Decentralized Identity Media Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional identity management systems are centralized, making them vulnerable and limiting user control over their identity data, whereas decentralized identifiers (DIDs) on a distributed ledger offer a secure, user-controlled solution but lack mechanisms for secure media data access and insertion.
Innovation Solution
A computing system and method that utilizes a decentralized network with a distributed ledger to manage DIDs, allowing partial access to media data based on user-associated DIDs, enabling secure insertion and access of media data while maintaining user control through cryptographic keys and permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized identity management systems are used, then security is maintained through professionally maintained hardware and software, but user control over identity data is limited and vulnerability to centralized attacks increases
Solution Approach 1:
The patent segments identity data into public and private portions, with the private portion encrypted and stored locally on user devices. This segmentation allows users to maintain control over their private identity data while still enabling verification through public portions, thus improving user control without compromising security.
Solution Approach 2:
The patent introduces decentralized identifiers (DIDs) as intermediaries that enable verification of identity data without requiring access to the actual private identity information. DIDs act as mediators that allow third-party verification while preserving user control and privacy, resolving the contradiction between security and user control.
2Ease of operation
If decentralized identifiers are used, then user control over identity data is improved and centralized vulnerability is reduced, but mechanisms for secure media data access and insertion are lacking
Solution Approach 1:
The patent embeds encrypted private identity data within media files, creating a nested structure where the identity information is hidden inside the media container. This nesting approach allows secure access control to be integrated within the existing media file structure, adding functionality without significant external complexity.
Solution Approach 2:
The patent performs preliminary encryption of private identity data before inserting it into media files. This advance preparation of the data with encryption and access control mechanisms simplifies subsequent access management, as the security framework is already in place before the data is shared or stored.
3Adaptability or versatility
If private portions of media data are made accessible to all users, then data sharing is improved, but security and user control are compromised
Solution Approach 1:
The patent applies different access permissions to different portions of the same media file. Public portions are accessible to all users, while private portions are encrypted and accessible only to authorized users. This local differentiation of access rights enables broad data sharing while maintaining security for sensitive information.
Solution Approach 2:
The patent changes the accessibility parameter of identity data within media files by encrypting private portions with user-specific keys. This parameter change allows the same media file to serve multiple purposes: public sharing for collaboration and secure private access for sensitive information, thus improving data sharing without compromising security.
Data Source
AI summary
Inserting media data into existing media data in a way that ensures the inserted data is not accessible to all users. The computing system and methods are implemented in a decentralized network that implements a distributed ledger, the distributed ledger backing one or more decentralized identities (DID) for one or more users of the computing system. Access to a first portion of media data is granted to various users. The access is partially based on a DID that is associated with each of the users. A second portion of media data is received that is inserted into the first portion of media data. The second portion of media data is accessible by only some of the users who have access to the first portion of media data. Access to the second portion of media data is also partially based on the DID of each of the subset of users.


