Decentralized Identity Management via Distributed Ledger

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication and authorization methods in cross-enterprise environments rely on physical security tokens that can be faked or stolen, or on personal relationships, lacking nuanced access control and automated revocation mechanisms, which compromises security and access management.

Innovation Solution

A decentralized identity management system using cryptographically signed token files stored on a distributed ledger, allowing for secure and attribute-based authentication and authorization across enterprises, eliminating the need for physical tokens and personal trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical security tokens are used for authentication, then access control is provided, but the tokens can be faked, stolen, or forged compromising security

Engineering Contradiction:
Improveaccess controlVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces physical security tokens with a cryptographic system based on distributed ledger technology. Instead of relying on physical objects that can be stolen or forged, the system uses cryptographic key pairs and digitally signed tokens stored on immutable ledgers, substituting mechanical/physical authentication mechanisms with cryptographic ones that are inherently more secure against duplication and theft.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system creates digital copies of identity credentials in the form of cryptographically signed tokens that can be verified without exposing the original private keys. These token copies can be safely transmitted and stored while maintaining security through cryptographic verification, eliminating the need to share or physically handle sensitive authentication materials.

Inventive Principle:
Principle #26Copying

2Ease of operation

If uniform credentials are used across all product instances, then service access is simplified, but security is compromised as one credential can compromise multiple instances

Engineering Contradiction:
Improveservice accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into instance-specific credential pairs stored on individual distributed ledgers for each product instance. Instead of one uniform credential set across all instances, each instance has its own segmented cryptographic identity, so that compromise of one instance's credentials does not affect other instances. This segmentation maintains operational simplicity through automated verification while dramatically improving security isolation.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If personal relationships and trusted relationships are used for authentication, then access is granted based on recognition, but there is no automated revocation mechanism and nuanced access control is lacking

Engineering Contradiction:
ImproveauthenticationVSAvoidaccess management
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The system implements automated feedback mechanisms where the distributed ledger continuously verifies credential validity and can automatically revoke access by invalidating cryptographic signatures or removing token authorizations. This provides real-time feedback on authentication status without requiring personal intervention, enabling both automated access management and nuanced control through programmable authorization rules embedded in the smart contracts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10587413B1Decentralized identities for cross-enterprise authentication and/or authorization
Publication Date: 2020.03.10 EMC IP HLDG CO LLC
  • US10587413B1 patent drawing
  • US10587413B1 patent drawing
  • US10587413B1 patent drawing

AI summary

At least one identity for a given entity of a first enterprise is established in accordance with a decentralized identity management system maintained in accordance with a distributed ledger. The identity of the given entity of the first enterprise and a set of attributes relating to the identity are defined by at least one cryptographically signed token file. The cryptographically signed token file is referenced in the distributed ledger enabling a second enterprise to authenticate and/or authorize the given entity in accordance with at least one of the set of attributes.