Cryptographic Credentials for Privacy-Preserving User Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data sharing methods between smart devices and entities lack user control and privacy, with existing approaches being insecure and cumbersome, especially in scenarios involving user authentication and preference sharing across multiple entities.

Innovation Solution

The implementation of cryptographic authentication and preference credentials, generated and verified using Key Generating Engine (KGE), Proof Generating Engine (PGE), and Proof Verifying Engine (PVE), allows users to securely share and authenticate their data and preferences across devices and entities, maintaining user privacy and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional data sharing methods are used between entities, then data exchange efficiency is improved, but user privacy and security deteriorate

Engineering Contradiction:
Improvedata exchange efficiencyVSAvoiduser privacy breach
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces cryptographic credentials as an intermediary mechanism that enables data sharing without direct exposure of user information. The credential system acts as a mediator between the user and entities, allowing verification of user attributes (like age, membership) without revealing the actual personal data. This resolves the contradiction by maintaining efficient data exchange through automated credential verification while protecting user privacy through cryptographic abstraction.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts only the necessary verification information from user data and embeds it in cryptographic credentials. Instead of sharing complete user profiles or personal information, the system extracts specific attributes (e.g., age verification, membership status) and proves them through cryptographic means. This extraction approach enables efficient verification while minimizing privacy exposure by sharing only what is strictly necessary.

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If cryptographic authentication credentials are implemented, then user privacy and security are improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidauthentication system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service through automated credential verification. The cryptographic credentials are designed to be verifiable by any entity without requiring complex authentication infrastructure. The verification process is self-contained within the credential itself, allowing entities to independently verify user attributes without needing to contact the credential issuer or maintain complex authentication systems. This reduces overall system complexity while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The cryptographic credential system is designed as a universal authentication mechanism that can be applied across multiple contexts and entities. A single credential can verify multiple user attributes and work with different service providers without requiring separate authentication systems for each. This multi-functionality reduces the need for multiple specialized systems, thereby降低ing overall complexity while maintaining robust security across diverse applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If user data is shared across multiple entities, then service versatility is improved, but loss of information control by user increases

Engineering Contradiction:
Improveservice versatilityVSAvoiduser data control
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent applies local quality by allowing different levels of data disclosure for different entities and contexts. Users can grant fine-grained permissions where specific entities receive verification of specific attributes while maintaining control over other information. For example, a user might allow one entity to verify age while preventing another entity from accessing the same information. This localized control approach enables service versatility across multiple entities while preserving user control through differentiated permission settings.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary action by obtaining user consent and configuring permission settings before any data sharing occurs. Users pre-configure which attributes can be verified and by whom, establishing control boundaries in advance. This preliminary configuration enables seamless multi-entity service delivery while ensuring users maintain ongoing control over their information, as the pre-set permissions automatically enforce user preferences across all data sharing interactions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10320781B2System and methods for sharing and trading user data and preferences between computer programs and other entities while preserving user privacy
Publication Date: 2019.06.11 SAFELISHARE INC
  • US10320781B2 patent drawing
  • US10320781B2 patent drawing
  • US10320781B2 patent drawing

AI summary

Systems and methods are provided which allow computer programs or other entities to share user data and information so that users may be authenticated and their preferences shared among entities in networked environments and machines. Cryptographic credentials are generated for these purposes. While the credentials can be shared to provide entities with user authentication and preference data, a salient feature of the sharing technology is that the user is always in control of, and integral to, the sharing protocol. Moreover, the sharing preserves the privacy of the user's data.