Federated Identity Verification via Segmented Digital Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in verifying identities in fully electronic and remote transactions without direct access to bank or payment card issuer systems, while adapting to changing laws and regulations, and ensuring secure, flexible, and privacy-protected identity verification processes.

Innovation Solution

A method for generating user-initiated federated identities involves creating digital asset files and hash files, which are stored on a blockchain, allowing entities to selectively share identity information securely and independently verify identities without relying on bank systems, enabling flexible adaptation to regulatory changes and maintaining privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If bank or payment card issuer systems are accessed directly for identity verification, then identity verification reliability is improved, but system complexity and access restrictions increase

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces federated identities as an intermediary layer between the bank/payment card issuer systems and the entities needing verification. Instead of direct access to bank systems, entities obtain verified identity data through federated identity files that contain authentication information from multiple sources including bank verifications. This mediator approach maintains verification reliability while eliminating the need for direct system access and complex integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all identity data is shared for verification, then verification completeness is improved, but data privacy and security risks increase

Engineering Contradiction:
Improveverification completenessVSAvoiddata privacy risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments identity data into specific verification categories (authentication data, compliance data, credit data) within federated identity files. Entities receive only the specific segments needed for their verification purposes rather than complete identity datasets. This segmentation enables complete verification for each specific need while minimizing unnecessary data exposure and reducing privacy risks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different federated identity files or sections within files provide different levels and types of verification data tailored to specific entities and purposes. The data structure allows customized verification completeness for each local context (different entities, different transaction types) while maintaining consistent privacy protection standards across all data sharing operations.

Inventive Principle:
Principle #3Local quality

3Manufacturing precision

If identity verification systems are adapted to regulatory changes, then compliance accuracy is improved, but system adaptability time increases

Engineering Contradiction:
Improvecompliance accuracyVSAvoidsystem adaptability time
Core Design Contradiction:
Manufacturing precisionVSAdaptability or versatility

Solution Approach 1:

The federated identity system employs dynamic data structures and verification protocols that can be updated independently for different entities and verification types. When regulations change, the system can dynamically adjust the content, format, or requirements of specific federated identity files without reconfiguring the entire verification infrastructure, enabling rapid adaptation while maintaining compliance accuracy.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal federated identity framework that handles multiple verification types (authentication, compliance, credit) and accommodates various regulatory requirements through a single adaptable system. This multi-functional design allows the system to respond to different regulatory changes across various jurisdictions and transaction types using the same underlying infrastructure, reducing adaptation time.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If remote electronic transactions are enabled, then transaction convenience is improved, but identity verification security decreases

Engineering Contradiction:
Improvetransaction convenienceVSAvoididentity verification security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary identity verification and authentication before the actual transaction takes place. Federated identity files are created and validated in advance through multi-source verification processes, so that when remote transactions occur, the identity security work has already been completed. This preliminary action enables convenient remote transactions while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11810081B2Method and system for the generation of user-initiated federated identities
Publication Date: 2023.11.07 CORNER BANCA SA
  • US11810081B2 patent drawing
  • US11810081B2 patent drawing

AI summary

A method for generating user-initiated federated identities, said method being characterized in that it comprises:providing a plurality of electronic data sets (104) stored in one or more files (103) of an electronic memory (102) of a first entity (100) being an identity certification subject, each electronic data set (104) including identity information univocally pertaining to a respective second entity or subject (201);accessing one electronic data set (104)selecting (1001) a sub-set of identity information from the accessed electronic data set (104);generating (1002) a digital asset file (302) containing the sub-set of identity information, wherein said step of selecting (1001) is performed either by the first or the second entity, said step of generation (1002) is performed after the step of selection (1001) and is performed by said first entity (100);a subsequent step of automatic generation (1003) of an hash file (301) of said digital asset file (302), said step of generation of said hash file (301) being performed by an electronic computer (101) associated to the first entity (100) and accessing to said memory (102);the method further comprises a step of automatic generation of a transaction (1004) with a third entity or subject (202) comprising the generation of an electronic message containing the hash file (301) and the digital asset file (302) or the digital asset file (302) and an evidence of the hash file (301), wherein the electronic message is at least temporarily stored on said memory (102).