Blockchain Identity Attestation Service for Sybil Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Blockchain platforms are vulnerable to Sybil attacks due to the ease and cost-free creation of user accounts, which allows a single user to generate and control multiple accounts, disrupting the integrity of applications such as voting systems and social networks.

Innovation Solution

An identity system that includes an attestation service, executed on a server with a processor and non-volatile memory, which communicates with a user computer device and a blockchain platform to create a blockchain account, verify user ownership, and associate trusted identity data from a trusted identity provider with the blockchain account, thereby preventing unauthorized account creation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user accounts are created freely and costlessly on blockchain platforms, then ease of operation is improved, but security deteriorates due to vulnerability to Sybil attacks

Engineering Contradiction:
Improveease of account creationVSAvoidsecurity against Sybil attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted identity provider as an intermediary between users and the blockchain platform. This identity provider issues verifiable credentials that users present during account creation, allowing the system to maintain ease of account creation while preventing Sybil attacks through cryptographic verification of unique identities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs identity verification in advance before allowing blockchain account creation. Users must first obtain verifiable credentials from a trusted identity provider, which are then verified by the blockchain system during account registration. This preliminary verification ensures that each user has a unique identity before they can create an account, preventing Sybil attacks while maintaining operational simplicity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional trusted identity providers are used, then security is improved, but adaptability to blockchain platforms deteriorates due to lack of cross-platform identity utilization

Engineering Contradiction:
Improveidentity verification securityVSAvoidcross-platform identity utilization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal identity verification system where verifiable credentials issued by trusted identity providers can be used across multiple blockchain platforms and applications. The cryptographic proof of identity is platform-agnostic, allowing the same identity to be utilized across different decentralized applications while maintaining security through the trusted identity provider's verification process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11233648B2Identity system for use with blockchain platform
Publication Date: 2022.01.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11233648B2 patent drawing
  • US11233648B2 patent drawing
  • US11233648B2 patent drawing

AI summary

An identity system is provided that may include an attestation service that is configured to communicate with a user computer device and a blockchain platform, and create a blockchain account for the attestation service on the blockchain platform, the account having an associated backend blockchain identity application. The attestation service may further be configured to determine that a user of the user computing device owns a user blockchain account by obtaining a signed message of the user. The signed message may include a user access token from the user of the user computer device and a blockchain address of the user to associate with the access token, the user access token having been generated by a trusted identity provider service. The attestation service may further be configured to identify one or more identity claims associated with the token, and store the identity claim for future presentation to a third party.