DID Wallet Authentication Tokens to Reduce Claim Impersonation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In decentralized environments, verifiable claim issuers face challenges in verifying the authenticity of entities requesting claims, as malicious parties can impersonate legitimate subjects, leading to potential misuse of verifiable claims.

Innovation Solution

A digital wallet associated with a DID owner generates an identification value, which is signed using a private key, and requests an authentication token from an identity provider. This token is then used to request verifiable claims, ensuring the identity provider's authentication and validation, binding the authentication proofs to the DID owner's identity, thus verifying the authenticity of the claim requester.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If decentralized identifiers are used to eliminate centralized authority, then user control and privacy are improved, but authentication security and verification reliability deteriorate due to lack of centralized validation

Engineering Contradiction:
Improveuser controlVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an identity provider as an intermediary service that issues authentication tokens to verify the authenticity of decentralized identifiers. This mediator enables reliable authentication without requiring centralized control of the identifier itself, resolving the contradiction between user control and authentication security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional centralized mechanical authentication systems with a decentralized model using cryptographic tokens and distributed verification. The authentication mechanism shifts from centralized database validation to token-based verification, improving both user control and security simultaneously.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If verifiable claims are issued without strict authentication, then ease of operation and accessibility are improved, but security and risk of impersonation worsen

Engineering Contradiction:
ImproveaccessibilityVSAvoidimpersonation risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary authentication of the decentralized identifier against the identity provider before allowing any verifiable claim issuance. This preliminary verification step prevents impersonation attempts while maintaining smooth operation, as the authentication happens transparently in the background.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms where the identity provider continuously validates the authenticity of decentralized identifiers attempting to access verifiable claims. This feedback loop detects and prevents impersonation attempts while allowing legitimate users to operate seamlessly.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12388822B2Securing authentication flows using a decentralized identifier
Publication Date: 2025.08.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12388822B2 patent drawing
  • US12388822B2 patent drawing
  • US12388822B2 patent drawing

AI summary

A digital wallet generates an identification value associated with a DID of a DID owner. The digital wallet generates a first request including the identification value for an authentication token from an identification provider. The first request is provided to the identification provider. The digital wallet receives, in response to the identification provider validating the first request, the authentication token that authenticates the digital wallet with a verifiable claim issuer including the identification value from the identification provider. The digital wallet generates a second request for one or more verifiable claims from the verifiable claim issuer. The second request includes the DID and authentication token including the identification value. In response to the verifiable claim issuer validating the authentication token and the identification value, one or more verifiable claims from the verifiable claim issuer are received by the digital wallet.