Decentralized Identity Permission Scope Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized identity management systems lack user control and flexibility in data access, as users have limited control over their personal data and cannot easily grant permissions to third-party applications, leading to potential misuse and loss of data privacy.

Innovation Solution

Implementing a decentralized network with a distributed ledger that uses Decentralized Identifiers (DIDs) to allow users to control their own data and grant permissions to applications on a scope-by-scope basis, ensuring that only necessary data is accessed for specific tasks, and enabling users to manage access rights directly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized identity management systems are used, then data security and authentication are improved, but user control and flexibility in data access are worsened

Engineering Contradiction:
Improvedata securityVSAvoiduser control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts control authority from centralized identity management systems and returns it to individual users through Decentralized Identifiers (DIDs). Each user owns their own DID and can selectively grant permissions to third-party applications without requiring centralized system intervention, thereby improving user control while maintaining security through cryptographic key pairs.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a decentralized permission management layer that acts as an intermediary between users and third-party applications. This layer enables users to grant specific permissions to applications without transferring full data access rights, allowing selective data sharing while maintaining overall security and user control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users grant full access to third-party applications, then application functionality is improved, but data privacy and security are worsened

Engineering Contradiction:
Improveapplication functionalityVSAvoiddata misuse risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments data access permissions into discrete, manageable scopes rather than granting full access. Users can authorize applications to access only specific data types, locations, or time periods based on the application's functional needs. This segmentation minimizes the risk of data misuse while maintaining the necessary functionality for legitimate applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables partial data access where applications receive only the specific data portions needed for their intended function rather than full data access. This partial action approach allows applications to function adequately without exposing users to unnecessary data privacy risks from excessive data access.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If decentralized identifier systems are implemented, then user control over data is improved, but system complexity is worsened

Engineering Contradiction:
Improveuser controlVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service functionality where users independently manage their own DIDs, generate key pairs, and control permission grants without requiring complex centralized system intervention. The decentralized architecture allows users to autonomously manage their data and permissions, simplifying the user experience while distributing system complexity across multiple independent nodes rather than concentrating it in a single complex central authority.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11381567B2Execution of an application within a scope of user-granted permission
Publication Date: 2022.07.05 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11381567B2 patent drawing
  • US11381567B2 patent drawing
  • US11381567B2 patent drawing

AI summary

Executing an application within a scope of user-granted permission in a decentralized network that implements a distributed edger. First, receiving a request from an entity for using data stored in a data storage that is associated with a DID owner as one or more inputs of an application associated with the entity to generate one or more results. Next, one or more characteristics of the application associated with the entity is identified. Based on identified one or more characteristics, a scope of permission to access the requested data that is to be granted to the entity is determined. Then, the scope of permission is granted to the entity to use the data as the one or more inputs of the application associated with the entity. Finally, the one or more results from the application is received.