Decentralized Identity Management via Distributed Ledger
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication and authorization methods in cross-enterprise environments rely on physical security tokens that can be faked or stolen, or on personal relationships, lacking nuanced access control and automated revocation mechanisms, which compromises security and access management.
Innovation Solution
A decentralized identity management system using cryptographically signed token files stored on a distributed ledger, allowing for secure and attribute-based authentication and authorization across enterprises, eliminating the need for physical tokens and personal trust.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If physical security tokens are used for authentication, then access control is provided, but the tokens can be faked, stolen, or forged compromising security
Solution Approach 1:
The patent replaces physical security tokens with a cryptographic system based on distributed ledger technology. Instead of relying on physical objects that can be stolen or forged, the system uses cryptographic key pairs and digitally signed tokens stored on immutable ledgers, substituting mechanical/physical authentication mechanisms with cryptographic ones that are inherently more secure against duplication and theft.
Solution Approach 2:
The system creates digital copies of identity credentials in the form of cryptographically signed tokens that can be verified without exposing the original private keys. These token copies can be safely transmitted and stored while maintaining security through cryptographic verification, eliminating the need to share or physically handle sensitive authentication materials.
2Ease of operation
If uniform credentials are used across all product instances, then service access is simplified, but security is compromised as one credential can compromise multiple instances
Solution Approach 1:
The patent segments the authentication system into instance-specific credential pairs stored on individual distributed ledgers for each product instance. Instead of one uniform credential set across all instances, each instance has its own segmented cryptographic identity, so that compromise of one instance's credentials does not affect other instances. This segmentation maintains operational simplicity through automated verification while dramatically improving security isolation.
3Ease of operation
If personal relationships and trusted relationships are used for authentication, then access is granted based on recognition, but there is no automated revocation mechanism and nuanced access control is lacking
Solution Approach 1:
The system implements automated feedback mechanisms where the distributed ledger continuously verifies credential validity and can automatically revoke access by invalidating cryptographic signatures or removing token authorizations. This provides real-time feedback on authentication status without requiring personal intervention, enabling both automated access management and nuanced control through programmable authorization rules embedded in the smart contracts.
Data Source
AI summary
At least one identity for a given entity of a first enterprise is established in accordance with a decentralized identity management system maintained in accordance with a distributed ledger. The identity of the given entity of the first enterprise and a set of attributes relating to the identity are defined by at least one cryptographically signed token file. The cryptographically signed token file is referenced in the distributed ledger enabling a second enterprise to authenticate and/or authorize the given entity in accordance with at least one of the set of attributes.


