Distributed Ledger Identity Wallet for Secure Access Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems rely on intermediary information sources, such as human resources databases, which increase computational resources and complexity, and are vulnerable to data privacy issues like identity theft due to the handling of sensitive personally identifiable information (PII) and Machine Identifiable Information (MII).

Innovation Solution

An access validation system utilizing a distributed ledger to generate record data structures for user medical statuses, enabling secure credential generation and verification without disclosing actual PII, through an Identity Wallet and service broker, reducing intermediaries and enhancing security and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intermediary information sources like human resources databases are used for access control, then access validation can be performed, but computational resources and system complexity increase

Engineering Contradiction:
Improveaccess validationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the credential verification function from centralized intermediary databases and places it directly on the user's device through a distributed ledger. The user's device stores and presents credentials locally, eliminating the need for complex intermediary validation systems while maintaining access control reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the access control functionality by separating credential storage (on user device) from credential verification (on access control system). This segmentation removes the need for complex intermediary databases, reducing system complexity while preserving validation capability.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If sensitive personally identifiable information is handled in access control systems, then user identification can be verified, but data privacy security is compromised due to vulnerability to identity theft

Engineering Contradiction:
Improveuser identificationVSAvoiddata privacy vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent uses cryptographic copies (hashes) of personally identifiable information stored on the distributed ledger instead of the actual PII. The access control system verifies credentials by comparing cryptographic hashes, enabling precise user identification without exposing sensitive data, thus preventing identity theft while maintaining verification accuracy.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The distributed ledger acts as an intermediary that stores cryptographic representations of PII rather than the actual sensitive information. This intermediary layer enables user identification verification while protecting against data privacy vulnerabilities by never exposing the actual PII to the access control system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If intermediary information sources are used for credential validation, then access control can be performed, but computational resources are increased

Engineering Contradiction:
Improvecredential validationVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the computationally intensive credential storage and verification functions from centralized intermediary systems and places them on the user's device and distributed ledger. The access control system only performs lightweight verification by comparing cryptographic hashes, dramatically reducing computational resource consumption while maintaining validation reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments computational work by performing heavy cryptographic operations locally on the user's device and storing verified credentials on the distributed ledger. The access control system performs only lightweight verification operations, reducing energy consumption while preserving credential validation capability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12093403B2Systems and methods of access validation using distributed ledger identity management
Publication Date: 2024.09.17 TYCO FIRE & SECURITY GMBH
  • US12093403B2 patent drawing
  • US12093403B2 patent drawing
  • US12093403B2 patent drawing

AI summary

An access validation device includes a user interface and one or more processors. The user interface includes at least one of a display and an audio output device. The one or more processors cause an identity wallet to generate a credential regarding a medical status of a user using credential data representative of the status received from a distributed ledger. The one or more processors cause the identity wallet to present an indication of the status using the user interface.