ID Wallet and HSM Architecture for Copy-Protected Digital Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems lack effective copy protection for self-sovereign identities (SSI) and hardware security modules (HSMs), leading to insecure storage and transmission of digital credentials, which can be compromised or forged, and hinder interoperability and trust verification.

Innovation Solution

A system utilizing operationally non-manipulable hardware security modules (HSMs) integrated with ID wallets, enabling secure storage and management of self-sovereign identities (SSI) through asymmetric encryption, preventing private key transfers, and allowing secure communication between actors using ID-wallet-to-ID-wallet interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If digital credentials are stored in software memory, then accessibility and ease of operation are improved, but security and copy protection are worsened

Engineering Contradiction:
Improveaccessibility of digital credentialsVSAvoidsecurity and copy protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the digital identity system into two segments: software-based ID wallets for ease of operation and hardware-based HSMs for security. The HSM contains a secure element that stores private keys and cryptographic materials, while the ID wallet software provides the user interface and credential management functions. This segmentation allows the system to simultaneously achieve both accessibility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware security module acts as an intermediary between the user and the digital credentials. Instead of directly accessing credentials in software memory, the system uses the HSM as a mediator that provides secure storage and cryptographic operations. The HSM interfaces with the ID wallet software through defined protocols, enabling secure credential management without exposing private keys to the software environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If self-sovereign identities are implemented without additional authority, then autonomy and adaptability are improved, but trust verification and interoperability are worsened

Engineering Contradiction:
Improveautonomy of digital identityVSAvoidtrust verification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The hardware security module is designed with universal functionality to support multiple verification methods and communication protocols. It can perform asymmetric cryptography for self-sovereign identity verification, symmetric cryptography for secure communication, and store various types of credentials. This multi-functionality enables the HSM to work across different digital identity ecosystems while maintaining autonomy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the parameter of trust verification from relying on centralized authorities to relying on cryptographic parameters stored in the HSM. The HSM contains pre-configured cryptographic materials and protocols that enable verification of digital credentials without requiring additional external authorities. This parameter change allows self-sovereign identities to maintain both autonomy and verifiability.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If cryptographic keys are stored in software memory, then ease of operation is improved, but security against copying and unauthorized access is worsened

Engineering Contradiction:
Improvemanageability of cryptographic keysVSAvoidvulnerability to copying and unauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system extracts the cryptographic key storage function from the software environment and places it in a dedicated hardware security module. The HSM contains a secure element that physically isolates private keys from the software memory and processing environment. This extraction removes the vulnerability of software-based key storage while maintaining the ability to manage keys through software interfaces.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The HSM provides a flexible interface layer between the software ID wallet and the secure hardware storage. This interface allows software to request cryptographic operations and manage keys as if they were accessible in memory, while the hardware layer provides physical protection against copying and unauthorized access. The interface acts as a thin film that enables software compatibility while maintaining hardware security.

Inventive Principle:
Principle #30Flexible shells and thin films

Data Source

PatentUS20260067090A1System, method, and computer program product for secure communication between two actors
Publication Date: 2026.03.05 KAPRION TECHNOLOGIES GMBH
  • US20260067090A1 patent drawing
  • US20260067090A1 patent drawing
  • US20260067090A1 patent drawing

AI summary

The invention relates to a system comprising at least one ID wallet (software for managing digital identities and verifiable digital credentials) and at least one hardware security module (HSM) for the secure, authenticated exchange of digital credentials between two actors of a common digital identity ecosystem, as well as to a method and to a computer program product for secure, authenticated communication between two such systems for issuing, transmitting and receiving digital credentials and providing and verifying proof of ownership thereof.