Digital Credential Verification via Distributed Ledger

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack secure and efficient methods for verifying and managing digital credentials, leading to issues with data theft and misrepresentation during information transfer.

Innovation Solution

A system utilizing a distributed ledger for secure storage and verification of digital credentials, employing cryptography and smart contracts to ensure legitimacy and authenticity, allowing users to prove identity and access through a decentralized identifier system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If digital credentials are used for authentication, then identity verification capability is improved, but security against data theft and misrepresentation deteriorates

Engineering Contradiction:
Improveidentity verification capabilityVSAvoidsecurity against data theft and misrepresentation
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a distributed ledger system as an intermediary between credential issuers and verifiers. The ledger stores cryptographic proofs and credential metadata immutably, mediating the authentication process to prevent both data theft and misrepresentation. This resolves the contradiction by enabling precise identity verification through cryptographic proofs while maintaining security through the decentralized, tamper-proof nature of the ledger.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical authentication systems (centralized databases, password verification) with cryptographic mechanisms. Digital credentials use public-key cryptography, digital signatures, and zero-knowledge proofs to verify identity without exposing sensitive data. This substitution enables accurate identity verification while enhancing security, as cryptographic operations are mathematically guaranteed to prevent theft and misrepresentation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Speed

If centralized credential verification systems are used, then verification speed is improved, but vulnerability to data theft and misrepresentation increases

Engineering Contradiction:
Improveverification speedVSAvoidvulnerability to data theft and misrepresentation
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent segments the credential verification process into independent cryptographic operations that can be performed distributedly. Instead of a single centralized verification point, the system divides verification into: (1) credential presentation by holder, (2) cryptographic validation by verifier, and (3) immutable record storage on distributed ledger. This segmentation maintains verification speed through parallel processing while eliminating the single point of failure that creates vulnerability to theft and misrepresentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The distributed ledger acts as a trusted intermediary that stores cryptographic proofs without storing sensitive personal data. The ledger mediates between credential issuers and verifiers, providing fast verification through cryptographic checks while preventing data theft by never centralizing sensitive information. This resolves the contradiction by enabling rapid verification through efficient cryptographic operations while the distributed nature of the ledger prevents misrepresentation and theft.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cryptographic verification methods are implemented, then security against misrepresentation is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity against misrepresentationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses cryptographic copies (digital signatures, hashes, and proofs) instead of storing or transmitting sensitive original data. The system verifies credentials by checking cryptographic copies that mathematically prove authenticity without exposing the actual credential data. This approach enhances security against misrepresentation while reducing system complexity, as cryptographic verification is simpler than managing and protecting sensitive data stores.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces complex mechanical security systems (physical security, manual verification procedures, centralized data protection infrastructure) with cryptographic mechanisms. Public-key cryptography, digital signatures, and zero-knowledge proofs provide automated, mathematically guaranteed security that is actually simpler to implement than traditional security infrastructure. This substitution improves security against misrepresentation while reducing overall system complexity by eliminating the need for complex physical and procedural security measures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11531783B2Digital credentials for step-up authentication
Publication Date: 2022.12.20 WORKDAY INC
  • US11531783B2 patent drawing
  • US11531783B2 patent drawing
  • US11531783B2 patent drawing

AI summary

The system comprises an interface and a processor. The interface is configured to receive a request from an application for authorization to access, wherein access to the application is requested by a user, and receive a task request from the application for authorization to access a task, wherein access to the task is requested by the user. The processor is configured to authenticate the request from the application for authorization to access, determine that the task comprises a sensitive task, determine a user authentication device, provide a challenge for a digital credential to the user authentication device, wherein the digital credential is backed by data stored in a distributed ledger, receive a response from the user authentication device, determine the response is valid, and provide an authorization to access the sensitive task.