Identity Escrow System for Selective Disclosure and Access Notification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Individuals face challenges in selectively disclosing identity information for verification purposes without revealing unnecessary personal details, especially when accountability is required without accessing full identity information.
Innovation Solution
An identity escrow system that uses a hardware processor to generate a public-private key pair, distributing the private key to escrow providers and the public key to an auditable ledger, allowing users to selectively disclose information through a user interface, and notify the holder of access by a verifier.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a user presents full identity information (e.g., driver's license) for verification, then verification reliability is improved, but information privacy is worsened as unnecessary personal details are revealed
Solution Approach 1:
The identity information is segmented into multiple components (e.g., name, address, date of birth, photo) that can be selectively disclosed. The system allows users to present only the specific attributes needed for verification (such as age proof) without revealing the complete identity profile, thus resolving the contradiction between verification reliability and information privacy.
Solution Approach 2:
The patent extracts only the necessary verification attributes from the full identity information and separates them from unnecessary personal details. By taking out only the required information (e.g., extracting age verification capability while leaving address and other sensitive data undisclosed), the system enables reliable verification without compromising privacy.
2Ease of operation
If a user stores identity information on their personal device, then ease of access is improved, but accountability is worsened as there is no mechanism to track or notify users about access to their information
Solution Approach 1:
The system implements a feedback mechanism where escrow providers are notified when verifiers access identity information held in escrow. This notification feedback loop ensures users are informed about who accesses their information and when, maintaining accountability while preserving ease of access through the escrow service.
Solution Approach 2:
The escrow service acts as an intermediary between the user and the verifier. Instead of users directly storing and managing their own identity information, the escrow provider holds the information securely and mediates access requests from verifiers, thereby maintaining ease of access while introducing accountability through controlled and monitored access.
3Loss of information
If a user discloses minimal information (e.g., only age without birthdate), then information privacy is improved, but verification capability is worsened as verifiers cannot fully verify identity claims
Solution Approach 1:
The system dynamically adjusts the level of information disclosure based on the specific verification requirements. Rather than a static disclosure policy, the system allows flexible, context-dependent disclosure where users can reveal different levels of detail (minimal information for low-risk verifications, more comprehensive information for high-risk verifications), thus balancing privacy with verification capability.
Solution Approach 2:
The patent changes the parameter of information disclosure from fixed to variable. Users can modify the disclosure parameters (e.g., disclosing only age instead of full birthdate, or providing additional attributes when needed) based on the verification context, enabling the system to adapt between privacy preservation and verification capability requirements.
Data Source
AI summary
Identity systems, methods, and media for auditing and notifying users concerning verifiable claims are provided. In some embodiments, the method comprises: prior to engaging with a verifier needing information held in escrow on behalf of a holder, receiving a request to store the information associated with the holder in escrow; causing a user interface to be presented, wherein the user interface allows the holder to select an escrow provider from a plurality of escrow providers for storing the information associated with the holder in escrow; transmitting the information to the selected escrow provider, wherein a public-private key pair for signing with the information associated with the holder is generated, wherein the public-private key pair includes a public key and a private key, wherein the private key and the information associated with the holder is distributed to the plurality of escrow providers, and wherein the public key is transmitted to an auditable ledger system; receiving from each of the plurality of escrow providers, an escrow identifier corresponding to a location where the information is stored in escrow to obtain a set of escrow identifiers; and transmitting the set of escrow identifiers to a verifier device for verifying a claim.


