Decentralized Identifier Credentials for Secure Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized identity management systems for exchanging confidential information are vulnerable to fraud, data exposure, and unauthorized access, making it difficult to maintain data privacy and trace unauthorized access.

Innovation Solution

A system utilizing a blockchain and smart contracts to manage authorization requests and verifiable credentials with embedded decentralized identifiers, enabling secure and decentralized exchange of confidential information without the need for centralized credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized identity management systems are used to exchange confidential information, then information exchange is facilitated, but security vulnerabilities and data exposure risks increase

Engineering Contradiction:
Improveinformation exchangeVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a blockchain network as an intermediary layer between entities exchanging confidential information. The blockchain stores verifiable credentials and decentralized identifiers (DIDs) that enable secure verification without centralized control. Smart contracts act as automated intermediaries that enforce access policies and manage credential verification, eliminating the need for trusted centralized authorities while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments identity management into decentralized components: DIDs for unique entity identification, verifiable credentials for attribute verification, and blockchain storage for immutable record-keeping. This segmentation distributes trust across multiple independent elements rather than relying on a single centralized authority, reducing security risks associated with centralized systems.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If centralized credentials are used for access control, then authorization is simplified, but fraud and unauthorized access risks increase

Engineering Contradiction:
ImproveauthorizationVSAvoidfraud risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional mechanical centralized credential systems with cryptographic mechanisms. Verifiable credentials use digital signatures and public-key cryptography to provide tamper-evident authorization. The blockchain's consensus mechanism substitutes centralized credential issuance and validation, making fraud detection and prevention inherent to the system architecture rather than relying on centralized monitoring.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements feedback through the blockchain's immutable ledger that permanently records all credential issuances, presentations, and verifications. This creates an auditable trail that provides real-time feedback on authorization events, enabling detection of fraudulent activities and unauthorized access attempts while maintaining simplified authorization through cryptographic verification.

Inventive Principle:
Principle #23Feedback

3Reliability

If decentralized identifiers and verifiable credentials are used, then security and data privacy are improved, but system complexity increases

Engineering Contradiction:
Improvedata privacyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs universal standards for DIDs and verifiable credentials that can be applied across multiple applications and domains. The blockchain infrastructure provides a universal platform for storing and verifying credentials, eliminating the need for application-specific credential management systems. This universality reduces complexity by providing a standardized framework that can be reused rather than building custom solutions for each use case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If blockchain technology is implemented for credential verification, then fraud prevention is enhanced, but processing time and computational requirements increase

Engineering Contradiction:
Improvefraud preventionVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-issuing verifiable credentials with embedded cryptographic proofs of authenticity. These credentials are signed by trusted issuers and stored on the blockchain in advance, so verification requires only checking the cryptographic signatures rather than querying the issuer in real-time. This preliminary credential issuance reduces verification time while maintaining strong fraud prevention through cryptographic validation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260050919A1Methods and systems for exchanging confidential information using decentralized identifiers via a blockchain
Publication Date: 2026.02.19 WOLTERS KLUWER DXG U S INC
  • US20260050919A1 patent drawing
  • US20260050919A1 patent drawing
  • US20260050919A1 patent drawing

AI summary

Systems and methods for securely accessing information pertaining to an upstream entity using a verifiable credential with an embedded distributed identifier includes generating an authorization request for access to the information by a downstream entity. The authorization request includes a decentralized identifier associated with the downstream entity and is transmitted to a content storage entity. An authorization notification corresponding to the authorization request is received. An authorization token is retrieved. The authorization token includes a verifiable credential generated by the upstream entity and incorporating the decentralized identifier. A request transaction including a request to access the information pertaining to the upstream entity and the authorization token is generated and transmitted to the content storage entity. A verification challenge corresponding to the request transaction based on the verifiable credential is received and a response is transmitted. A reply transaction is received granting access to the information pertaining to the upstream entity.