Circle of Trust Access Control for Digital Identity Wallets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems face risks of unauthorized access and data breaches due to malware and nefarious applications posing as trusted entities, compromising sensitive user data.
Innovation Solution
A system for access control using a 'circle of trust' framework, where digital identity wallet applications are secured through a processor that verifies the trust relationship between user applications and digital identity wallet applications, utilizing decentralized identifiers (DIDs) and verifiable credentials to establish secure communication channels and manage trust directories.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user credentials are stored as cookies in a browser for easy authentication across applications, then user convenience is improved, but security is worsened due to risk of malware accessing these cookies
Solution Approach 1:
The patent segments the authentication system into separate components: a digital identity wallet application that securely stores credentials and a notification system that mediates authentication requests. This segmentation prevents malware from directly accessing stored credentials while maintaining user convenience through automated authentication.
Solution Approach 2:
The patent introduces a notification system as an intermediary between user applications and the digital identity wallet application. This intermediary verifies the legitimacy of authentication requests before allowing access to credentials, blocking malicious applications while enabling legitimate ones.
2Reliability
If a separate digital identity wallet application is used for secure authentication, then security is improved, but vulnerability to spam and phishing attacks is worsened
Solution Approach 1:
The patent implements a feedback mechanism where the notification system receives authentication requests, verifies them against trusted application lists, and provides feedback by either granting or denying access to the digital identity wallet application. This feedback loop prevents spam and phishing attacks while maintaining security.
Solution Approach 2:
The patent performs preliminary verification of authentication requests before they can access the digital identity wallet application. The notification system checks whether the requesting application is legitimate and authorized beforehand, preventing malicious applications from even attempting to access credentials.
3Reliability
If authentication requests are processed through a notification system, then control over access is improved, but system complexity is worsened
Solution Approach 1:
The patent implements a universal notification system that handles multiple functions: verifying authentication requests, managing trusted application lists, and coordinating with the digital identity wallet application. This multi-functional approach improves access control while minimizing the need for separate specialized components.
Data Source
AI summary
A system for access control includes an interface to receive an access request from a first user application for permission to access a first digital identity wallet application and a processor to: determine whether to grant access for the first user application to the first digital identity wallet application, wherein access is granted for the first user application to the first digital identity wallet application in response to the first user application belonging to a first circle of trust and the first digital identity wallet application belonging to the first circle of trust; and in response to determining to grant access for the first user application to the first digital identity wallet application, provide an access granting indication.


