Controlled-Share Identity Transport Stack for Secure Distributed Ledger Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing digital identities lack effective mechanisms for securely sharing and authenticating identity information in electronic transactions, particularly in ensuring the authenticity and privacy of identity data across distributed networks.
Innovation Solution
A transport stack that includes a data layer for storing identity information, a blockchain layer for recording mutualized data on a distributed ledger, and an application layer for managing requests and granting viewing-shares, utilizing authenticity artifacts to establish the authenticity of identity information and controlling access through user interfaces and peer node membership.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If identity information is stored and shared across distributed networks, then accessibility and utility of identity data is improved, but security and authenticity verification become more complex
Solution Approach 1:
The system segments identity information into controlled shares distributed across multiple parties and storage locations. Each party holds a portion of the identity data, and no single party has access to the complete identity information, thereby improving security while maintaining accessibility through coordinated retrieval.
Solution Approach 2:
The patent introduces intermediary components including authenticity artifacts and verification mechanisms that mediate between identity information storage and access requests. These intermediaries verify authenticity and manage access control, reducing the complexity burden on individual system components while enabling widespread access.
2Reliability
If controlled shares of identity information are distributed across multiple parties, then security and privacy are improved, but coordination and access management become more difficult
Solution Approach 1:
The system implements universal access control mechanisms that work across all distributed parties and identity information types. The controlled share architecture and verification protocols provide multi-functional capabilities for security, privacy, and access management, simplifying operations despite the distributed nature of the system.
Solution Approach 2:
The patent utilizes parameter changes in the form of dynamic access control policies, verification thresholds, and share reconstruction parameters. These parameters can be adjusted to balance security requirements with operational ease, allowing the system to adapt to different access scenarios without fundamental architectural changes.
3Measurement precision
If authenticity artifacts are recorded on distributed ledger, then verification capability is improved, but storage requirements and system overhead increase
Solution Approach 1:
The system creates and distributes copies of authenticity artifacts across the distributed ledger network. Each node maintains a copy of the verification data, which improves verification accuracy and speed while distributing the storage burden across multiple parties, thereby reducing the storage overhead for any single entity.
Solution Approach 2:
Authenticity artifacts are generated and recorded on the distributed ledger in advance, before actual verification is needed. This preliminary action allows verification to be performed quickly and accurately when required, while the storage overhead is spread out over time and distributed across the network, reducing immediate system overhead.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A transport stack may control identity information that may be owned by a user. An information record of the identity information may be stored on a distributed ledger. Transactors may request a viewing-share for the identity information to support transactions with the user. The transport stack may generate a grant record when a transactor is provided with a viewing-share of the identity information. The grant record may be stored on the distributed ledger. The distributed ledger may provide a verifiable record of the identity information content and history of viewing-share grants.