Decentralized Identity Authentication via Secure Containers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems face data confidentiality issues due to centralized storage of personal data, making them vulnerable to attacks and intrusions.

Innovation Solution

A method and system where personal data is stored on a user's terminal in a secure container, with only links to this data stored on a server, allowing authorization and access to the data by a third-party device without storing the data itself, ensuring secure and decentralized storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personal data is stored on a centralized server, then data accessibility and service provision are improved, but data security and confidentiality deteriorate due to vulnerability to attacks and intrusions

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments data storage by moving personal data from centralized server storage to decentralized storage on users' personal devices. Only metadata (links) are stored centrally, while actual personal data resides locally in secure containers on user terminals, eliminating the centralized storage vulnerability while maintaining accessibility through the link-based retrieval mechanism

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention extracts personal data from the centralized server storage environment and places it on users' personal devices. The server retains only the link to the data and authorization metadata, effectively removing the harmful centralized storage of sensitive personal information while preserving the ability to access data through authorized requests

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of manufacture

If personal data is stored on a centralized server, then service provisioning is simplified, but data confidentiality deteriorates in the event of server attack or intrusion

Engineering Contradiction:
Improveservice provisioningVSAvoiddata confidentiality
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system separates data storage functions between centralized metadata storage (links) and decentralized personal data storage (secure containers on user devices). This segmentation maintains service provisioning capability through link-based data location while ensuring data confidentiality by eliminating centralized storage of sensitive personal information

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces secure containers as intermediary storage structures on user devices that hold personal data. These containers act as trusted intermediaries between the centralized server (which only stores links) and the actual data, enabling service provisioning while protecting data confidentiality through localized secure storage

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If personal data is stored on user terminals in secure containers, then data security and confidentiality are improved, but system complexity increases due to decentralized storage and authorization mechanisms

Engineering Contradiction:
Improvedata securityVSAvoidsystem architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The invention extracts the complex data storage function from the centralized server and relocates it to users' personal devices. While this increases individual device complexity, it eliminates server-side complexity related to secure data storage and reduces overall system complexity by using simple link-based references instead of complex centralized data management

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements self-service through user terminals that autonomously manage their own secure containers and data storage. Each terminal independently handles its personal data without requiring centralized server intervention for storage operations, reducing server complexity while distributing the complexity burden to end-user devices that already possess the necessary computational capabilities

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3757832B1System and method for remote authentication of a person holding an identity document by a third party
Publication Date: 2023.05.17 IMPRIMERIE NAT
  • EP3757832B1 patent drawingFigure 1
  • EP3757832B1 patent drawingFigure 2
  • EP3757832B1 patent drawingFigure 3

AI summary

The invention relates to a method and a system for authenticating a person (1) by a third-party device (15), wherein: - the person transmits personal data to a third-party device, which transmits a data verification request to a server, - the server (10) uses at least one of the identity document data contained in the request to find the link associated with the secure container containing the person's data, - the server (10) transmits an authorization request to a dedicated application so that the person can authenticate themselves and grant authorization to access at least part of the data in the secure container, - upon authorization by the person (36), the dedicated terminal application opens the container and transmits the data to the server, (37, 38), - the server transmits (39), without storing them, the part of the data accessible to the third-party device, which, after authentication of the person, authorizes the latter to use a service, (40),- when there is no authorization, a rejection message is sent, (41).