Attribute Information Conversion for Decentralized Identity Interoperability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a decentralized identity (DID) platform environment, there is a challenge in verifying user attribute information across different DID platforms with distinct signature and verification schemes, as certificates issued by one platform may not be recognized or verified by another platform.

Innovation Solution

An attribute information conversion device and method that interconnects two DID platforms with different signature schemes, allowing for the conversion of user attribute information from one platform to another by generating linked verification and issuance request URLs, enabling the verification and re-signing of certificates for compatibility across platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificates are issued with platform-specific signature schemes, then security and authenticity are ensured within each DID platform, but interoperability between different DID platforms is compromised

Engineering Contradiction:
Improvecertificate verification reliabilityVSAvoidcross-platform compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a conversion device as an intermediary between different DID platforms. This device receives certificates from one platform, verifies them using the source platform's signature scheme, converts the certificate format and signature to be compatible with the target platform, and issues a new certificate. This intermediary approach maintains the security of both platforms while enabling cross-platform interoperability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The conversion device changes the cryptographic parameters of certificates during conversion. It transforms signature schemes, verification methods, and certificate structures from one platform's specifications to another platform's specifications. This parameter transformation allows certificates to maintain their security properties while becoming compatible with different platform requirements.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple DID platforms operate with independent signature schemes, then each platform maintains control over its security standards, but user attribute information cannot be verified across platforms

Engineering Contradiction:
Improveplatform independenceVSAvoidcross-platform verification reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The conversion device serves as a trusted intermediary that bridges independent DID platforms. It accepts certificates verified by source platform standards, performs conversion while preserving security properties, and issues certificates verifiable by target platform standards. This enables platform independence to be maintained while achieving cross-platform verification reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements verification feedback mechanisms where the conversion device receives verification results from both source and target platforms. It uses this feedback to ensure that converted certificates maintain security properties and can be successfully verified across platform boundaries, continuously improving cross-platform reliability.

Inventive Principle:
Principle #23Feedback

3Device complexity

If direct verification between different DID platforms is attempted, then system complexity is minimized, but verification fails due to incompatible signature schemes

Engineering Contradiction:
Improveverification system complexityVSAvoidverification success rate
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Rather than attempting direct verification between incompatible platforms, the patent introduces a conversion intermediary that handles the complexity of signature scheme translation. This approach increases local device complexity but eliminates the need for complex multi-platform verification logic, achieving simpler overall system architecture with reliable verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If certificate conversion functionality is added to existing ID Wallet applications, then cross-platform compatibility is achieved, but existing applications require additional functions and modifications

Engineering Contradiction:
Improvecross-platform certificate compatibilityVSAvoidapplication functionality complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The conversion device operates as a standalone intermediary service that existing ID Wallet applications can utilize without modification. Applications simply interact with the conversion device through standardized interfaces to obtain converted certificates, avoiding the need to embed complex conversion functionality within each application and maintaining application simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12177362B2Attribute information conversion device, computer-readable recording medium storing attribute information conversion program, and attribute information conversion method
Publication Date: 2024.12.24 FUJITSU LTD
  • US12177362B2 patent drawing
  • US12177362B2 patent drawing
  • US12177362B2 patent drawing

AI summary

An attribute information conversion device includes: a memory; and a processor coupled to the memory and configured to: issue first access information and second access information linked to each other in response to a request upon reception of the request for conversion from attribute information of a first type of a user that may be used in a first service into the attribute information of a second type that may be used in a second service different from the first service; perform, upon acquisition of the attribute information of the user from a terminal through the first access information, conversion of the acquired attribute information from the attribute information of the first type into the attribute information of the second type; and output the converted attribute information to a terminal that has made access through the second access information.