DID Wallet Delegated Credential Issuance for Offline Authority Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current DID-based service environments lack a standardized method for delegating verifiable credentials, which is essential for temporary authority and identity information transfer between users, particularly in offline environments.
Innovation Solution
A delegated credential data model is proposed, allowing users to apply the W3C verifiable credential data model standard in a DID-based service environment. This model enables the configuration and issuance of hierarchical delegated credentials through digital wallets connected to a DID registry, facilitating the transfer of credentials between users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a standardized delegated credential data model is implemented, then adaptability and versatility are improved, but device complexity increases
Solution Approach 1:
The delegated credential system is segmented into distinct functional components: the credential data model, the delegation mechanism, the verification process, and the DID registry integration. This segmentation allows each component to be developed and maintained independently, reducing overall system complexity while maintaining adaptability across different use cases
Solution Approach 2:
The delegated credential data model is designed as a universal framework that can accommodate multiple types of credentials and delegation scenarios through a single standardized interface. This multi-functionality approach enables the system to handle diverse credential types (identity, authorization, certification) without requiring separate complex mechanisms for each type
2Reliability
If hierarchical delegated credentials are configured and issued, then reliability is improved, but manufacturing precision requirements increase
Solution Approach 1:
The hierarchical credential structure implements a nested doll pattern where delegated credentials are embedded within the original credential framework. Each delegation level contains references to the parent credential, creating a nested hierarchy that ensures reliability through chained verification while maintaining manageable complexity at each nesting level
Solution Approach 2:
The system performs preliminary validation and configuration of the delegated credential structure before actual issuance. This includes pre-verifying the original credential validity, pre-establishing the delegation hierarchy, and pre-configuring verification rules, which ensures reliability while reducing the precision requirements during the actual credential issuance process
Data Source
AI summary
Disclosed herein are an apparatus and method for issuing delegated credentials between digital wallets possessed by multiple users connected to a Decentralized Identifier (DID) registry through wired/wireless communication. The method includes receiving, by a digital wallet of a first user, a delegated credential issuance request message including a newly created DID document from a digital wallet of a second user, generating, by the digital wallet of the first user, a delegated credential using both the delegated credential issuance request message, received from the digital wallet of the second user, and an original credential, previously issued by the digital wallet of the first user, and transmitting, by the digital wallet of the first user, the generated delegated credential and the original credential, together with a delegated credential registration request message, to the digital wallet of the second user.


