Decentralized Identity Verification Using Segmented DIDs and Verifiable Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack efficient methods for verifying and presenting digital identities, particularly for scenarios requiring government-issued or third-party identification documents.
Innovation Solution
The implementation of Decentralized Identifiers (DIDs) and verifiable credentials (VCs) allows users to assert and prove their identity using a self-owned digital identity associated with a DID, enabling secure and decentralized identity verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional centralized identity verification systems are used, then identity verification can be performed, but security and privacy control are compromised
Solution Approach 1:
The identity verification system is segmented into separate components: decentralized identifiers (DIDs) for identity representation, verifiable credentials (VCs) for identity attributes, and verifiable presentations (VPs) for identity proof. This segmentation allows users to control which identity aspects are shared while maintaining secure verification through cryptographic signatures, resolving the contradiction between verification reliability and privacy control.
Solution Approach 2:
The patent introduces verifiable credentials as an intermediary mechanism between identity holders and verifiers. These credentials, signed by trusted issuers, serve as portable proof of identity attributes without requiring direct access to underlying identity data. This intermediary enables secure verification while preserving user privacy and control over identity information.
2Ease of operation
If decentralized identity systems are implemented, then user control and privacy are enhanced, but verification efficiency may be reduced
Solution Approach 1:
The system performs preliminary actions by pre-issuing verifiable credentials from trusted issuers before verification scenarios occur. These credentials contain cryptographically signed identity attributes that can be quickly presented and verified without requiring real-time connection to issuing authorities. This preliminary credential issuance enables fast verification while maintaining user control and privacy.
Solution Approach 2:
The patent uses cryptographic copying where verifiable credentials create verified copies of identity attributes that can be freely shared and presented. Instead of repeatedly accessing central identity databases, the system uses these cryptographic copies (VCs and VPs) that contain all necessary verification information, significantly improving verification speed while preserving user control over what information is copied and shared.
3Reliability
If third-party issued identification is integrated, then authenticity of identity claims is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal verifiable credential framework that can accommodate multiple third-party issuers (governments, educational institutions, employers, etc.) through a common data model and verification process. The same VC/VP infrastructure handles diverse identity claims from different sources, eliminating the need for separate verification systems for each issuer type and reducing overall system complexity while maintaining authenticity.
Solution Approach 2:
The system uses parameter changes in the form of configurable trust settings and verification policies. Verifiers can adjust verification parameters (such as required credential types, issuer trust levels, and attribute requirements) based on specific use cases. This parameter-based approach allows flexible integration of third-party issuers without requiring complex custom verification logic for each issuer, simplifying system architecture while ensuring authenticity.
Data Source
AI summary
Disclosed are various embodiments for providing verifiable credentials representing a driver's license or other form of identification issued by a government or a third-party. A wallet application can request a third-party issued identification of a user from a third-party application installed on the computing device. The wallet application can then receive the third-party issued identification from the third-party application. Subsequently, the wallet application can verify the third-party issued identification and then establish a secure communications channel with an issuer service. The wallet application can then request a verifiable credential that represents the third-party issued identification.


