Blockchain Identity Verification Protocol for Secure Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for managing digital identities in decentralized networks face challenges such as security risks, data duplication, and the need for specific crypto assets, as well as limitations in revoking identity claims validated by third-parties, particularly in public blockchain solutions like Sovrin.

Innovation Solution

A computer-implemented method using a blockchain that allows users to control their digital identity data, storing hashed and encrypted data attributes, enabling secure sharing and verification without relying on specific crypto assets, and allowing trusted third-parties to revoke assertions, applicable over any blockchain or decentralized ledger.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user identity data is stored on service provider servers, then service providers can easily access and manage user data, but security risks such as hacking and identity theft increase

Engineering Contradiction:
Improvedata accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a blockchain-based intermediary layer that mediates between users and service providers. Instead of storing sensitive identity data on service provider servers, the system uses blockchain to store cryptographic proofs and verification data. Service providers can verify user identities through blockchain-based assertions without accessing actual personal data, thus maintaining security while enabling data access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts sensitive identity data from service provider servers and stores it only on user-controlled devices. The blockchain stores only verification proofs and hashed data, separating the actual identity information from the verification mechanism. This extraction eliminates the security vulnerability of centralized storage while preserving verification capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the same identity data is stored in multiple accounts on distinct server computers, then service providers can independently verify user identities, but unnecessary storage usage occurs due to data duplication

Engineering Contradiction:
Improveidentity verificationVSAvoidstorage usage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent uses cryptographic copying where each service provider receives a verified copy of the user's identity proof from the blockchain, rather than storing duplicate copies of actual identity data. The blockchain stores a single source of truth, and multiple service providers can independently verify against this single copy, eliminating redundant storage while maintaining verification reliability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The blockchain-based identity verification system provides universal verification across multiple service providers through a common protocol. A single identity assertion on the blockchain can be verified by any service provider implementing the protocol, eliminating the need for each provider to store and manage separate copies of identity data while maintaining independent verification capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If service providers store and manage user identity data in account-based systems, then they can update and maintain data, but the approach does not allow automatic updating based on data updates made by other accounts

Engineering Contradiction:
Improvedata managementVSAvoidautomatic data update
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The blockchain system provides automatic feedback mechanisms where identity assertions and updates are immediately recorded on the distributed ledger. When a user's identity data is updated by any service provider, the blockchain automatically propagates this update to all other service providers through its consensus mechanism, enabling automatic data synchronization without manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service automatic updates through smart contracts and decentralized identity protocols. Users can autonomously update their identity data, and the blockchain automatically distributes these updates to all service providers, eliminating the need for service providers to manually synchronize data while maintaining data management capabilities.

Inventive Principle:
Principle #25Self-service

4Reliability

If a public blockchain like Sovrin is used for self-sovereign identity, then users can control their own data, but specific crypto assets are required and business models must be altered

Engineering Contradiction:
Improveuser data controlVSAvoidsystem implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal blockchain-based identity verification protocol that can be implemented across existing service providers without requiring adoption of specific public blockchain networks or crypto assets. The system uses standardized cryptographic protocols that work with any blockchain infrastructure, allowing users to control their data while maintaining compatibility with existing business models and technical infrastructures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3883204B1System and method for secure generation, exchange and management of a user identity data using a blockchain
Publication Date: 2022.09.14 CERTSIGN SA
  • EP3883204B1 patent drawingFigure 1
  • EP3883204B1 patent drawingFigure 2
  • EP3883204B1 patent drawingFigure 3

AI summary

The present invention represents a blockchain-based computer implemented system and its underlying methods. Within the decentralized computing system, a computing device can determine the authenticity of an identity claim by comparing an assertion derived from said claim with an assertion received from a trusted computing device within the system. This is how the invention allows secure decentralized identity management and identity data exchange among the various components of the distributed computing system. The invention enables parties that have never interacted in the physical world to trust the authenticity of identity data exchanged over an untrusted computer network such as the internet. Although the main application of this invention is a self-sovereign identity scheme that can be used by governments, financial institutions and other businesses to decentralize know-your-customer processes, another application can also allow autonomous devices to prove to third parties that they are authorized to perform certain tasks.