If reference documents and biometric information are stored in non-blockchain repositories, then data privacy is improved, but system complexity increases due to multiple storage locations

Engineering Contradiction:
Improvedata privacyVSAvoidstorage architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

Cryptographic hashes act as intermediaries between the private storage repositories and the public blockchain. These hashes enable verification of data integrity and linkage to off-chain storage without exposing the actual sensitive data on the blockchain, thereby maintaining privacy while managing the distributed storage architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments storage into two distinct locations: private off-chain repositories for sensitive data and the blockchain for immutable records and hashes. This segmentation allows each component to serve its optimal function - private storage for security and blockchain for integrity - while reducing overall system complexity compared to attempting to store everything on-chain.

Inventive Principle:
Principle #1Segmentation

4Productivity

If smart contracts are used to automatically manage digital identities, then operational efficiency is improved, but implementation complexity increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsmart contract implementation
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Smart contracts implement self-service automation where the system automatically manages digital identity creation, updates, and permission controls without manual intervention. The contracts execute predefined logic to handle identity operations autonomously, improving operational efficiency by eliminating manual administrative tasks and reducing human error.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11128467B2Systems and methods for digital identity management and permission controls within distributed network nodes
Publication Date: 2021.09.21 NORTHERN TRUST CORP
  • US11128467B2 patent drawing
  • US11128467B2 patent drawing
  • US11128467B2 patent drawing

AI summary

Embodiments disclosed herein provide systems and methods for digital identity management and permission controls within distributed network nodes. A network node may receive a request to generate a new digital identity record for an entity. The network node may retrieve a template based on an entity type; and receive information, reference documents, and biometric information for the new digital identity record. The network node may associate and store the received information to the data fields in the new digital identity record, generate respective one directional cryptographic hashes of the reference documents and the biometric information, and store the hashes in the new digital identity record while storing the reference documents and biometric information in a non-blockchain repository. The network node may generate a digital identity record block for the new digital identity record, encrypt the digital identity record block, and append the encrypted block to the latest valid blockchain.