Credential Graph Recovery in Verifiable Claims Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity verification systems are cumbersome and invasive, as users often need to reveal unnecessary personal information to prove specific aspects, and there is a risk of losing or compromising identity information stored on devices like mobile devices or smart cards.

Innovation Solution

A method and system for restoring user credentials in verifiable claims-based systems by reconstructing a graph of interdependencies between issuers and claims using a hardware processor, involving root credential restoration, message transmission to backup providers, and graph reconstruction, which allows for minimal disclosure of identity information and secure recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If identity information is stored on a user's device (mobile device, smart card, etc.), then the user can carry multiple forms of identification and prove membership, but the system becomes vulnerable to loss, compromise, or damage of the storage device

Engineering Contradiction:
ImproveAbility to carry and use multiple identification formsVSAvoidSecurity and availability of identity information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the identity verification system into multiple distributed backup providers rather than relying on a single user device. Each backup provider stores portions of the credential graph, so that no single point of failure can compromise all identity information. This segmentation resolves the contradiction by distributing the reliability burden across multiple independent entities while maintaining the ease of operation for the user.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces backup providers as intermediary entities between the user and the credential storage system. These intermediaries hold encrypted portions of the credential graph and can restore user credentials without requiring the original user device. This intermediary layer protects against device loss while maintaining user access to identification functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If a user presents a driver's license or other identification to verify a specific attribute (e.g., age), then the verification can be performed, but additional sensitive personal information (address, characteristics, legal name, organ donation options) is revealed

Engineering Contradiction:
ImproveAbility to verify specific identity attributesVSAvoidPrivacy of personal information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts only the specific attribute needed for verification from the complete identity credential. The credential graph structure allows verifiers to query and receive only the minimal necessary information (e.g., age verification) without obtaining unrelated sensitive data (address, organ donation options, etc.). This extraction principle resolves the contradiction by providing precise verification while preserving privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by allowing different portions of the credential graph to have different accessibility and disclosure properties. Sensitive information can be encrypted or hidden in specific graph portions that are not revealed during routine verification, while non-sensitive verification attributes remain accessible. This enables precise control over what information is disclosed in each verification context.

Inventive Principle:
Principle #3Local quality

3Reliability

If the credential graph is distributed across multiple backup providers, then recovery capability is improved, but the complexity of managing and reconstructing the graph increases

Engineering Contradiction:
ImproveAbility to recover credentials after device lossVSAvoidComplexity of graph reconstruction process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the user's device to autonomously reconstruct the credential graph from distributed backup providers without requiring complex manual intervention or centralized coordination. The device can independently query backup providers, retrieve stored graph portions, and reassemble the complete credential structure. This self-service capability improves reliability through distributed storage while managing complexity through automated reconstruction processes.

Inventive Principle:
Principle #25Self-service

4Loss of information

If minimal disclosure credentials are used to protect privacy, then personal information security is improved, but the ability to recover and restore complete identity information becomes more difficult

Engineering Contradiction:
ImproveProtection of personal information privacyVSAvoidAbility to restore credentials after loss
Core Design Contradiction:
Loss of informationVSEase of repair

Solution Approach 1:

The patent applies preliminary action by having backup providers store encrypted portions of the complete credential graph in advance, before any device loss occurs. This preliminary backup ensures that even though minimal disclosure is used during normal operation, the complete identity information is preserved in encrypted form at backup providers. When restoration is needed, the pre-stored encrypted data can be retrieved and decrypted, resolving the contradiction between privacy protection and recovery capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11811742B2Methods, systems, and media for recovering identity information in verifiable claims-based systems
Publication Date: 2023.11.07 GOOGLE LLC
  • US11811742B2 patent drawing
  • US11811742B2 patent drawing
  • US11811742B2 patent drawing

AI summary

Methods, systems, and media for recovering identity information in verifiable claims-based systems are provided. In some embodiments, the method comprises: determining that a graph of interdependencies between a plurality of issuers and a plurality of claims for a holder is to be reconstructed; restoring a root credential; transmitting a plurality of messages that are each signed with the root credential to a plurality of backup providers, wherein each of the plurality of backup providers has a portion of the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder stored in a storage device; receiving a plurality of graph portions from at least a portion of the plurality of backup providers in response to each of the portion of the plurality of backup providers determining that the root credential is a correct root credential corresponding to the holder; and reconstructing the graph of interdependencies between the plurality of issuers and the plurality of claims for the holder using the plurality of received graph portions.