Portable Personal Identity Information Binding and Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital identity systems face challenges in securely transferring and verifying identity information across different clients without requiring users to regenerate or reacquire identifying information, making it burdensome for users to maintain their identity across multiple platforms.
Innovation Solution
The solution involves binding identifying information, metadata, and backing data into a container, which is then sent to a receiving client for secure identification, allowing users to maintain their identity without regenerating or reacquiring the information, using InfoCards and associated metadata to facilitate seamless transitions between clients.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If identifying information is stored on a single client, then identification security is improved, but user convenience deteriorates when transitioning between clients
Solution Approach 1:
The identifying information is segmented into multiple components (claims, metadata, backing data) that can be independently managed and selectively transferred between clients. This allows the system to maintain security by keeping the information distributed while enabling convenience by allowing selective porting of specific segments to different clients as needed.
Solution Approach 2:
A porting mechanism acts as an intermediary between clients, enabling the transfer of identifying information without requiring the user to manually recreate it on each client. This intermediary process maintains security by controlling what information is transferred and to whom, while simultaneously improving convenience by automating the transfer process across multiple clients.
2Measurement precision
If identifying information is regenerated on each client, then identification accuracy is improved, but time consumption increases
Solution Approach 1:
The identifying information is prepared and bound together in advance (claims with metadata and backing data) so that when a user needs to transition to a different client, the information is already packaged and ready for immediate transfer. This preliminary preparation eliminates the need for time-consuming regeneration processes while maintaining identification accuracy through the structured binding format.
Solution Approach 2:
Instead of regenerating identifying information on each client, the system creates and transfers accurate copies of the bound identifying information (claims, metadata, backing data) from one client to another. This copying approach maintains identification accuracy by preserving the original structured format while dramatically reducing the time required compared to regeneration processes.
3Adaptability or versatility
If identifying information is transferred between clients, then user flexibility is improved, but security risk increases
Solution Approach 1:
The identifying information is structured as nested components where claims contain metadata, and metadata contains references to backing data. This nested structure allows for controlled transfer at different levels of granularity, enabling user flexibility to transfer only specific portions of information while maintaining security by keeping the complete nested structure intact and protected on the receiving client.
Solution Approach 2:
The system changes the state of identifying information by binding it into a structured format with specific parameters (claims, metadata, backing data relationships) before transfer. This parameter transformation ensures that the information maintains its security properties during transfer while becoming adaptable for use on different clients, as the bound structure can be verified and validated on the receiving end.
Data Source
AI summary
A user interacts with a client containing personal identity information operable to identify the user to a relying party when the relying party is presented with claims comprising a portion of the personal identity information. The personal identity information includes one or more claims, metadata associated with the one or more claims, and backing data associated with the one or more claims. The user may initiate use of another client and seek to be identified by the relying party while interacting with the other client by first porting the personal identity information to the other client. Porting the personal identity information includes binding the personal identity information and sending the bound personal identity information to a receiving client.


