Digital Identity Authentication via Distributed Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital identity verification systems are vulnerable to identity theft, errors in recording invariant identity data, fraudulent profiles, and fraudulent corporate roles due to reliance on passwords, centralization of sensitive information, and lack of secure multi-factor authentication, leading to significant financial and emotional losses, as well as undermining trust in online transactions and critical infrastructure.

Innovation Solution

A digital identity authentication system utilizing a computer platform with an identity server that employs multi-factor authentication, public identifiers, and encryption, where an identity editor verifies and signs user data, and a requestor verifies the identity through a challenge-response process using public and private keys, ensuring secure and accurate identity confirmation independent of invariant data secrecy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized databases store identity information for verification, then identity verification can be performed remotely, but the system becomes vulnerable to hacking, fraud, and identity theft

Engineering Contradiction:
Improveremote identity verificationVSAvoidsecurity against hacking and fraud
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the identity verification process from centralized databases and redistributes verification capabilities to multiple independent validators. Each validator holds a portion of the verification logic, and identity confirmation requires consensus from multiple validators, eliminating the single point of failure in centralized systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the centralized identity verification function into distributed validation nodes. Identity data is divided into multiple components stored across different validators, and verification requires aggregation of results from multiple segments, preventing any single node from compromising the entire system.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If passwords are used for authentication, then users can access online services, but passwords can be stolen, leading to identity theft and security breaches

Engineering Contradiction:
Improveuser authenticationVSAvoidpassword theft and fraud
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical password-based authentication system with a cryptographic key pair system. Instead of relying on secret passwords stored in databases, the system uses public-key cryptography where verification is performed through cryptographic proofs rather than secret sharing, eliminating the vulnerability of password theft.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system introduces cryptographic protocols as intermediaries between users and service providers. Rather than direct password verification, a cryptographic mediator layer performs zero-knowledge proofs and digital signature verification, allowing authentication without exposing sensitive credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If invariant identity data is kept secret, then identity security is maintained, but errors in recording invariant data can go undetected

Engineering Contradiction:
Improveidentity securityVSAvoiddetection of recording errors
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where validators cross-check invariant identity data against multiple independent sources and verify consistency through cryptographic proofs. Errors in recording are detected through discrepancy analysis between different validation paths, providing feedback that maintains both security and accuracy.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies different verification strategies to different types of identity data. Invariant data undergoes cross-validation through multiple independent verification paths with error-detection codes, while variant data uses different validation mechanisms, optimizing both security and error detection for each data type.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11044087B2System for digital identity authentication and methods of use
Publication Date: 2021.06.22 VAN DER VELDEN ALEXANDER J M
  • US11044087B2 patent drawing
  • US11044087B2 patent drawing
  • US11044087B2 patent drawing

AI summary

A cryptography system for digital identity authentication, and security including a computer system or platform to enable users (individual, identity editor, requestor) using invariant and variant data on an identity server which uses multi-factor authentication, one or more user devices, at least one hardware device; and utilizing an authentication protocol system with an encryption function having a hardware key and a software key, a private key and a public key. The private key may be generated from said hardware key and said software key may be stored on said at least one hardware device in communication with one of said one or more user devices. The public key may be managed in a key infrastructure on said identity server. The public key may be restricted to use between paired user accounts on said server.