Digital Identity System Using Credential Publication Modules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional identity verification methods, such as passports and national ID cards, are cumbersome and valuable, making it inconvenient to carry them everywhere, while digital identity solutions lack robust security and efficient management.
Innovation Solution
A digital identity system that creates a digital profile from real-world identity documents, using a processor to generate credentials and publish profiles securely, allowing entities to assert their identity through a digital credential, which can be verified by comparing visual images and metadata, with features like one-time use credentials and confidence values for enhanced security and accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical identity documents (passports, ID cards) are used for verification, then security and reliability are improved, but ease of operation deteriorates due to the need to carry physical documents everywhere
Solution Approach 1:
The patent creates digital copies of physical identity documents in the form of credentials stored on mobile devices. The enrolment module captures data from physical documents and creates digital profiles, which are then used to generate credentials that can be presented electronically, eliminating the need to carry physical documents while maintaining verification capability
Solution Approach 2:
The patent segments the identity verification process into distinct components: enrolment (creating digital profiles from physical documents), credential generation (creating secure tokens), and verification (validating credentials against published profiles). This segmentation allows the system to separate the secure storage of identity data from the presentation of credentials, improving both security and convenience
2Ease of operation
If digital identity solutions are implemented, then ease of operation is improved by eliminating physical documents, but reliability deteriorates due to security concerns about digital storage and access
Solution Approach 1:
The patent introduces an intermediary verification process where credentials are not directly validated against stored profiles but through a published profile mechanism. The publication module creates time-limited, purpose-specific publications of profile data, and validators verify credentials against these publications rather than accessing raw profile data, adding a layer of security mediation
Solution Approach 2:
The patent implements dynamic credential validation where the system adapts verification requirements based on the validation context. The validator can request additional information or re-validation as needed, and the system supports revocation and renewal of credentials, making the security model flexible and responsive to threats rather than static
3Productivity
If digital profiles are made accessible for verification, then ease of operation is improved by enabling quick validation, but security deteriorates due to potential exposure of sensitive identity information
Solution Approach 1:
The patent applies local quality by publishing only the specific portions of identity profiles that are necessary for the verification purpose at hand, rather than exposing the entire profile. The publication module selectively releases profile data with appropriate granularity, and credentials can be generated for specific purposes (e.g., age verification only), ensuring that sensitive information not needed for the specific validation remains protected
Solution Approach 2:
The patent implements periodic action through time-limited profile publications. Published profiles have expiration times and are automatically revoked after use or after a specified period, requiring periodic re-publication for ongoing verification needs. This temporal limitation reduces the window of vulnerability for exposed information while maintaining verification capability when needed
4Reliability
If comprehensive identity data is stored in digital profiles, then reliability is improved by enabling thorough verification, but device complexity increases due to storage and management requirements
Solution Approach 1:
The patent extracts only the essential verification data from complete identity profiles and stores it in published, time-limited formats suitable for validation purposes. The enrolment module captures comprehensive data from physical documents, but the publication module selectively releases only what is necessary for specific verification contexts, reducing storage requirements while maintaining verification accuracy
Data Source
AI summary
The disclosure relates to a digital identity system including an enrolment module executing on a processor configured to receive a data item from an enrolling device and to create in persistent electronic storage a digital profile comprising the data item. The system also includes a credential creation module executing on a processor configured to generate a credential from a random sequence, to associate the credential with the digital profile in a database, and to transmit the credential to the enrolling device. The system further includes a publication module executing on a processor configured, in response to later presentation of the credential to the digital identity system, to publish the digital profile by storing a version of the digital profile in a memory location accessible to a device presenting the credential.


