Identity Attribute Validation with Selective Disclosure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity validation methods disclose unnecessary personal information, compromising privacy and security, especially in transactions where only specific attributes are required, such as age verification.
Innovation Solution
A server-based and terminal-based method for controlled disclosure of attribute data, where a computer server receives a credential and an attribute disclosure profile, determining the validity of the credential and providing only authorized attribute data to the communication device, while keeping unauthorized data hidden.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all information stored or shown on a hardware token is disclosed to the recipient, then the recipient can verify identity attributes, but unnecessary personal information is exposed compromising privacy and security
Solution Approach 1:
The patent segments identity information into multiple attributes (e.g., age, name, address, photograph) and enables selective disclosure of only the specific attributes required for verification. The system divides the credential data into individual attribute elements that can be independently controlled and disclosed based on policy rules, rather than disclosing all information at once.
Solution Approach 2:
The patent applies local quality by allowing different disclosure policies for different attributes. Each attribute can have its own disclosure rules and permissions, enabling the system to disclose only the specific local portion of information needed for verification while keeping other portions protected. This allows precise control over what information is revealed in each verification context.
2Ease of operation
If a driver's license is presented to prove age, then age verification is achieved, but other identity attributes such as residence address and height are unnecessarily disclosed
Solution Approach 1:
The patent extracts only the specific attribute information needed for the transaction (e.g., age for liquor purchase) from the complete set of credential data. The system separates the required attribute (age) from unnecessary attributes (address, height, photograph) and discloses only the extracted relevant information, preventing loss of unnecessary personal data.
3Object-affected harmful factors
If an attribute disclosure profile is implemented to control information release, then privacy is enhanced, but the system complexity increases
Solution Approach 1:
The patent implements a universal attribute disclosure profile framework that can be applied across multiple verification scenarios and credential types. The same policy mechanism handles different attributes (age, name, address, photograph) and different verification contexts, providing a multi-functional solution that reduces overall system complexity despite the added privacy controls.
Data Source
Figure 1
Figure 2
Figure 3a
AI summary
A method of identity attribute validation at a computer server involves the computer server receiving an identity attribute validation request from a communication terminal. The computer server further receives a credential, and is configured with an attribute disclosure profile of attributes authorized for disclosure to the communication terminal. The computer server determines the validity of the credential, and provides the communication terminal with a response to the identity attribute validation request based on an outcome of the credential validity determination. The attribute validation response includes attributes data associated with the credential authorized for disclosure by the attribute disclosure profile but excludes attributes data associated with the credential not authorized for disclosure by the attribute disclosure profile.