NFC Identity Claims Verification via HCE and Digital Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital identity verification systems face challenges in efficiently and securely sharing and verifying identity claims across various systems and organizations, particularly due to centralized storage vulnerabilities, limited interoperability, and reliance on identity issuing organizations, which can lead to performance bottlenecks and data security issues.
Innovation Solution
The iDentityChain platform utilizes Near Field Communication (NFC) peer-to-peer protocol and Host Card Emulation (HCE) to enable secure, offline sharing and verification of identity claims on portable devices, interfacing with a backend system that can be either blockchain or non-blockchain based, using digital signatures for authenticity and allowing fine-grained control over data sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized storage is used for identity claims, then identity verification can be performed, but vulnerability to data breaches and loss of user control occur
Solution Approach 1:
The patent extracts identity claims from centralized storage and places them directly on users' mobile devices. Each user's identity claims are stored locally in their smartphone or tablet, eliminating the need for a centralized database. This extraction removes the vulnerability of centralized storage while maintaining verification capability through peer-to-peer communication.
Solution Approach 2:
Instead of maintaining a single centralized copy of identity claims, the system creates multiple copies distributed across users' devices. Each user holds their own identity claims locally, and verifiers receive copies of claims from claimants directly. This distribution eliminates single point of failure while maintaining data availability.
2Adaptability or versatility
If identity claims are shared among multiple participants, then verification can be performed, but fine-grained control over data sharing becomes difficult
Solution Approach 1:
The patent segments identity claims into discrete, individually controllable units. Each claim can be selectively shared with specific verifiers based on user-defined criteria. The system divides the verification process into separate modules that can operate independently, allowing fine-grained control over which claims are shared and with whom.
Solution Approach 2:
The system enables dynamic control over data sharing by allowing users to modify their sharing preferences in real-time. Users can dynamically add or remove verifiers from their sharing list, adjust the scope of shared claims, and update their privacy settings without affecting other users. This dynamic adaptability maintains interoperability while providing operational control.
3Productivity
If real-time communication with backend system is required, then identity verification can be performed online, but offline verification capability is lost
Solution Approach 1:
The system performs preliminary actions by pre-loading identity claims and verification algorithms onto users' mobile devices before verification is needed. Users can store their identity claims and verifier contact information locally in advance, enabling them to perform verification operations offline without real-time backend communication. This preliminary preparation maintains both online and offline verification capabilities.
4Measurement precision
If complex verification algorithms are implemented, then verification accuracy can be improved, but device computational resources are consumed
Solution Approach 1:
The patent employs lightweight, efficient cryptographic algorithms that are computationally inexpensive but sufficiently secure for identity verification. Instead of using complex, resource-intensive algorithms, the system utilizes optimized cryptographic primitives that can execute efficiently on mobile devices. This approach maintains verification accuracy while minimizing computational resource consumption and energy usage.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This solution provides a secure, flexible, and efficient method for identity claim management, enabling secure offline verification and reducing reliance on centralized authorities, while ensuring the authenticity of shared identity claims through digital signatures, thus enhancing user control and data protection.
Implementation Method 1
using Near Field Communication (NFC) peer-to-peer protocol and Host Card Emulation (HCE) protocol
Data Source
AI summary
Provided is a method and/or system that facilitates offline sharing and verifying digital identity claims among NFC enabled portable smart devices that are enabled by enabling applications. The enabled portable smart-devices store, verify and share identity, peer to peer and offline. Each identity claim is digitally signed by an identity issuing authority, and the claim can be verified to reliably detect tampering of the claim and thus brings trust in the process of claim sharing and verifying the identity/credentials embodied in the claim. Either Blockchain or non-blockchain, as the backend system of the method/system, can be used, via an inter-operable middleware layer, for onboarding claim holders, claim verifiers, and claim issuers, and for creating/issuing, for managing digital identity claims. NFC, as the communication protocol, facilitates secure data sharing among the NFC-enabled devices.


