Decentralized Identifier Delegation via Signed Claims

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized identity management systems are limited in flexibility and convenience, as they require direct interaction between parties for identity verification and management, which can be inefficient and time-consuming.

Innovation Solution

A method for delegating the use of a Decentralized Identifier (DID) from a first DID owner to a second DID owner, allowing the second owner to act on behalf of the first owner in interactions with third-party entities, through a signed claim that specifies the scope of permission, which is recorded on a distributed ledger.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized identity management systems are used, then security is improved through professional hardware and software maintenance, but flexibility and convenience deteriorate due to direct interaction requirements

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility and convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a third-party service that acts as an intermediary between the first DID owner and the second DID owner. This service enables the first owner to delegate DID usage rights to the second owner without requiring direct interaction or technical expertise from either party, thus maintaining security while improving ease of operation through automated delegation processes

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If direct interaction between parties is required for identity verification, then security control is maintained, but processing time increases and productivity decreases

Engineering Contradiction:
Improvesecurity controlVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by allowing the first DID owner to pre-establish and record delegation relationships with multiple second DID owners before actual verification events occur. These pre-configured delegations are stored in a distributed ledger, enabling rapid verification without requiring time-consuming direct interactions during actual use, thus reducing processing time while maintaining security through cryptographic verification

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If centralized identity management is used, then identity verification can be performed, but system complexity and interaction requirements increase

Engineering Contradiction:
Improveidentity verification capabilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent extracts the complex centralized identity management functionality and distributes it across multiple independent DIDs and a distributed ledger system. Instead of requiring a single complex centralized system, the system uses simple, self-contained DID structures that can be independently managed by different owners, reducing overall system complexity while maintaining verification capability through cryptographic proofs recorded on the distributed ledger

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4018614B1Did delegation/revocation to another did
Publication Date: 2024.05.22 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4018614B1 patent drawingFigure 1
  • EP4018614B1 patent drawingFigure 2
  • EP4018614B1 patent drawingFigure 3

AI summary

Delegating use of a DID from a first DID owner to a second DID owner. An indication is received that a first DID owner desires to delegate use of a DID owned by the first DID owner to a second DID owner. This may allow the second DID owner to act on behalf of the first DID owner in interactions with third-party entities. A signed claim is generated that specifies that the first DID owner has delegated use of the DID to the second DID owner. The signed claim identifies the DID owned by the first DID owner and defines a scope of permission for the second DID owner when the second DID owner uses the delegated DID on behalf of the first DID owner. The signed claim may then be provided to the second DID owner.