Digital Credential Verification via Distributed Ledger

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack secure and efficient methods for verifying and managing digital credentials, leading to issues with data theft and misrepresentation during information transfer.

Innovation Solution

A system utilizing a distributed ledger for secure storage and verification of digital credentials, employing cryptography and smart contracts to authenticate and authorize access, ensuring the legitimacy and integrity of credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If digital credentials are distributed to users for proving qualifications, then user authentication capability is improved, but security against data theft and misrepresentation deteriorates

Engineering Contradiction:
Improveuser authentication capabilityVSAvoidsecurity against data theft and misrepresentation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A distributed ledger system acts as an intermediary between credential issuers and users. The ledger stores cryptographic proofs of credential issuance and verification, preventing both data theft (by eliminating centralized vulnerable storage) and misrepresentation (by providing immutable verification records). Users can prove qualifications through cryptographic proofs without exposing sensitive credential data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If cryptographic digital credentials are distributed to users, then authentication efficiency is improved, but verification security deteriorates due to lack of secure external device confirmation

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidverification security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The distributed ledger serves as a trusted intermediary that enables secure verification between external devices and the authentication system. When a user presents cryptographic credentials, the verifying device can query the ledger to confirm the credential's authenticity and status without requiring secure physical confirmation or trusted hardware channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the distributed ledger provides real-time verification status of credentials. Verifying devices receive immediate confirmation from the ledger about credential validity, revocation status, and issuance authenticity, enabling efficient and secure verification without manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11698979B2Digital credentials for access to sensitive data
Publication Date: 2023.07.11 WORKDAY INC
  • US11698979B2 patent drawing
  • US11698979B2 patent drawing
  • US11698979B2 patent drawing

AI summary

A system for providing access is configured to receive an application access request from an application for authorization to access and a sensitive data access request from the application for authorization to access a document that includes sensitive data. The system is further configured to determine to authorize access to the application in response to the application access request; to determine the user authentication device in response to the sensitive data access request; to provide a secondary request for authorization to access sensitive data to the user authentication device in response to the sensitive data access request, receive a secondary request response from the user authentication device to the secondary request; and to provide the secondary request response to the application enabling access to the sensitive data, where the document is encrypted for delivery to the application for the user using a blinding secret and an identity private key.