Decentralized Identity Network Using Gossip Protocol for Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, particularly in metaverse settings, the secure management of personally identifying information is challenging due to issues like data replication, privacy concerns, and the risk of leakage, as conventional decentralized identity systems face problems such as the Proximity Problem, Scale Problem, Flexibility Problem, Privacy Problem, and Consent Problem.

Innovation Solution

A distributed identity network using a consensus mechanism that allows individuals to be identified without sharing private information, with a focus on maintaining personal control over digital information and applying consent-based rules for information sharing, employing a gossip protocol and zero-knowledge proofs to determine identity and store the realized state of transactions in a merkle database for efficient query execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personally identifying information is stored in cloud computing environments for identity verification and authorization, then user identity management capability is improved, but the risk of information leakage and privacy breaches increases

Engineering Contradiction:
Improveidentity verification capabilityVSAvoidinformation leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments personally identifying information into multiple distributed shards stored across different nodes in a decentralized network. No single node contains the complete identity information, making it resistant to centralized breaches while maintaining verification capability through cryptographic proof mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries (hash functions, zero-knowledge proofs, and digital signatures) that enable identity verification without directly exposing sensitive personal information. These intermediaries act as mediators between identity proof and verification, preventing information leakage while maintaining reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If decentralized identity systems replicate data across multiple nodes for distributed storage, then system reliability and availability are improved, but data privacy protection deteriorates

Engineering Contradiction:
Improvesystem availabilityVSAvoidprivacy protection
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

Identity data is segmented into cryptographic fragments distributed across multiple nodes. Each node stores only a portion of the hashed identity information, making it impossible to reconstruct personal information from any single node, thus maintaining both availability and privacy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms personally identifying information into cryptographic parameters (hash values, encrypted tokens, zero-knowledge proofs) before distribution. This parameter change maintains the functional utility of identity verification while eliminating the risk of privacy loss through data replication.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If comprehensive user profiles are collected for personalized experiences in metaverse applications, then user experience quality is improved, but consent management and privacy control become more difficult

Engineering Contradiction:
Improvepersonalized experience qualityVSAvoidconsent management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service consent management where users autonomously control their own identity data through cryptographic keys and smart contracts. Users can grant, revoke, and manage consent for data access without requiring complex centralized authorization systems, simplifying consent management while enabling personalized experiences.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Cryptographic intermediaries and smart contracts mediate between user consent and data access. These intermediaries automatically enforce consent rules and manage data sharing permissions, reducing the complexity of consent management while maintaining high-quality personalized user experiences.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Speed

If centralized identity management systems are used for efficient query execution, then query processing speed is improved, but single points of failure and security vulnerabilities increase

Engineering Contradiction:
Improvequery processing speedVSAvoidsystem security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the identity management system into distributed nodes that collectively process queries. Query processing is divided into multiple operations across different nodes, maintaining speed through parallel processing while eliminating single points of failure and improving security through decentralization.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11770445B2Decentralized information management database system
Publication Date: 2023.09.26 SALESFORCE INC
  • US11770445B2 patent drawing
  • US11770445B2 patent drawing
  • US11770445B2 patent drawing

AI summary

A request to present digital content at a client machine associated with a designated network identifier may be received. For each of a plurality of preference characteristics, a respective characteristic query message may be transmitted via a network to a respective plurality of identity nodes via a gossip communication protocol defining a peer-to-peer procedure for transmitting information among the plurality of identity nodes. For each of the plurality of preference characteristics, a respective preference identification response message that includes a respective preference value corresponding with the respective preference characteristic may be received. The designated network identifier may be stored in a trust ledger shared among the plurality of identity nodes. A digital content item may be selected based at least in part on the preference values.