Digital Identity Establishment Without Continuous Trust Provider Dependency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital authentication systems rely on third-party trust providers, leading to continuous dependency and unnecessary information sharing, and lack confidentiality and data protection.
Innovation Solution
A method and arrangement for establishing a digital identity using a random data generator to produce a crypto seed, combined with cryptographic operations, ensuring secure and decentralized authentication without continuous dependency on third parties, and enabling secure communication with encrypted information exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital authentication relies on third-party trust providers, then authentication can be established, but continuous dependency on trust providers is created and additional costs are incurred
Solution Approach 1:
The patent segments the authentication process into two distinct phases: (1) initial trust establishment where the trust provider issues a digital certificate containing the user's public key and identity information, and (2) decentralized authentication where the user independently presents this certificate to service providers without repeated trust provider involvement. This segmentation eliminates continuous dependency while maintaining reliability.
Solution Approach 2:
The trust provider performs preliminary authentication and issues a comprehensive digital certificate in advance. This certificate contains all necessary information (public key, identity, validity period) that the user will repeatedly present to service providers. By performing the authentication action beforehand, the system eliminates the need for continuous trust provider involvement in subsequent authentication events.
2Reliability
If digital certificates contain comprehensive user information, then authentication is robust, but unnecessary information is shared with service providers
Solution Approach 1:
The digital certificate is designed with local quality by containing different types of information with different sensitivity levels. The certificate includes essential authentication data (public key, identity identifier) that service providers need, while also containing additional user information that may be unnecessary for specific service contexts. The system allows selective disclosure or masking of sensitive fields based on the specific authentication context, ensuring service providers receive only the information quality they require.
3Reliability
If users repeatedly contact trust providers for authentication, then trust can be continuously verified, but additional costs are incurred that users must pay
Solution Approach 1:
The trust provider performs the computationally expensive authentication and certificate issuance action in advance, creating a self-contained digital certificate. This preliminary action transfers the authentication burden from repeated online interactions to a single offline event, eliminating continuous cost accumulation while maintaining trust verification through the cryptographically secure certificate that service providers can validate independently.
Data Source
AI summary
An arrangement has a random data generator for producing a crypto seed, and may use a secure transport mechanism. The arrangement may produce, through a first cryptographic operation, a cryptographic intermediate product that is deterministically dependent on both the crypto seed and a user's secret received through the secure transport mechanism. This cryptographic intermediate product constitutes a digital identity of the party. A second cryptographic operation uses the digital identity of the party to produce a cryptographic output including the crypto seed in encrypted form. The arrangement transmits at least part of the cryptographic output through the secure transport mechanism.


