Distributed-Ledger Credential Verification Through Service Providers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional credential verification and issuance systems are costly, inefficient, and insecure, relying on centralized databases that are expensive to maintain, vulnerable to privacy concerns, and susceptible to fraud and man-in-the-middle attacks, especially with digital credentials like QR codes.

Innovation Solution

A distributed system infrastructure using credential service providers, such as telecom carriers, employs a decentralized ledger to verify and issue digital credentials through sharing tokens and service endpoints, ensuring secure and real-time verification without relying on centralized servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized credential verification systems are used, then verification can be performed, but the system becomes expensive to build and maintain, and vulnerable to privacy concerns and single point of failure

Engineering Contradiction:
Improveverification reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized verification system into multiple distributed credential service providers, each operating independently. This segmentation eliminates the single point of failure while reducing the complexity of any individual system component, as each provider only manages credentials for specific clients rather than all clients globally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a distributed ledger as an intermediary layer between credential service providers and verifiers. This intermediary enables verification without requiring direct contact between verifiers and centralized databases, reducing system complexity while maintaining verification reliability through the shared distributed ledger.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized databases are used for credential storage, then verification infrastructure can be established, but privacy data protection concerns arise and the database is not available to the general public

Engineering Contradiction:
Improveverification capabilityVSAvoidprivacy data protection risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments centralized database access into distributed providers, each maintaining localized credential storage. This segmentation limits the exposure of sensitive data to any single point, reducing privacy risks while maintaining verification capability through the distributed network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses copies of credential information stored across multiple distributed providers and the distributed ledger, rather than a single centralized database. This copying approach ensures data redundancy and availability while distributing privacy risks across multiple entities.

Inventive Principle:
Principle #26Copying

3Productivity

If QR codes are used for credential verification, then digital credentials can be issued, but the system becomes insecure and susceptible to man-in-the-middle attacks

Engineering Contradiction:
Improveverification efficiencyVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces the distributed ledger as an intermediary that verifies credential authenticity before QR code presentation. This intermediary layer prevents man-in-the-middle attacks by ensuring the QR code corresponds to a valid credential recorded on the distributed ledger, maintaining verification efficiency while enhancing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the distributed ledger continuously updates and verifies credential status. This feedback loop allows the system to detect and prevent fraudulent QR codes by comparing them against the latest credential records on the distributed ledger, maintaining efficiency while improving security.

Inventive Principle:
Principle #23Feedback

4Reliability

If direct contact with centralized servers is required for verification, then verification can be performed, but the system becomes inefficient and stops when the centralized site is down

Engineering Contradiction:
Improveverification functionVSAvoidverification speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the verification function across multiple distributed providers that can operate independently. This segmentation eliminates dependency on a single centralized server, maintaining verification function and productivity even when one provider is down, as other providers can continue serving their clients.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent ensures continuity of verification service through the distributed architecture, where multiple providers can continue operating independently. The distributed ledger maintains continuous availability of credential information, eliminating interruptions caused by centralized server downtime and maintaining constant verification productivity.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP3932002B1Credential verification and issuance through credential service providers
Publication Date: 2025.10.15 TBCASOFT INC
  • EP3932002B1 patent drawingFigure 1
  • EP3932002B1 patent drawingFigure 2
  • EP3932002B1 patent drawingFigure 3

AI summary

Methods, systems, apparatuses, and computer readable mediums storing processor-executable process steps for verifying a requested credential of a credential owner and/or issuing a new credential through one or more credential service providers. A method for verifying and issuing credential, includes providing, by a first credential management system of a first credential service provider, a sharing credential token and a service endpoint to a requesting device of the credential owner, upon a request; receiving, by a second credential management system of a second credential service provider, from a verifying device of a verifier through the requesting device, the sharing credential token and the service endpoint; sending, by the second credential management system, a proof request to the first credential management system based on the service endpoint; generating, by the first credential management system, a proof based on the proof request; and verifying, by the second credential management system, the proof based on credential cryptography information retrieved from a distributed ledger.