Decentralized Digital Identity Authentication via Hardware Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital identity authentication systems are vulnerable to identity theft, recording errors, fraudulent profiles, and fraudulent corporate roles due to reliance on insecure password-based systems and centralized data storage, which leads to significant financial and emotional losses, as well as undermining trust in online transactions and democracy.

Innovation Solution

A system utilizing a computer platform with multi-factor authentication, involving an identity editor to create and verify public identifiers linked to encrypted user data, and a requestor to verify identities through a secure protocol using hardware and software keys, ensuring that only the individual can decrypt and authenticate their identity information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized data storage and password-based authentication are used, then ease of operation is improved, but reliability deteriorates due to vulnerability to identity theft and data breaches

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into multiple independent components: decentralized identity wallets held by users, distributed verification networks, and modular credential verification protocols. This segmentation eliminates the single point of failure inherent in centralized storage, allowing the system to maintain ease of operation while significantly improving reliability through distributed security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries including digital signatures, zero-knowledge proofs, and verifiable credentials as mediators between users and verification systems. These intermediaries enable secure authentication without requiring centralized data storage, resolving the contradiction by providing both operational convenience and cryptographic reliability simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If centralized identity verification systems are implemented, then productivity is improved through streamlined authentication, but loss of information increases due to security breaches and identity theft

Engineering Contradiction:
ImproveproductivityVSAvoidloss of information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent extracts sensitive identity information from centralized databases and places it in decentralized user-controlled wallets. Only verified credential data, not raw personal information, is stored centrally. This extraction maintains productivity through efficient verification while preventing information loss by eliminating the attractive target for thieves.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements disposable or ephemeral credentials that can be generated, used, and revoked as needed. These short-lived verification tokens enable rapid authentication (improving productivity) while their temporary nature prevents long-term information compromise (reducing information loss risk).

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of operation

If traditional password systems are used, then ease of operation is maintained, but device complexity increases to protect against security threats

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical password system with cryptographic mechanisms including hardware security modules, biometric authentication, and public key infrastructure. This substitution maintains ease of operation through seamless authentication while reducing device complexity by eliminating the need for complex password management and security protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of operation

If centralized authentication systems are deployed, then ease of operation improves, but reliability worsens due to insider threats and fraudulent access

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent inverts the traditional trust model by placing verification power in the user's wallet rather than the central system. Users control their own authentication credentials and can verify identities themselves. This inversion maintains operational simplicity while dramatically improving reliability by eliminating insider threats, as no central authority has access to compromise credentials.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS10887098B2System for digital identity authentication and methods of use
Publication Date: 2021.01.05 VAN DER VELDEN ALEXANDER J M
  • US10887098B2 patent drawing
  • US10887098B2 patent drawing
  • US10887098B2 patent drawing

AI summary

A cryptography system for digital identity authentication, and security including computer system or platform to enable users (individual, identity editor, requestor) using one or more user devices, having user data including a public identifier and a hardware key, a server, a private key on an individual user device and a matching public key on the server linked to individual user data on the server, an individual user device converts an individual user data into an individual user code on individual user device, editor user device receives individual user code and communicates individual user code to server, server pairs individual user device and editor user device by matching individual user code transmitted by said editor user device to user data on the server, and requestor to request verification of an identity of individual via issuance of a verification request and verified if match of decrypted public identifier in an identity contract.