Nonlinkable Digital Credentials with Request-Specific Security Objects
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital credentials can be linked across different requestors, compromising user privacy and allowing unauthorized information sharing, as responses to different requests often include the same mobile security object, enabling collusive behavior.
Innovation Solution
Generating multiple instances of digital credentials with unique mobile security objects for each request, ensuring that different requestors receive distinct responses, thereby preventing linkability and unauthorized information sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the same mobile security object is used across different requests, then verification efficiency is improved, but user privacy is compromised and linkability is enabled
Solution Approach 1:
The patent segments the mobile security object into multiple unique instances, where each instance is used for a specific requestor. Instead of reusing a single security object across multiple requests, the system generates distinct security objects for different requestors, thereby preventing linkability while maintaining verification efficiency for each individual request.
Solution Approach 2:
The patent applies local quality by making each mobile security object instance unique to a specific requestor context. Each security object instance has localized properties (unique identifiers, requestor-specific parameters) that differentiate it from other instances, ensuring that verification remains efficient for each requestor while preventing cross-requestor linkability.
2Loss of information
If multiple instances of digital credentials are generated with unique mobile security objects, then user privacy is protected and linkability is prevented, but system complexity increases
Solution Approach 1:
The patent uses copying to generate multiple instances of digital credentials with unique mobile security objects. Instead of creating fundamentally new verification mechanisms, the system creates copies of the credential structure with modified security object parameters, thereby protecting user privacy while maintaining manageable system complexity through standardized credential templates.
Solution Approach 2:
The patent applies parameter changes by modifying specific parameters of the mobile security object (such as unique identifiers, requestor-specific keys) while keeping the overall credential structure consistent. This approach protects user privacy through uniqueness while avoiding excessive system complexity by maintaining a standardized framework with variable parameters.
3Loss of information
If unique mobile security objects are used for each requestor, then information sharing between requestors is prevented, but credential management complexity increases
Solution Approach 1:
The patent extracts the unique identifying elements from the mobile security object and uses them specifically for preventing information sharing between requestors. By separating the unique instance identifiers from the core credential data, the system achieves information sharing control while simplifying management through modular credential structures.
Data Source
AI summary
A computing device can receive a request from a requesting device for one or more data elements associated with a digital credential. The computing device can store the digital credential which includes a set of data elements and a security object. The computing device can determine a subset of the data elements based at least in part on the request. The computing device can generate the response, wherein the response includes the subset of the data elements and the security object. The computing device can transmit the response to the requesting device.


