Circle of Trust Access Control for Digital Identity Wallets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems face risks of unauthorized access and data breaches due to malware and nefarious applications posing as trusted entities, compromising sensitive user data.

Innovation Solution

A system for access control using a 'circle of trust' framework, where digital identity wallet applications are secured through a processor that verifies the trust relationship between user applications and digital identity wallet applications, utilizing decentralized identifiers (DIDs) and verifiable credentials to establish secure communication channels and manage trust directories.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user credentials are stored as cookies in a browser for easy authentication across applications, then user convenience is improved, but security is worsened due to risk of malware accessing these cookies

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into separate components: a digital identity wallet application that securely stores credentials and a notification system that mediates authentication requests. This segmentation prevents malware from directly accessing stored credentials while maintaining user convenience through automated authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a notification system as an intermediary between user applications and the digital identity wallet application. This intermediary verifies the legitimacy of authentication requests before allowing access to credentials, blocking malicious applications while enabling legitimate ones.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a separate digital identity wallet application is used for secure authentication, then security is improved, but vulnerability to spam and phishing attacks is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidspam and phishing attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the notification system receives authentication requests, verifies them against trusted application lists, and provides feedback by either granting or denying access to the digital identity wallet application. This feedback loop prevents spam and phishing attacks while maintaining security.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary verification of authentication requests before they can access the digital identity wallet application. The notification system checks whether the requesting application is legitimate and authorized beforehand, preventing malicious applications from even attempting to access credentials.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication requests are processed through a notification system, then control over access is improved, but system complexity is worsened

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal notification system that handles multiple functions: verifying authentication requests, managing trusted application lists, and coordinating with the digital identity wallet application. This multi-functional approach improves access control while minimizing the need for separate specialized components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11539533B1Access control using a circle of trust
Publication Date: 2022.12.27 WORKDAY INC
  • US11539533B1 patent drawing
  • US11539533B1 patent drawing
  • US11539533B1 patent drawing

AI summary

A system for access control includes an interface to receive an access request from a first user application for permission to access a first digital identity wallet application and a processor to: determine whether to grant access for the first user application to the first digital identity wallet application, wherein access is granted for the first user application to the first digital identity wallet application in response to the first user application belonging to a first circle of trust and the first digital identity wallet application belonging to the first circle of trust; and in response to determining to grant access for the first user application to the first digital identity wallet application, provide an access granting indication.