Credential Verification via Selective Aspect Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Individuals face inconvenience and privacy concerns when carrying multiple forms of identification, as verifying a specific aspect of their identity often requires revealing additional personal information.

Innovation Solution

A method and system for authenticating user credentials that involves receiving a request for access to a service, determining the required credential aspect, transmitting a request for information related to that aspect, verifying the information signed with a user device key, and granting access only if the aspect is satisfied, using an auditable ledger for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional identification methods are used to verify user credentials, then verification accuracy is improved, but personal information privacy is compromised

Engineering Contradiction:
Improveverification accuracyVSAvoidpersonal information privacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts only the specific credential aspect needed for verification (e.g., age) from the complete identification document, allowing verification without exposing other personal information. The system requests and processes only the minimal necessary data element rather than the entire credential.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments user credentials into distinct aspects or attributes (age, name, address, etc.) that can be independently verified. This allows the verification system to request and validate only the specific segment needed for the service, keeping other segments private.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple forms of identification are carried to cover different verification needs, then credential versatility is improved, but device complexity and user burden increase

Engineering Contradiction:
Improvecredential versatilityVSAvoiduser burden
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal credential system where a single digital credential contains multiple aspects or attributes that can satisfy different verification requirements. Instead of needing separate physical IDs for different purposes, users have one multi-functional credential that can be selectively verified.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple credential aspects into a single unified digital credential structure. This consolidation allows the user to carry one credential instead of multiple separate identification documents, reducing complexity while maintaining versatility.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12069053B2Secure methods, systems, and media for generating and verifying user credentials
Publication Date: 2024.08.20 GOOGLE LLC
  • US12069053B2 patent drawing
  • US12069053B2 patent drawing
  • US12069053B2 patent drawing

AI summary

Secure methods, systems, and media for generating and verifying user credentials are provided. In some embodiments, the method comprises: receiving, from a user device, a request for access to a service that requires valid user credentials; determining an aspect of the user credentials that is to be satisfied to grant access to the requested service; transmitting, to the user device, a request for information related to the aspect of the user credential; receiving, from the user device, information related to the aspect of the user credential, wherein the information has been signed using a key associated with the user device; verifying the key used to sign the information by the user device; in response to verifying the key used to sign the information, determining whether the aspect of the user credential has been satisfied based on the received information; and, in response to determining that the aspect of the user credential has been satisfied, granting access to the service.