Blockchain Merkle Tree for Secure KYC Validation Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current KYC processes are inefficient, costly, and vulnerable to security attacks due to repeated validation of customer identity across institutions, leading to high costs and negative user experiences, as companies do not share validation information effectively.
Innovation Solution
A method using blockchain technology to securely share validation information by constructing a structured Merkle tree and utilizing a permissioned blockchain to link satellite chains, allowing companies to trust each other within alliances for shared validation, while maintaining customer privacy through all-or-nothing encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If companies perform independent KYC validation processes without sharing validation information, then each company can ensure security and validate customer identities, but the process becomes costly and inefficient with repeated validations across institutions
Solution Approach 1:
The patent merges validation information from multiple companies into a shared blockchain ledger. Validation results are combined into a Merkle tree structure that can be verified by any participating company, eliminating the need for each company to independently validate the same customer data. This combining approach maintains security through cryptographic verification while dramatically improving efficiency by avoiding repeated validations.
Solution Approach 2:
The blockchain-based validation system creates a universal validation record that serves multiple companies simultaneously. A single validation performed by one company can be reused by any other company in the network through the shared ledger, making the validation process multi-functional and applicable across different institutions without requiring separate validation processes for each company.
2Productivity
If companies share validation information across institutions, then validation efficiency improves and costs decrease, but security vulnerabilities increase and data privacy risks arise
Solution Approach 1:
The patent extracts only the essential validation information needed for verification while leaving sensitive personal data on the customer's device. The Merkle tree root hash is extracted and stored on the blockchain, allowing verification of validation status without exposing actual personal information. This extraction approach enables information sharing for efficiency while maintaining security by not sharing the underlying sensitive data.
Solution Approach 2:
The blockchain ledger acts as an intermediary that facilitates secure information sharing between companies. Instead of companies directly sharing sensitive customer data with each other, they interact through the blockchain intermediary that stores only cryptographic hashes and validation metadata. This intermediary layer enables efficient validation sharing while protecting security by preventing direct access to sensitive information.
3Ease of operation
If all validation information is stored centrally, then access and sharing become easier, but security attacks become more vulnerable and data privacy is compromised
Solution Approach 1:
The patent segments validation information into hierarchical levels using a Merkle tree structure. The root hash is stored centrally on the blockchain for easy access and verification, while the actual validation data remains distributed across individual company systems and customer devices. This segmentation enables easy access to validation status through the central ledger while preventing security attacks by not concentrating sensitive data in a single vulnerable location.
Data Source
AI summary
A method for securely sharing validation information of one or more data files stored on different cloud servers using distributed ledger technology includes requesting access to the data files and calculating a hash thereof. A structured Merkle tree is constructed using the hash and additional hashes of other data files for which a user has not granted access, but has used to construct a corresponding Merkle tree for which the user has committed a root value to a main blockchain. It is checked whether the root value of the Merkle tree is the same as the one the user has committed, and whether the hash of the data files is stored in a block of a satellite blockchain linked to the main blockchain and operated by a subset of nodes of the main blockchain that trust one another.


