Credential Validation via Segmented Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing credential validation systems fail to efficiently manage and disseminate user credentials, particularly in scenarios where different credential issuing organizations are involved, leading to issues with access control and information sharing.
Innovation Solution
A system that uses a validating device and server to validate user credentials by receiving representations of credentials from client devices, verifying identification data, and determining the appropriate data to share based on instructions from the credential issuing organization, distinguishing between public and private information and controlling access accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If credential information is freely disseminated to all validating devices, then ease of access is improved, but security and information control deteriorate
Solution Approach 1:
The patent applies local quality by differentiating the level of information disclosure based on the validating device's identity verification status. Public information is made available to all validating devices, while private information is restricted to only those devices that have been verified. This creates localized access control where different parts of the system (validated vs. unvalidated devices) receive different quality levels of information, resolving the contradiction between ease of access and security.
2Reliability
If identification data verification is required for all data access, then security is improved, but device complexity and access time increase
Solution Approach 1:
The patent segments user data into two distinct categories: public information and private information. This segmentation allows the system to apply different access control rules to different data types. Public information can be accessed without complex verification, maintaining simplicity, while private information requires identification data verification, ensuring security. This segmentation resolves the contradiction by allowing simple access for non-sensitive data while maintaining strict control for sensitive data.
3Ease of operation
If credential validation is performed without verifying validating device identity, then ease of operation is improved, but information control and authorization deteriorate
Solution Approach 1:
The patent implements preliminary action by performing identity verification of the validating device before disclosing private information. The system proactively checks whether the validating device has been properly verified and only then proceeds to disclose sensitive credential information. This preliminary verification action prevents information control issues later, as the system ensures authorization is established before any sensitive data is released, resolving the contradiction between validation speed and information control.
Data Source
AI summary
A validating device receives, from a client device associated with a user, a representation for a first credential associated with the user. The validating device validates the representation for the first credential associated with the user based on data derived from the representation for the first credential associated with the user and identification data associated with the validating device. The validating device obtains a first set of data associated with the user and a second set of data associated with the user. The second set of data is different from the first set of data. The first set of data is obtained based on verifying the identification data associated with the validating device. Obtaining the second set of data is independent of verifying the identification data associated with the validating device.


