Decentralized Identity Verification via User Agent Ledger

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing broker-based identity verification systems are limited by reliance on active identity providers, inability to mix-and-match identification attributes, and disclosure of sensitive data, necessitating improved methods for electronic identity provision and verification.

Innovation Solution

An identity management system using a ledger-based approach where an identity provider server generates and transmits data bundles with encrypted attributes, utilizing user and identity provider public keys, and stores entries in ledgers for secure and decentralized authentication and authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized broker is used to facilitate identity verification between identity providers and relying parties, then identity verification can be coordinated, but the system becomes vulnerable to service outages and requires continuous active participation of identity providers

Engineering Contradiction:
Improveidentity verification availabilityVSAvoidcentralized broker dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized broker functionality into distributed components: identity providers, relying parties, and user agents operate independently without requiring a central coordinator. Each entity maintains its own data and verification processes, eliminating the single point of failure represented by the centralized broker.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system enables self-service verification where user agents can directly interact with multiple identity providers and relying parties without broker mediation. Users control their own authentication data through cryptographic keys, allowing independent verification operations that do not depend on continuous broker availability or identity provider participation.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If existing broker-based models are used, then identity verification is facilitated, but users cannot mix-and-match identification attributes from multiple identity providers

Engineering Contradiction:
Improveattribute mixing capabilityVSAvoidbroker-based architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal cryptographic framework where a single user agent can interact with multiple identity providers and relying parties using consistent cryptographic operations. The same public key infrastructure enables versatile attribute mixing across different providers without requiring provider-specific integration logic or broker-mediated coordination.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If broker-based identity verification is implemented, then authentication is enabled, but sensitive data such as addresses must be disclosed

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsensitive data disclosure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by allowing selective disclosure of attributes based on verification needs. Users can provide specific authentication attributes (e.g., email verification) without disclosing unrelated sensitive data (e.g., physical address). The cryptographic system enables attribute-specific verification where each attribute can be independently validated without revealing the user's complete identity profile.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3424177B1Systems and methods for distributed identity verification
Publication Date: 2021.10.13 SECUREKEY TECH
  • EP3424177B1 patent drawingFigure 1
  • EP3424177B1 patent drawingFigure 2
  • EP3424177B1 patent drawingFigure 3A

AI summary

Systems and methods for decentralized and asynchronous authentication flow between users, relying parties and identity providers. A trusted user agent application or digital lock box under a user's control may perform the functions of an authentication broker. In particular, the user agent application or digital lock box can accept relying party requests and respond with authentication and identity data previously obtained from an identity provider server, and without the involvement of a centralized broker server.