Decentralized Identity Verification via User Agent Ledger
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing broker-based identity verification systems are limited by reliance on active identity providers, inability to mix-and-match identification attributes, and disclosure of sensitive data, necessitating improved methods for electronic identity provision and verification.
Innovation Solution
An identity management system using a ledger-based approach where an identity provider server generates and transmits data bundles with encrypted attributes, utilizing user and identity provider public keys, and stores entries in ledgers for secure and decentralized authentication and authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a centralized broker is used to facilitate identity verification between identity providers and relying parties, then identity verification can be coordinated, but the system becomes vulnerable to service outages and requires continuous active participation of identity providers
Solution Approach 1:
The patent segments the centralized broker functionality into distributed components: identity providers, relying parties, and user agents operate independently without requiring a central coordinator. Each entity maintains its own data and verification processes, eliminating the single point of failure represented by the centralized broker.
Solution Approach 2:
The system enables self-service verification where user agents can directly interact with multiple identity providers and relying parties without broker mediation. Users control their own authentication data through cryptographic keys, allowing independent verification operations that do not depend on continuous broker availability or identity provider participation.
2Adaptability or versatility
If existing broker-based models are used, then identity verification is facilitated, but users cannot mix-and-match identification attributes from multiple identity providers
Solution Approach 1:
The patent implements a universal cryptographic framework where a single user agent can interact with multiple identity providers and relying parties using consistent cryptographic operations. The same public key infrastructure enables versatile attribute mixing across different providers without requiring provider-specific integration logic or broker-mediated coordination.
3Reliability
If broker-based identity verification is implemented, then authentication is enabled, but sensitive data such as addresses must be disclosed
Solution Approach 1:
The patent applies local quality by allowing selective disclosure of attributes based on verification needs. Users can provide specific authentication attributes (e.g., email verification) without disclosing unrelated sensitive data (e.g., physical address). The cryptographic system enables attribute-specific verification where each attribute can be independently validated without revealing the user's complete identity profile.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Systems and methods for decentralized and asynchronous authentication flow between users, relying parties and identity providers. A trusted user agent application or digital lock box under a user's control may perform the functions of an authentication broker. In particular, the user agent application or digital lock box can accept relying party requests and respond with authentication and identity data previously obtained from an identity provider server, and without the involvement of a centralized broker server.