Decentralized Identity Authentication Node for SSI Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of Self-Sovereign Identity (SSI) into existing centralized Identity and Access Management (IAM) architectures is hindered by the differences between decentralized SSI and centralized IAM systems, leading to complexity and user inconvenience.

Innovation Solution

A method for identity authentication that determines the confidence of an authentication node based on historical behavior, consensus, contribution, and security, allowing encrypted user data to be received, decrypted, and authenticated in a decentralized network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If decentralized SSI is integrated into centralized IAM architectures, then security and privacy protection are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces authentication nodes as intermediaries between users and service providers in the decentralized SSI system. These nodes verify user identities and authenticate encrypted data without having access to private keys or sensitive information, thereby maintaining security while managing system complexity through a trusted intermediary layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the identity authentication system into independent components: users hold encrypted credentials, authentication nodes verify identities, and service providers access authenticated information. This segmentation allows each component to operate independently with clearly defined responsibilities, reducing overall system complexity while maintaining security

Inventive Principle:
Principle #1Segmentation

2Reliability

If decentralized SSI is integrated into centralized IAM architectures, then privacy protection is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where users independently manage their own encrypted credentials and identity information in local storage. Users can autonomously control what information to share and with whom, eliminating the need for centralized privacy management while improving both privacy protection and user convenience

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Authentication nodes serve as mediators that handle the complex verification processes between users and service providers. Users simply present their encrypted credentials to authentication nodes, which automatically verify identities and facilitate authentication, making the privacy-protecting system easy to use without requiring users to understand complex cryptographic operations

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250141676A1Method, electronic device, and computer program product for identity authentication
Publication Date: 2025.05.01 DELL PROD LP
  • US20250141676A1 patent drawing
  • US20250141676A1 patent drawing
  • US20250141676A1 patent drawing

AI summary

In embodiments of the present disclosure, a method for identity authentication is provided, which includes determining a confidence of an authentication node based on historical behavior, consensus, contribution, and security of the authentication node. The method further includes: receiving, by the authentication node, encrypted data of a user in response to the authentication node being a trusted node, where the authentication node is a node in a decentralized network and is connected with the Internet through a communication protocol to receive and authenticate encrypted data from the Internet, and the encrypted data includes personal information associated with user information and a signature issued by a publisher; decrypting the encrypted data; and determining an identity of the user based on authentication of the decrypted data. By using the method implemented in the present disclosure, the complexity of decentralized implementation is reduced, the user experience is improved, and users multiple sign-on options.