Blockchain Identity Asset Provider Key Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Blockchain systems face challenges in ensuring financial fairness and protecting privacy during the exchange of identity assets, particularly in anonymous and unlinkable transactions, where parties can potentially abort protocols without fulfilling their obligations.
Innovation Solution
A processor-implemented method that encrypts identity assets bit by bit using a provider key, with double encryption and proof of correctness, and employs a protocol to ensure financial fairness by adjusting payments based on pre-defined rules, ensuring that both parties fulfill their obligations in a blockchain network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If identity assets are exchanged anonymously in blockchain, then privacy is protected, but financial fairness cannot be ensured
Solution Approach 1:
The secret key is segmented into multiple shares (first share, second share, third share) that are distributed to different parties. No single party possesses the complete key, preventing any one entity from unilaterally accessing or aborting the transaction. The key shares are combined only when all parties contribute their portions, ensuring financial fairness while maintaining anonymity.
Solution Approach 2:
A trusted intermediary (such as a mixer service or decentralized protocol) is introduced to facilitate the exchange of key shares and coordinate the combination process. This intermediary ensures that all parties fulfill their obligations before the complete key is reconstructed, providing financial fairness guarantees without compromising the anonymous nature of the transaction.
2Adaptability or versatility
If a party can abort the protocol at any time, then flexibility is improved, but financial fairness deteriorates
Solution Approach 1:
All parties must perform preliminary actions to generate and distribute their key shares before the actual identity asset transfer can occur. The protocol structure requires that key share distribution is completed and verified before any party can unilaterally abort, ensuring that if the protocol is aborted at this stage, no party gains unfair advantage. The flexible abort mechanism is built into the protocol to allow parties to exit cleanly after contributing their shares.
Solution Approach 2:
The protocol incorporates feedback mechanisms where parties confirm receipt and validity of key shares before proceeding to the next stage. This feedback loop ensures that all parties have fulfilled their obligations and provides a clear state where fair abort can occur. The feedback mechanism tracks the protocol state to determine whether aborting would be fair or unfair to the parties involved.
3Speed
If the complete provider key is transmitted to the consumer, then transaction speed is improved, but security and privacy are compromised
Solution Approach 1:
Instead of transmitting the complete provider key in one operation, the key is segmented into multiple shares transmitted through different channels and at different times. The consumer receives key shares incrementally rather than all at once, which maintains security and privacy while still enabling eventual decryption. The segmented transmission prevents any single transmission point from being compromised.
Solution Approach 2:
The key transmission problem is solved by adding temporal and spatial dimensions to the transmission process. Key shares are transmitted across different time periods and potentially different communication channels, transforming a single high-risk transmission into multiple lower-risk transmissions. This dimensional approach maintains security while ultimately achieving the goal of key delivery.
Data Source
AI summary
A processor-implemented method improves security in a blockchain network of devices, which supports a blockchain, by protecting security, privacy, financial fairness, and secure transfer of identity assets. An identity asset provider device creates an identity asset related to an entity. The identity asset provider also creates a provider key, which is composed of multiple bits, and which is needed to decrypt an encrypted version of the identity asset. The identity asset provider device transmits the provider key bit-by-bit to an identity asset consumer device. A price for the provider key depends on how many bits have been transmitted to the identity asset consumer device.


