Credential Validation via Segmented Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing credential validation systems fail to efficiently manage and disseminate user credentials, particularly in scenarios where different credential issuing organizations are involved, leading to issues with access control and information sharing.

Innovation Solution

A system that uses a validating device and server to validate user credentials by receiving representations of credentials from client devices, verifying identification data, and determining the appropriate data to share based on instructions from the credential issuing organization, distinguishing between public and private information and controlling access accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credential information is freely disseminated to all validating devices, then ease of access is improved, but security and information control deteriorate

Engineering Contradiction:
Improveease of accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by differentiating the level of information disclosure based on the validating device's identity verification status. Public information is made available to all validating devices, while private information is restricted to only those devices that have been verified. This creates localized access control where different parts of the system (validated vs. unvalidated devices) receive different quality levels of information, resolving the contradiction between ease of access and security.

Inventive Principle:
Principle #3Local quality

2Reliability

If identification data verification is required for all data access, then security is improved, but device complexity and access time increase

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments user data into two distinct categories: public information and private information. This segmentation allows the system to apply different access control rules to different data types. Public information can be accessed without complex verification, maintaining simplicity, while private information requires identification data verification, ensuring security. This segmentation resolves the contradiction by allowing simple access for non-sensitive data while maintaining strict control for sensitive data.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If credential validation is performed without verifying validating device identity, then ease of operation is improved, but information control and authorization deteriorate

Engineering Contradiction:
Improvevalidation speedVSAvoidinformation control
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements preliminary action by performing identity verification of the validating device before disclosing private information. The system proactively checks whether the validating device has been properly verified and only then proceeds to disclose sensitive credential information. This preliminary verification action prevents information control issues later, as the system ensures authorization is established before any sensitive data is released, resolving the contradiction between validation speed and information control.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9438597B1Regulating credential information dissemination
Publication Date: 2016.09.06 STRATEGY INC
  • US9438597B1 patent drawing
  • US9438597B1 patent drawing
  • US9438597B1 patent drawing

AI summary

A validating device receives, from a client device associated with a user, a representation for a first credential associated with the user. The validating device validates the representation for the first credential associated with the user based on data derived from the representation for the first credential associated with the user and identification data associated with the validating device. The validating device obtains a first set of data associated with the user and a second set of data associated with the user. The second set of data is different from the first set of data. The first set of data is obtained based on verifying the identification data associated with the validating device. Obtaining the second set of data is independent of verifying the identification data associated with the validating device.