Identity-Bound Passkeys With Selective Disclosure for Private Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity systems face challenges such as identity theft, excessive information disclosure, forgery, and cumbersome online verification processes, particularly with physical IDs transitioning to digital formats like Verifiable Credentials (VCs), which lack long-term usability, unlinkability, bidirectional undeniability, and synchronization across devices.

Innovation Solution

A system comprising a user device, identity issuer server, and verification server, utilizing device-bound passkeys and selective disclosure mechanisms to securely manage and synchronize VCs, enabling seamless and privacy-preserving identity verification and content signing, with features like biometric authentication and public witness networks for trust and transparency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical IDs are used for digital systems, then identity verification is possible, but identity theft and excessive information disclosure occur

Engineering Contradiction:
Improveidentity verificationVSAvoididentity theft and information disclosure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary verification elements from physical IDs by using selective disclosure mechanisms. Verifiable credentials contain full identity information, but only specific attributes are revealed during verification. For example, to prove age, only the birth date attribute is disclosed without revealing name, address, or other personal information, thus preventing excessive information disclosure while maintaining verification reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by making different parts of the identity system have different disclosure properties. Each verifiable credential attribute can be independently controlled for disclosure. The system allows selective revelation of specific credential attributes based on verification needs, ensuring that only the minimum necessary information is exposed at each location in the verification process, thereby preventing identity theft while maintaining reliable verification

Inventive Principle:
Principle #3Local quality

2Reliability

If Verifiable Credentials are used for digital identity, then identity theft is prevented, but long-term usability and synchronization across devices are lacking

Engineering Contradiction:
Improveidentity theft preventionVSAvoidlong-term usability
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent segments the identity verification system into multiple components: verifiable credentials stored in a digital wallet, device-bound passkeys for authentication, and a public witness network for verification. This segmentation allows the identity system to be distributed across multiple devices and storage locations, enabling long-term usability and cross-device synchronization while maintaining security against identity theft through cryptographic proof mechanisms

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a public witness network as an intermediary that stores and verifies passkey-credential bindings. This intermediary enables long-term usability by allowing identity verification to occur across different devices and time periods without requiring the original credential issuer to be involved in each verification, thus solving the long-term usability problem while maintaining the security guarantees that prevent identity theft

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If selective disclosure is implemented, then excessive information disclosure is reduced, but system complexity increases

Engineering Contradiction:
Improveinformation disclosure controlVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent uses copying by creating device-bound passkeys that are cryptographic copies of the verifiable credential's public key. These passkey copies enable selective disclosure functionality without requiring complex real-time cryptographic operations on the original credentials. The passkey copies can be stored and used independently across multiple devices, reducing system complexity while maintaining the ability to control information disclosure through the existing credential structure

Inventive Principle:
Principle #26Copying

4Reliability

If device-bound passkeys are used for authentication, then unlinkability is achieved, but verification process complexity increases

Engineering Contradiction:
ImproveunlinkabilityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a public witness network as an intermediary that pre-stores the mappings between passkeys and verifiable credentials. This intermediary eliminates the need for complex real-time verification of unlinkability properties. When verification occurs, the system simply queries the public witness network, which returns the binding information without requiring complex cryptographic operations, thus achieving unlinkability while keeping the verification process simple

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260081782A1Computing systems and methods for provisioning privacy-preserving identity-bound passkeys and digital signatures
Publication Date: 2026.03.19 LOGIN ID INC
  • US20260081782A1 patent drawing
  • US20260081782A1 patent drawing
  • US20260081782A1 patent drawing

AI summary

Systems and methods are provided that allows users to execute a secure digital action that is authenticated by their digital wallet app (or wallet) on a user device or a wallet server. An identity issuer server issues a batch of verification credentials (VCs) for an identity holder to the wallet. The wallet stores the batch of VCs, respectively binds each VC in the batch of VCs with a given passkey from a plurality of passkeys, generates selective disclosures via a content generator server, and transmits the batch of VCs, as a plurality of VC presentations, to an identity verification server. An identity verification server requests and validates the plurality of VC presentations, and, responsive to validating the plurality of VC presentations, registers the plurality of device-bound passkeys respectively bound to the batch of VCs to generate a plurality of registered passkeys. In a secure digital action, after generating the plurality of registered passkeys, the identity verification server is further configured to authenticate the identity holder using one or more of the registered passkeys.