Decentralized Identity Authentication Framework for Secure Credentialing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centralized identity and access management systems are inefficient and vulnerable to breaches, especially in decentralized environments where secure credentialing and access control are critical, such as in the pharmaceutical supply chain and healthcare organizations, due to reliance on insecure sharing mechanisms and cloud-based storage of private keys.
Innovation Solution
Implementing a decentralized identity authentication framework that uses self-sovereign credentials stored on uniquely identifiable devices, such as smartphones or RFID badges, which enable secure, locally-stored private keys and revocable access privileges, leveraging decentralized networks like permissioned blockchains for secure access delegation without exposing private keys to the cloud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized identity and access management systems are used, then ease of operation is improved, but security and vulnerability to breaches worsen
Solution Approach 1:
The patent extracts private keys from centralized cloud storage and places them in decentralized keystores on user-controlled devices. This removes the single point of failure in centralized systems while maintaining ease of operation through automated key management and seamless authentication processes.
Solution Approach 2:
The system segments identity management into decentralized units where each user controls their own private keys in individual keystores. This segmentation eliminates the centralized vulnerability while maintaining operational simplicity through standardized interfaces and automated workflows.
2Ease of operation
If cloud-based storage of private keys is used, then ease of operation is improved, but reliability and security worsen
Solution Approach 1:
The patent extracts private keys from cloud-based storage and relocates them to decentralized keystores on user devices. This extraction eliminates the security vulnerability of centralized cloud storage while maintaining ease of operation through automated key management and seamless authentication processes.
3Reliability
If decentralized identity authentication framework is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The system implements self-service through automated key generation, storage, and management in decentralized keystores. Users automatically control their own credentials without requiring complex manual management, reducing perceived device complexity while maintaining high security through cryptographic operations.
Solution Approach 2:
The patent creates a universal decentralized identity framework that works across multiple devices and systems. The standardized credential verification process and multi-device support reduce complexity by providing a consistent interface while maintaining security through cryptographic validation.
4Reliability
If secure credentialing mechanisms are implemented, then reliability is improved, but ease of operation worsens
Solution Approach 1:
The system implements self-service automation where the decentralized identity framework automatically handles credential verification, key management, and authentication processes. This automation maintains high security through cryptographic operations while preserving ease of operation by eliminating manual security management tasks.
Data Source
AI summary
The disclosed technology teaches an implementation for leveraging self-sovereign credentials held on mobile devices to provision credentials that empower one party (“recipient” or “user”, used synonymously herein) to obtain credentialed access to information and resources on behalf of another party (“sender” or “administrator”, used synonymously herein), without either party exposing private key information to each other or to the cloud. The sender is able to revoke user credentials at any time. Parties are able to leverage commodity hardware to automatically mutually authenticate their credentials and access available relevant options and workflows.


