Digital Identity System Using Credential Publication Modules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional identity verification methods, such as passports and national ID cards, are cumbersome and valuable, making it inconvenient to carry them everywhere, while digital identity solutions lack robust security and efficient management.

Innovation Solution

A digital identity system that creates a digital profile from real-world identity documents, using a processor to generate credentials and publish profiles securely, allowing entities to assert their identity through a digital credential, which can be verified by comparing visual images and metadata, with features like one-time use credentials and confidence values for enhanced security and accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical identity documents (passports, ID cards) are used for verification, then security and reliability are improved, but ease of operation deteriorates due to the need to carry physical documents everywhere

Engineering Contradiction:
Improveidentity verification securityVSAvoidconvenience of carrying documents
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates digital copies of physical identity documents in the form of credentials stored on mobile devices. The enrolment module captures data from physical documents and creates digital profiles, which are then used to generate credentials that can be presented electronically, eliminating the need to carry physical documents while maintaining verification capability

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent segments the identity verification process into distinct components: enrolment (creating digital profiles from physical documents), credential generation (creating secure tokens), and verification (validating credentials against published profiles). This segmentation allows the system to separate the secure storage of identity data from the presentation of credentials, improving both security and convenience

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If digital identity solutions are implemented, then ease of operation is improved by eliminating physical documents, but reliability deteriorates due to security concerns about digital storage and access

Engineering Contradiction:
Improveconvenience of digital identityVSAvoidsecurity of digital credentials
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary verification process where credentials are not directly validated against stored profiles but through a published profile mechanism. The publication module creates time-limited, purpose-specific publications of profile data, and validators verify credentials against these publications rather than accessing raw profile data, adding a layer of security mediation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements dynamic credential validation where the system adapts verification requirements based on the validation context. The validator can request additional information or re-validation as needed, and the system supports revocation and renewal of credentials, making the security model flexible and responsive to threats rather than static

Inventive Principle:
Principle #15Dynamics

3Productivity

If digital profiles are made accessible for verification, then ease of operation is improved by enabling quick validation, but security deteriorates due to potential exposure of sensitive identity information

Engineering Contradiction:
Improvespeed of identity verificationVSAvoidexposure of identity information
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by publishing only the specific portions of identity profiles that are necessary for the verification purpose at hand, rather than exposing the entire profile. The publication module selectively releases profile data with appropriate granularity, and credentials can be generated for specific purposes (e.g., age verification only), ensuring that sensitive information not needed for the specific validation remains protected

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements periodic action through time-limited profile publications. Published profiles have expiration times and are automatically revoked after use or after a specified period, requiring periodic re-publication for ongoing verification needs. This temporal limitation reduces the window of vulnerability for exposed information while maintaining verification capability when needed

Inventive Principle:
Principle #19Periodic action

4Reliability

If comprehensive identity data is stored in digital profiles, then reliability is improved by enabling thorough verification, but device complexity increases due to storage and management requirements

Engineering Contradiction:
Improveaccuracy of identity verificationVSAvoidsystem storage and management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential verification data from complete identity profiles and stores it in published, time-limited formats suitable for validation purposes. The enrolment module captures comprehensive data from physical documents, but the publication module selectively releases only what is necessary for specific verification contexts, reducing storage requirements while maintaining verification accuracy

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10325090B2Digital identity system
Publication Date: 2019.06.18 YOTI HLDG LTD
  • US10325090B2 patent drawing
  • US10325090B2 patent drawing
  • US10325090B2 patent drawing

AI summary

The disclosure relates to a digital identity system including an enrolment module executing on a processor configured to receive a data item from an enrolling device and to create in persistent electronic storage a digital profile comprising the data item. The system also includes a credential creation module executing on a processor configured to generate a credential from a random sequence, to associate the credential with the digital profile in a database, and to transmit the credential to the enrolling device. The system further includes a publication module executing on a processor configured, in response to later presentation of the credential to the digital identity system, to publish the digital profile by storing a version of the digital profile in a memory location accessible to a device presenting the credential.