Distributed Identity Ledger Using Segmentation and Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management systems (IDMS) face challenges with centralized databases, including single points of failure, complex data management, lack of user privacy and anonymity, and reliance on third-party components, which are not suitable for peer-to-peer transactions and do not provide reliable binding of digital identities to real-world entities.

Innovation Solution

A peer-to-peer identity management system using a global, distributed, append-only public identities ledger, called the Blockchain Information eXchange (BIX) system, where identities are managed without third-party involvement, ensuring privacy, anonymity, and secure binding to real-world entities through cryptographic protection and consent-based distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized database repositories are used for identity management, then identity data can be stored and managed, but the system creates single points of failure and requires complex security protection

Engineering Contradiction:
Improvesystem reliabilityVSAvoidsecurity protection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the centralized identity management system into distributed peer-to-peer nodes. Each node maintains its own copy of the identity ledger, eliminating the single point of failure. The system segments the centralized authority into multiple independent participants who collectively maintain the identity data through cryptographic verification and consensus mechanisms.

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If centralized database repositories are used for identity management, then identity data can be stored, but user privacy and anonymity are compromised

Engineering Contradiction:
Improveidentity data storageVSAvoidprivacy loss
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent extracts personally identifiable information (PII) from the public ledger. Sensitive identity attributes are stored separately in encrypted form, while the public ledger contains only cryptographic hashes and verification data. This allows identity verification to proceed without exposing actual personal information, thereby maintaining privacy while enabling identity management.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If third-party components are involved in identity management, then identity validation can be performed, but the system requires trust in external entities and increases complexity

Engineering Contradiction:
Improveidentity validation reliabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service identity validation where each participant independently verifies identity claims using cryptographic proofs stored in the distributed ledger. No third-party authority is needed to validate identities during transactions, as the decentralized nature of the system allows any participant to verify another's identity through cryptographic verification of ledger entries.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If centralized database repositories are used for identity management, then identity data can be accessed, but the system creates single points of failure

Engineering Contradiction:
Improveidentity data accessVSAvoidsystem availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges multiple independent copies of the identity ledger across distributed peer-to-peer nodes. Instead of relying on a single centralized database, the system combines the storage and verification capabilities of numerous participants, each maintaining an identical copy of the identity data. This redundancy ensures that the system remains operational even if individual nodes fail.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9635000B1Blockchain identity management system based on public identities ledger
Publication Date: 2017.04.25 MUFTIC SEAD
  • US9635000B1 patent drawing
  • US9635000B1 patent drawing
  • US9635000B1 patent drawing

AI summary

The invention describes an identity management system (IDMS) based on the concept of peer-to-peer protocols and the public identities ledger. The system manages digital identities, which are digital objects that contain attributes used for the identification of persons and other entities in an IT system and for making identity claims. The identity objects are encoded and cryptographically encapsulated. Identity management protocols include the creation of identities, the validation of their binding to real-world entities, and their secure and reliable storage, protection, distribution, verification, updates, and use. The identities are included in a specially constructed global, distributed, append-only public identities ledger. They are forward- and backward-linked using the mechanism of digital signatures. The linking of objects and their chaining in the ledger is based on and reflect their mutual validation relationships. The identities of individual members are organized in the form of linked structures called the personal identities chains. Identities of groups of users that validated identities of other users in a group are organized in community identities chains. The ledger and its chains support accurate and reliable validation of identities by other members of the system and by application services providers without the assistance of third parties. The ledger designed in this invention may be either permissioned or unpermissioned. Permissioned ledgers have special entities, called BIX Security Policy Providers, which validate the binding of digital identities to real-world entities based on the rules of a given security policy. In unpermissioned ledgers, community members mutually validate their identities. The identity management system provides security, privacy, and anonymity for digital identities and satisfies the requirements for decentralized, anonymous identities management systems.