Organization Certificate Field Structure for Credential Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online identity verification methods, such as second site authentication, are vulnerable to forgery and misrepresentation, as they lack control over the type of information certified and do not ensure the credibility of credentials, leading to potential misuses by unscrupulous individuals.

Innovation Solution

A system and method utilizing organization certificates (OC) and membership certificates (MC) with predetermined field structures to limit the type of information certified, incorporating public key cryptography and expiration dates to ensure credibility and prevent forgery, allowing for local verification within a user's browser without relying on untrusted websites.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If second site authentication is used to verify credentials, then users can access verification information from external sites, but the system becomes vulnerable to forgery and misrepresentation

Engineering Contradiction:
Improvecredential verification accessibilityVSAvoidcredential authenticity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted certificate authority (CA) as an intermediary that issues digital certificates to organizations. These certificates serve as mediators between the credential holder and the verifier, eliminating the need for direct second-site authentication while ensuring trust through cryptographic verification of the CA-signed certificates

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual mechanical process of visiting second sites and visually verifying certificates with automated cryptographic verification. The browser automatically verifies digital signatures using public key infrastructure, substituting human-driven mechanical verification with automated mathematical verification

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If centralized repositories store all authenticated credentials, then verification can be performed through checksum matching, but the system remains vulnerable to fake site creation

Engineering Contradiction:
Improveverification efficiencyVSAvoidcredential trustworthiness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs preliminary verification actions by having the certificate authority authenticate organizations and issue signed certificates before any credential verification occurs. This preliminary authentication creates a trust foundation that prevents fake sites from creating convincing counterfeit credentials, as the cryptographic signature verification occurs locally without requiring centralized repository queries

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If organizations pass certificates to repositories without retention control, then centralized verification is enabled, but organizations lose control over their certification data

Engineering Contradiction:
Improvecentralized verification accessVSAvoidorganization data control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent extracts the verification capability from centralized repositories and places it directly in the user's browser through local cryptographic verification. This extraction allows organizations to retain full control over their certificate data while still enabling easy verification, as the browser can independently verify certificates without requiring organizational participation or centralized storage

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If unlimited information types are included in credentials, then organizational flexibility is increased, but misrepresentation risks increase

Engineering Contradiction:
Improvecredential information flexibilityVSAvoidinformation credibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality control by allowing different organizations to define specific, tailored sets of attribute types relevant to their domain while maintaining overall system-wide cryptographic verification. Each organization can customize which information types appear in their certificates, providing local flexibility without compromising global reliability, as the CA-signed certificate structure ensures authenticity regardless of the specific attributes included

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8789163B2On-line membership verification utilizing an associated organization certificate
Publication Date: 2014.07.22 CAHN ROBERT S
  • US8789163B2 patent drawing
  • US8789163B2 patent drawing
  • US8789163B2 patent drawing

AI summary

A system and method is presented for providing verification of specified credentials to an independent person (a third party, that is, a user of a purported member's website) through the utilization of an “organization certificate” (OC) in combination with a “membership certificate” (MC), with the field structure of the OC limiting the type of information that can be certified by the issuing organization. The set of fields in the OC is defined as associated with a particular type of organization, where any extraneous information will not be permitted to form part of a legitimate membership certificate (hereinafter “MC”). The use of specific field descriptions thus assumes that any field appearing in an MC that does not have a corresponding <field> tag in the OC will cause the MC to be flagged as invalid by the user's browser extension during the verification process.