Decentralized Identifier Management for Secure Attribute Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing decentralized identifier (DID) technologies are inadequate for efficient attribute management and relationship establishment in both digital and physical environments, leading to inefficient manual review processes and limited usability outside of specific networks.

Innovation Solution

The implementation of a networked environment that utilizes decentralized identifiers (DIDs) for secure and convenient attribute management, integrating verifiable credentials (VCs) and physical chips to streamline relationship establishment and attribute access, enabling secure interactions and automatic data exchange without user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual first-party review is used for relationship establishment, then verification accuracy is improved, but processing time and operational efficiency deteriorate

Engineering Contradiction:
Improveverification accuracyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

A decentralized identifier (DID) management system acts as an intermediary between entities seeking relationship establishment and the verifying party. The system automatically manages DIDs, verifiable credentials, and relationship criteria, replacing manual review while maintaining verification integrity through cryptographic proof and automated validation mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Relationship criteria and verification requirements are pre-configured in the DID management system before actual relationship establishment occurs. The system pre-establishes trust frameworks, credential schemas, and validation rules, enabling automated real-time verification without manual intervention during the actual relationship formation process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional physical space interactions are used, then face-to-face verification is improved, but operational efficiency and scalability deteriorate

Engineering Contradiction:
Improveverification authenticityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Physical face-to-face verification mechanisms are replaced with cryptographic verification systems based on decentralized identifiers and verifiable credentials. The system uses digital signatures, blockchain verification, and automated credential validation to replace manual visual inspection and physical document verification, maintaining authenticity while enabling remote and scalable operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The DID management system provides universal verification capabilities that work across multiple platforms, devices, and interaction modes (digital and physical). The same cryptographic framework supports mobile applications, web interfaces, in-person interactions, and automated systems, eliminating the need for separate verification processes for different contexts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If network-specific relationship credentials are issued, then network security is improved, but usability outside the network deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidexternal usability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system issues verifiable credentials that are both network-specific and universally compatible. DIDs follow W3C standards that enable verification across different networks and platforms, while the credential content can be customized for specific network requirements. This dual compatibility allows credentials to maintain security within the issuing network while remaining usable and verifiable outside the network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The verification system segments credentials into modular components: the DID itself (universal identifier), the credential schema (network-specific requirements), and the verification method (flexible validation rules). This segmentation allows the same credential structure to satisfy both network-specific security requirements and general interoperability standards, enabling use across different contexts.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250045374A1Relationship and attribute management using decentralized identifiers
Publication Date: 2025.02.06 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US20250045374A1 patent drawing
  • US20250045374A1 patent drawing
  • US20250045374A1 patent drawing

AI summary

Disclosed are various approaches for relationship and attribute management are described. In some examples, a verifier service performs a verification process using a relationship decentralized identifier (DID) that provides proof of a relationship between the holder and a DID management service. An attribute request is that specifies an attribute is transmitted from the verifier service to the DID management service. The DID management service provides the verifier service with information based on the attribute once the holder provides an authorization response that authorizes usage of the attribute.