Empowerment Certificates for Universal Digital Identity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current public key infrastructure (PKI) systems face challenges in enabling universal verification of digital signatures, as they are limited to managed identities and do not easily allow individuals to sign data anywhere, and the cost and liability issues associated with certificate issuance hinder widespread adoption.
Innovation Solution
A method and system that generate empowerment certificates, allowing individuals to control access to their personal data and enable secure data transfer by using public key cryptography, where empowerment certificates empower relying entities to access personal data and include attributes for identification, sources, and relying entities, facilitating secure data exchange and ownership transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional PKI systems use managed identities with certificate authorities, then digital signature verification can be established, but the system cannot easily enable universal verification and individual signing capabilities
Solution Approach 1:
The patent inverts the traditional PKI model by making the individual hold the certificate rather than the certificate authority. This allows any individual to sign data anywhere without requiring complex managed identity systems, achieving universal verification capability while simplifying the overall system structure.
Solution Approach 2:
The patent extracts the certificate from the centralized authority model and places it with the individual user. This extraction enables individuals to independently manage their own digital identities and sign data without relying on complex PKI infrastructure, thereby achieving versatility without proportionally increasing system complexity.
2Reliability
If certificate authorities issue certificates for managed identities, then authentication can be provided, but cost and liability issues hinder widespread adoption
Solution Approach 1:
The patent enables individuals to self-issue their own certificates without requiring expensive certificate authority services. This self-service approach maintains authentication capability through cryptographic signatures while eliminating the cost and liability barriers that have hindered widespread adoption of PKI systems.
Solution Approach 2:
The patent employs disposable, individually-issued certificates that replace expensive, long-term managed identity certificates. These simple, low-cost certificates provide sufficient authentication capability without the high costs and liability issues associated with traditional CA-issued certificates, thereby facilitating widespread adoption.
3Reliability
If public key infrastructure enables managed identities, then secure data transfer can be achieved, but it does not easily allow individuals to control access to their personal data
Solution Approach 1:
The patent enables individuals to self-manage their personal data by issuing their own certificates that control access to their data. This eliminates the need for complex centralized identity management while maintaining secure data transfer through cryptographic authentication, thereby improving ease of operation for data access control.
Solution Approach 2:
The patent inverts the traditional model where centralized authorities control data access. Instead, individuals hold their own certificates and control who can access their personal data, achieving both secure data transfer and ease of operation through simple individual authorization.
Data Source
AI summary
A method and system for supply of data, including generating a first digital certificate referred (empowerment certificate) signed with a first signing entity's electronic signature. The empowerment certificate includes attributes of the described entity, information identifying the first signing entity, indication of data relating to the described entity, indication of a source of the data, and identification of a relying entity to which the data can be supplied. The relying entity forwards the empowerment certificate to a source supplying the data indicated in the empowerment certificate. The data may be supplied to the relying entity by a second digital certificate (custom certificate), signed with a second signing entity's electronic signature. Custom certificates may appear in custom certificate revocation lists. A system and method for transfer of ownership of electronic property from a first entity to a second entity, and a method and system for electronic voting are also provided.


