Decentralized Identity Management via Realm Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems are vulnerable to threats such as identity fraud and data misuse due to centralized architectures, which can compromise privacy and security, and lack efficient decentralized authentication and authorization methods.

Innovation Solution

A decentralized identity management system using a network of realm servers and computing devices that enables the creation, enrollment, and validation of digital identities, with hierarchical distribution of identity records and consensus-based validation, allowing for secure and private authentication and authorization across federated networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized digital identity management systems are used, then authentication and authorization can be achieved, but security and privacy are compromised due to centralized architecture vulnerabilities

Engineering Contradiction:
Improveauthentication securityVSAvoidcentralized architecture vulnerability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized identity management system into distributed realm servers, each independently managing identity records for specific realms. Identity records are divided into discrete units that can be selectively published and subscribed to across the network, eliminating the single point of failure inherent in centralized systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces identity records as intermediary data structures that contain public encryption keys and identity information. These records act as mediators between authentication requests and validation, enabling decentralized verification without requiring direct trust in a centralized authority.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If all identity records are distributed to all computing devices, then authentication can be performed locally, but network traffic and memory requirements increase significantly

Engineering Contradiction:
Improvelocal authentication capabilityVSAvoiddata storage requirement
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent implements local quality by allowing each computing device to subscribe to and store only the specific identity records relevant to its operational context. Different devices maintain different subsets of identity records based on their local needs, rather than all devices storing all possible identity records.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by implementing selective subscription where computing devices receive only a portion of the total identity records - specifically those needed for their local authentication and authorization operations. This avoids the excessive storage requirement of distributing complete identity databases to all devices.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If decentralized identity management is implemented, then security and privacy are improved, but system complexity increases due to distributed architecture

Engineering Contradiction:
Improveprivacy protectionVSAvoiddistributed system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the fundamental parameter of system architecture from centralized to decentralized, organizing identity management around autonomous realm servers and distributed computing devices. This parameter change enables privacy protection through cryptographic methods while the modular realm structure manages complexity through standardized interfaces and protocols.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240179015A1Method and system for decentralized identity management and data distribution
Publication Date: 2024.05.30 HATHAWAY MICHAEL WILLIAM
  • US20240179015A1 patent drawing
  • US20240179015A1 patent drawing
  • US20240179015A1 patent drawing

AI summary

A computing and network system employs decentralized methods to create and maintain digital identities for network connected computing devices and the distribution of information between them on public and private networks. Embodiments enable identities to be authenticated and digitally signed, and shared information to be validated by network services using locally stored information.