Hybrid Identity Service for Decentralized Browser Wallets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security of browser-based crypto-wallets is degraded due to the infrequent change of passcodes, leading to potential vulnerabilities in transaction authorization.

Innovation Solution

A hybrid identity service system that autonomously manages passcodes by generating and encrypting unique passcodes for each transaction, using a security provider plugin to enhance transaction security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the passcode is changed frequently, then the security of the crypto-wallet is improved, but the user convenience and ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically generates and rotates passcodes without requiring user intervention. The passcode rotation is managed by the system itself, which creates new passcodes periodically and updates the encrypted private keys accordingly, eliminating the need for users to manually change passcodes while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-generates passcodes and encrypts private keys before transactions occur. By establishing passcodes in advance and automatically rotating them, the system prepares security measures before potential threats arise, allowing frequent security updates without user action.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the passcode is changed infrequently, then the ease of operation is improved, but the security of the crypto-wallet deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The passcode rotation operates continuously in the background without interrupting user operations. The system maintains ongoing passcode generation and private key encryption processes, ensuring that security is continuously updated while users experience no disruption to their normal wallet operations.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system autonomously manages the passcode lifecycle, including generation, rotation, and associated private key encryption. This self-managed approach ensures frequent security updates occur automatically without burdening users with manual tasks, thus maintaining both convenience and security.

Inventive Principle:
Principle #25Self-service

3Reliability

If user initiated passcode change requests are processed, then the security can be updated, but the time required and complexity of operation increases

Engineering Contradiction:
Improvesecurity updateVSAvoidtime required
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs passcode generation and private key encryption in advance before transactions are needed. By pre-establishing security measures and automatically rotating passcodes, the system eliminates the need for users to initiate time-consuming passcode change processes when security updates are needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically handles passcode rotation and security updates without waiting for user requests. This autonomous operation reduces the time required for security updates from the perspective of the user, as the system performs these tasks proactively in the background.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12217252B2Hybrid identity as a service for decentralized browser based wallets
Publication Date: 2025.02.04 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US12217252B2 patent drawing
  • US12217252B2 patent drawing
  • US12217252B2 patent drawing

AI summary

Disclosed are various embodiments for a service for decentralized browser based wallets. Various embodiments of the present disclosure can receive a first passcode and a second passcode from a security provider device. Various embodiments can use a cryptowallet to decrypt a first encrypted private key using the first passcode to generate a decrypted private key. Various embodiments can use a cryptowallet to sign a transaction request with the decrypted private key. Various embodiments can use a cryptowallet to generate a second encrypted private key by encrypting the decrypted private key using the second passcode.