Personal Security Kernel Node Identity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity authentication methods rely on centralized authority management, leading to vulnerabilities such as easy data leakage and excessive collection of user identity information, which compromises user identity asset security.

Innovation Solution

An identity authentication method where a personal security kernel node determines and transmits only the necessary user identity credentials to a user identity credential certifier node, based on the identity authentication assurance level required by the service, thereby minimizing excessive information sharing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized authority manages identity information, then identity authentication can be performed, but information is easily obtained or sold maliciously and excessive identity information is collected

Engineering Contradiction:
Improveidentity authentication securityVSAvoiddata leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized identity management system into distributed identity authentication nodes. Each node independently performs authentication without accessing complete identity information, thereby distributing security responsibilities and reducing the risk of centralized data leakage. The identity verification process is divided into multiple nodes that each handle specific authentication tasks without possessing full identity datasets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and removes excessive identity information from the authentication process. Only the minimum necessary identity credentials required for verification are transmitted and processed, while complete identity information remains stored securely in user devices. This extraction principle ensures that authentication nodes receive only essential verification data, minimizing exposure to data leakage risks.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If complete identity information is collected for authentication, then verification accuracy is improved, but information security risks increase

Engineering Contradiction:
Improveidentity verification accuracyVSAvoididentity information exposure
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies local quality by enabling each identity authentication node to perform verification with locally processed credential information. Each node receives only the specific credential type needed for its authentication function, rather than complete identity information. This localized information processing maintains verification accuracy for each node's specific purpose while minimizing overall information exposure across the system.

Inventive Principle:
Principle #3Local quality

3Productivity

If centralized storage of identity information is used, then authentication efficiency is improved, but security vulnerabilities increase

Engineering Contradiction:
Improveauthentication efficiencyVSAvoiddata protection capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces intermediary identity authentication nodes that mediate between user devices and service providers. These intermediary nodes verify credentials without accessing or storing complete identity information, acting as secure intermediaries that maintain authentication efficiency while protecting user identity data. The intermediaries process verification requests and return authentication results without exposing sensitive identity information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250080531A1Identity authentication method, personal security kernel node, device, and medium
Publication Date: 2025.03.06 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US20250080531A1 patent drawing
  • US20250080531A1 patent drawing
  • US20250080531A1 patent drawing

AI summary

The present disclosure provides an identity authentication method, a personal security kernel node, a device, and a medium. The personal security kernel node is part of an identity authentication system, the identity authentication system further comprising a relying party node and a user identity credential certifier node. The method includes: obtaining an identity authentication assurance level corresponding to a service provided by a relying party; determining, according to the identity authentication assurance level, a user identity credential used by a user for the service; transmitting the user identity credential to a user identity credential certifier node through a relying party node, so that the user identity credential certifier node performs user identity credential authentication; and performing the service with the relying party node. According to the embodiments of the present disclosure, security of user identity assets can be improved during identity authentication.