Cross-Network Identity Provisioning via Interoperation Identity Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized databases face issues with data redundancy, security, and scalability, particularly in cross-network identity provisioning, where traditional databases fail to provide immutable and tamper-proof storage, leading to inefficiencies and vulnerabilities in data management and access control.

Innovation Solution

Implementing a blockchain-based system that enables cross-network identity provisioning through the creation of an interoperation identity network (IIN) using self-sovereign identity (SSI) networks, smart contracts, and verifiable credentials, allowing for secure, decentralized, and permissioned access control across multiple blockchain networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized database is used for identity management, then ease of management and control is improved, but security and immutability deteriorate due to vulnerability to tampering and single point of failure

Engineering Contradiction:
Improveease of managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The centralized database is segmented into a distributed network of blockchain nodes, where identity data is distributed across multiple participants rather than stored in a single location. This segmentation eliminates the single point of failure while maintaining manageable access control through cryptographic protocols and consensus mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A blockchain intermediary layer is introduced between identity providers and verifiers, enabling secure identity management without requiring direct trust between parties. The blockchain acts as a neutral mediator that ensures immutability and transparency while maintaining ease of operation through standardized interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If a centralized database is used, then data redundancy is minimized with a single storing place, but scalability and cross-network interoperability worsen due to inability to support multiple blockchain networks

Engineering Contradiction:
Improvedata redundancyVSAvoidcross-network interoperability
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The blockchain identity management system is designed with universal functionality that enables it to serve multiple blockchain networks simultaneously. The identity verification mechanisms are network-agnostic, allowing the same identity credential to be verified across different blockchain ecosystems, thereby achieving cross-network interoperability without duplicating identity data.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system transitions from a single-dimension centralized storage model to a multi-dimensional distributed architecture where identity data exists across multiple blockchain networks. This dimensional expansion enables the system to maintain data efficiency while supporting interoperability across diverse blockchain ecosystems through standardized identity protocols.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If traditional database access control is used, then ease of operation is maintained, but reliability and trustworthiness deteriorate due to lack of immutable and tamper-proof storage

Engineering Contradiction:
Improveaccess controlVSAvoidtrustworthiness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Access control policies are established in advance through smart contracts that encode authorization rules immutably on the blockchain. These preliminary actions ensure that access control decisions are made automatically based on pre-defined criteria, eliminating manual intervention while maintaining both ease of operation and high trustworthiness through cryptographic verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback mechanisms where access control decisions are transparently recorded on the blockchain and can be independently verified. This feedback loop ensures that the system maintains trustworthiness by providing auditable proof of access control operations while preserving ease of operation through automated enforcement of policies.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11184395B1Cross-network identity provisioning
Publication Date: 2021.11.23 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11184395B1 patent drawing
  • US11184395B1 patent drawing
  • US11184395B1 patent drawing

AI summary

An example operation includes one or more of connecting, by an identity provisioning node, a blockchain one to a blockchain two, creating, by an identity provisioning node, an interoperation identity network (IIN) for the blockchain one and for the blockchain two as an instance of a self-sovereign identity (SSI) network, executing a smart contract to: invoke an IIN access control policy, map attributes and permissions of the blockchain one to attributes and permissions of the blockchain two based on the IIN access control policy, and generate a valid verifiable credential (VC) of the IIN in the blockchain one and in the blockchain two based on the mapped attributes and the permissions.