Distributed Identity Ledger Using Segmentation and Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity management systems (IDMS) face challenges with centralized databases, including single points of failure, complex data management, lack of user privacy and anonymity, and reliance on third-party components, which are not suitable for peer-to-peer transactions and do not provide reliable binding of digital identities to real-world entities.
Innovation Solution
A peer-to-peer identity management system using a global, distributed, append-only public identities ledger, called the Blockchain Information eXchange (BIX) system, where identities are managed without third-party involvement, ensuring privacy, anonymity, and secure binding to real-world entities through cryptographic protection and consent-based distribution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized database repositories are used for identity management, then identity data can be stored and managed, but the system creates single points of failure and requires complex security protection
Solution Approach 1:
The patent divides the centralized identity management system into distributed peer-to-peer nodes. Each node maintains its own copy of the identity ledger, eliminating the single point of failure. The system segments the centralized authority into multiple independent participants who collectively maintain the identity data through cryptographic verification and consensus mechanisms.
2Quantity of substance
If centralized database repositories are used for identity management, then identity data can be stored, but user privacy and anonymity are compromised
Solution Approach 1:
The patent extracts personally identifiable information (PII) from the public ledger. Sensitive identity attributes are stored separately in encrypted form, while the public ledger contains only cryptographic hashes and verification data. This allows identity verification to proceed without exposing actual personal information, thereby maintaining privacy while enabling identity management.
3Reliability
If third-party components are involved in identity management, then identity validation can be performed, but the system requires trust in external entities and increases complexity
Solution Approach 1:
The patent implements self-service identity validation where each participant independently verifies identity claims using cryptographic proofs stored in the distributed ledger. No third-party authority is needed to validate identities during transactions, as the decentralized nature of the system allows any participant to verify another's identity through cryptographic verification of ledger entries.
4Ease of operation
If centralized database repositories are used for identity management, then identity data can be accessed, but the system creates single points of failure
Solution Approach 1:
The patent merges multiple independent copies of the identity ledger across distributed peer-to-peer nodes. Instead of relying on a single centralized database, the system combines the storage and verification capabilities of numerous participants, each maintaining an identical copy of the identity data. This redundancy ensures that the system remains operational even if individual nodes fail.
Data Source
AI summary
The invention describes an identity management system (IDMS) based on the concept of peer-to-peer protocols and the public identities ledger. The system manages digital identities, which are digital objects that contain attributes used for the identification of persons and other entities in an IT system and for making identity claims. The identity objects are encoded and cryptographically encapsulated. Identity management protocols include the creation of identities, the validation of their binding to real-world entities, and their secure and reliable storage, protection, distribution, verification, updates, and use. The identities are included in a specially constructed global, distributed, append-only public identities ledger. They are forward- and backward-linked using the mechanism of digital signatures. The linking of objects and their chaining in the ledger is based on and reflect their mutual validation relationships. The identities of individual members are organized in the form of linked structures called the personal identities chains. Identities of groups of users that validated identities of other users in a group are organized in community identities chains. The ledger and its chains support accurate and reliable validation of identities by other members of the system and by application services providers without the assistance of third parties. The ledger designed in this invention may be either permissioned or unpermissioned. Permissioned ledgers have special entities, called BIX Security Policy Providers, which validate the binding of digital identities to real-world entities based on the rules of a given security policy. In unpermissioned ledgers, community members mutually validate their identities. The identity management system provides security, privacy, and anonymity for digital identities and satisfies the requirements for decentralized, anonymous identities management systems.


