Credential Accessing Multiple Domains via Issuer Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing paper-based identity card model is inadequate for modern electronic transactions, as it requires multiple cards for different services, is costly to maintain due to frequent updates, and poses risks with the disclosure of personal information.
Innovation Solution
A method and apparatus that utilize a credential, including credential-owner authentication information and issuer validation information, to access multiple domains independently, allowing for secure and efficient transactions across various domains without relying on a specific credential issuer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a paper-based identity card model is used with multiple cards for different services, then access to multiple domains is enabled, but device complexity and the number of credentials required increases
Solution Approach 1:
The patent combines multiple credential functionalities into a single credential that can access multiple domains. The credential includes both credential-owner authentication information and issuer validation information, allowing it to serve multiple purposes simultaneously rather than requiring separate cards for each domain or service.
Solution Approach 2:
The credential is designed with universal applicability across multiple domains by incorporating validation information from the credential issuer that is recognized by multiple relying parties. This allows the same credential to function across different services and domains without requiring domain-specific cards.
2Reliability
If personal information is included on the card for authentication, then authentication reliability is improved, but security risks increase due to disclosure of personal information
Solution Approach 1:
The patent extracts personal information from the credential itself and stores it separately in a repository. The credential contains only the necessary authentication information and issuer validation information, while personal details are maintained in a secure, separate location that is not distributed with the credential.
Solution Approach 2:
The patent introduces a repository as an intermediary between the credential and personal information. This repository acts as a secure mediator that stores sensitive personal data and releases it only when properly authenticated, preventing direct exposure of personal information while still enabling reliable authentication.
Data Source
AI summary
In one embodiment, a method includes receiving from a credential a credential-owner authentication information associated with an identity of an individual. A issuer validation information associated with an issuer of the credential is also received. The method also includes providing a plurality of options, including a first option associated with a first domain and a second option associated with a second domain mutually exclusive from the first domain. The method also includes sending to a portion of the first domain the credential-owner authentication information and the issuer validation information in response to the first option being selected.


