Decentralized Identity Management via Realm Servers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital identity management systems are vulnerable to threats such as identity fraud and data misuse due to centralized architectures, which can compromise privacy and security, and lack efficient decentralized authentication and authorization methods.
Innovation Solution
A decentralized identity management system using a network of realm servers and computing devices that enables the creation, enrollment, and validation of digital identities, with hierarchical distribution of identity records and consensus-based validation, allowing for secure and private authentication and authorization across federated networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized digital identity management systems are used, then authentication and authorization can be achieved, but security and privacy are compromised due to centralized architecture vulnerabilities
Solution Approach 1:
The patent segments the centralized identity management system into distributed realm servers, each independently managing identity records for specific realms. Identity records are divided into discrete units that can be selectively published and subscribed to across the network, eliminating the single point of failure inherent in centralized systems.
Solution Approach 2:
The patent introduces identity records as intermediary data structures that contain public encryption keys and identity information. These records act as mediators between authentication requests and validation, enabling decentralized verification without requiring direct trust in a centralized authority.
2Ease of operation
If all identity records are distributed to all computing devices, then authentication can be performed locally, but network traffic and memory requirements increase significantly
Solution Approach 1:
The patent implements local quality by allowing each computing device to subscribe to and store only the specific identity records relevant to its operational context. Different devices maintain different subsets of identity records based on their local needs, rather than all devices storing all possible identity records.
Solution Approach 2:
The patent applies partial action by implementing selective subscription where computing devices receive only a portion of the total identity records - specifically those needed for their local authentication and authorization operations. This avoids the excessive storage requirement of distributing complete identity databases to all devices.
3Reliability
If decentralized identity management is implemented, then security and privacy are improved, but system complexity increases due to distributed architecture
Solution Approach 1:
The patent changes the fundamental parameter of system architecture from centralized to decentralized, organizing identity management around autonomous realm servers and distributed computing devices. This parameter change enables privacy protection through cryptographic methods while the modular realm structure manages complexity through standardized interfaces and protocols.
Data Source
AI summary
A computing and network system employs decentralized methods to create and maintain digital identities for network connected computing devices and the distribution of information between them on public and private networks. Embodiments enable identities to be authenticated and digitally signed, and shared information to be validated by network services using locally stored information.


