Identity Recognition via Signed Information Documents
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for secure sharing and collaboration of resources across networks, such as public key infrastructures, are complex and not user-friendly, making it difficult to recognize and authenticate entities outside traditional security domains.
Innovation Solution
A system and method for identity recognition and exchange using identity information documents signed by the sender, which separates identity authentication from authorization, allowing selective disclosure and storage of identity information for future recognition and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public key infrastructures are used to identify and authenticate entities, then identity recognition capability is improved, but system complexity increases
Solution Approach 1:
The patent extracts the core identity recognition function from the complex public key infrastructure. It uses a simplified approach where entities are identified by their network addresses and cryptographic signatures, removing the need for complex certificate authorities, registration processes, and trust relationship management while maintaining security through digital signatures on identity information documents.
Solution Approach 2:
The patent creates a simplified model of identity recognition that copies only the essential elements needed for authentication. Instead of implementing the full public key infrastructure with certificates and authorities, it uses lightweight identity information documents containing network addresses and cryptographic signatures, which can be verified without complex infrastructure.
2Adaptability or versatility
If traditional security domains with accounts and passwords are used, then authorization control is improved, but ease of operation deteriorates
Solution Approach 1:
The patent segments the traditional security system into two separate functions: identity recognition (authentication) and authorization. Identity recognition is handled through automatic verification of identity information documents using cryptographic signatures, while authorization is managed separately through access control lists and permissions. This segmentation eliminates the need for users to remember passwords while maintaining security through separate authentication and authorization mechanisms.
Solution Approach 2:
The patent replaces the mechanical system of password entry and verification with cryptographic signature verification. Instead of users manually entering and system verifying passwords, the system automatically verifies digital signatures on identity information documents, providing both improved security and user convenience.
3Reliability
If closed security domains are used, then security control is improved, but adaptability to external entities deteriorates
Solution Approach 1:
The patent creates a universal identity recognition mechanism that works across different security domains and networks. The identity information document format and verification process are domain-agnostic, allowing entities from any network or organization to be recognized and authenticated. This universal approach maintains security through cryptographic verification while enabling collaboration between disparate systems without requiring domain membership.
Data Source
AI summary
In accordance with various aspects, the present invention relates to methods and systems for sending an identity information document comprising selecting identity information from a self-identity information store for inclusion in the identity information document. The selected identity information is read from a self-identity information store. The identity information document is generated to include the selected identity information and one or more keys, and signed using a key associated with one of the keys included in the identity information document. The identity information document is then sent to a recipient. Receiving an identity information document comprises receiving a signed identity information document from an originator. A determination is made as to whether identity information in the identity information document is reliable. The identity information is saved in a recognized identity information store if the identity information is determined to be reliable. If the identity information is determined to be unreliable, an identity recognition number retrieved from the sender is compared to an identity recognition number generated by the recipient based on information in the received identity information document. If the identity recognition number is verified, the identity information is saved in the recognized identity information store.


