Credential Graph Recovery in Verifiable Claims Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity verification systems are cumbersome and invasive, as users often need to reveal unnecessary personal information to prove specific aspects, and there is a risk of losing or compromising identity information stored on devices like mobile devices or smart cards.
Innovation Solution
A method and system for restoring user credentials in verifiable claims-based systems by reconstructing a graph of interdependencies between issuers and claims using a hardware processor, involving root credential restoration, message transmission to backup providers, and graph reconstruction, which allows for minimal disclosure of identity information and secure recovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If identity information is stored on a user's device (mobile device, smart card, etc.), then the user can carry multiple forms of identification and prove membership, but the system becomes vulnerable to loss, compromise, or damage of the storage device
Solution Approach 1:
The patent segments the identity verification system into multiple distributed backup providers rather than relying on a single user device. Each backup provider stores portions of the credential graph, so that no single point of failure can compromise all identity information. This segmentation resolves the contradiction by distributing the reliability burden across multiple independent entities while maintaining the ease of operation for the user.
Solution Approach 2:
The patent introduces backup providers as intermediary entities between the user and the credential storage system. These intermediaries hold encrypted portions of the credential graph and can restore user credentials without requiring the original user device. This intermediary layer protects against device loss while maintaining user access to identification functions.
2Measurement precision
If a user presents a driver's license or other identification to verify a specific attribute (e.g., age), then the verification can be performed, but additional sensitive personal information (address, characteristics, legal name, organ donation options) is revealed
Solution Approach 1:
The patent extracts only the specific attribute needed for verification from the complete identity credential. The credential graph structure allows verifiers to query and receive only the minimal necessary information (e.g., age verification) without obtaining unrelated sensitive data (address, organ donation options, etc.). This extraction principle resolves the contradiction by providing precise verification while preserving privacy.
Solution Approach 2:
The patent applies local quality by allowing different portions of the credential graph to have different accessibility and disclosure properties. Sensitive information can be encrypted or hidden in specific graph portions that are not revealed during routine verification, while non-sensitive verification attributes remain accessible. This enables precise control over what information is disclosed in each verification context.
3Reliability
If the credential graph is distributed across multiple backup providers, then recovery capability is improved, but the complexity of managing and reconstructing the graph increases
Solution Approach 1:
The patent implements self-service by enabling the user's device to autonomously reconstruct the credential graph from distributed backup providers without requiring complex manual intervention or centralized coordination. The device can independently query backup providers, retrieve stored graph portions, and reassemble the complete credential structure. This self-service capability improves reliability through distributed storage while managing complexity through automated reconstruction processes.
4Loss of information
If minimal disclosure credentials are used to protect privacy, then personal information security is improved, but the ability to recover and restore complete identity information becomes more difficult
Solution Approach 1:
The patent applies preliminary action by having backup providers store encrypted portions of the complete credential graph in advance, before any device loss occurs. This preliminary backup ensures that even though minimal disclosure is used during normal operation, the complete identity information is preserved in encrypted form at backup providers. When restoration is needed, the pre-stored encrypted data can be retrieved and decrypted, resolving the contradiction between privacy protection and recovery capability.
Data Source
AI summary
Methods, systems, and media for recovering identity information in verifiable claims-based systems are provided. In some embodiments, the method comprises: determining that a graph of interdependencies between a plurality of issuers and a plurality of claims for a holder is to be reconstructed; restoring a root credential; transmitting a plurality of messages that are each signed with the root credential to a plurality of backup providers, wherein each of the plurality of backup providers has a portion of the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder stored in a storage device; receiving a plurality of graph portions from at least a portion of the plurality of backup providers in response to each of the portion of the plurality of backup providers determining that the root credential is a correct root credential corresponding to the holder; and reconstructing the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder using the plurality of received graph portions.


