Decentralized Identity Verification Using DIDs and Zero-Knowledge Proofs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centralized identity agencies store and have access to sensitive user information indefinitely, leading to potential data breaches and loss of user control over their information, with users often oversharing private data and relying on third-party login services that collect and sell personal information.
Innovation Solution
A decentralized identity verification system using blockchain technology allows users to store private data securely in a digital wallet, sharing only the necessary information with verifier entities through decentralized identifiers (DIDs) and zero-knowledge proofs, ensuring control over data sharing and verification without relying on centralized agencies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized identity agencies store sensitive user information indefinitely, then verification can be performed, but data security and user privacy are compromised
Solution Approach 1:
The patent extracts sensitive personal information from centralized storage and replaces it with decentralized identifiers (DIDs) and cryptographic proofs. Users retain control of their data in personal wallets, while only verification results are shared with third parties, eliminating the need for centralized agencies to store sensitive information indefinitely.
Solution Approach 2:
The patent introduces cryptographic intermediaries (zero-knowledge proofs, digital signatures, and verifiable credentials) that enable verification without direct access to sensitive data. These cryptographic mechanisms act as mediators between users and verifying entities, allowing verification while preserving privacy and security.
2Measurement precision
If users provide complete identity information to verification entities, then verification accuracy is improved, but user privacy and data control are lost
Solution Approach 1:
The patent applies local quality by enabling selective disclosure of information attributes. Users can choose which specific attributes of their identity to reveal to verification entities based on the verification requirements, rather than disclosing complete identity information. This allows verification accuracy while minimizing privacy loss.
Solution Approach 2:
The patent implements partial action by allowing users to disclose only the minimum necessary information required for verification. Through selective attribute revelation and zero-knowledge proofs, users provide just enough information to satisfy verification requirements without oversharing private data.
3Adaptability or versatility
If centralized agencies collect and store user data over time, then service functionality is enhanced, but device complexity and data management burden increase
Solution Approach 1:
The patent implements self-service by enabling users to autonomously manage their own identity data through personal wallets and digital identity applications. Users can store, protect, and selectively disclose their information without relying on centralized agencies to collect and manage data on their behalf, reducing data management complexity.
Solution Approach 2:
The patent applies universality through the creation of a standardized digital identity framework that can be used across multiple services and platforms. The same decentralized identifier and verifiable credential system can serve various verification needs (age verification, identity confirmation, credential validation) without requiring separate data collection systems for each service.
Data Source
AI summary
Techniques are disclosed relating to facilitating secure communication of private user data between different entities for a verification process conducted during an electronic interaction between the user and a verifier entity. In disclosed embodiments, a verification service executing on a server computer system for a verification session for verifying a holder entity on behalf of a verifier entity receives a verification request from a remote computer system. The verification request includes an attestation proof generated from one or more credentials and the verification service communicates with a holder service that manages an identity storage storing credentials for the holder entity. The verification service transmits, to the verifier service, the attestation proof and then receives, from the verifier service based on the proof, verification results that are usable by the verifier to determine whether to process an action requested by the holder prior to requesting verification.


