Portable User Accounts for Self-Sovereign Identity Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional user accounts are owned and maintained by service providers, lacking user control and autonomy, and they rely on centralized security mechanisms that may compromise user privacy.
Innovation Solution
The development of secure self-sovereign identity (SSI) portable user accounts that are owned, operated, and controlled by individual users, utilizing cryptographic security and transparently logged data such as blockchain technology to ensure secure access and management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional user accounts are owned and maintained by service providers, then centralized security management is achieved, but user control and autonomy are lost
Solution Approach 1:
The patent implements self-service through self-sovereign identity where users autonomously manage their own digital identities using cryptographic keys. Users can create, control, and transfer their own accounts without service provider intervention, enabling full user control while maintaining security through cryptographic mechanisms rather than centralized management.
Solution Approach 2:
The patent inverts the traditional account model by transferring ownership from service providers to users. Instead of service providers managing user accounts, users now own and control their accounts through self-sovereign identity, with service providers becoming mere validators of user-controlled credentials.
2Device complexity
If centralized security mechanisms are used, then account management is simplified, but user privacy is compromised
Solution Approach 1:
The patent extracts personal information from centralized service provider databases and places it under user control through decentralized identifiers and cryptographic credentials. Users can selectively disclose only necessary information to service providers without exposing their complete personal data, thereby protecting privacy while maintaining account management functionality.
Solution Approach 2:
The patent introduces cryptographic credentials and verifiable presentations as intermediaries between users and service providers. These credentials enable privacy-preserving authentication where service providers can verify user identities without accessing underlying personal information, thus maintaining simplified account management while protecting user privacy.
3Reliability
If service providers maintain user accounts, then account security is centralized, but user autonomy is reduced
Solution Approach 1:
The patent segments the account management system into user-controlled identity wallets and service provider validation systems. Users maintain their own cryptographic key pairs and control their identity data in decentralized wallets, while service providers only perform cryptographic verification. This segmentation enables both strong security through cryptographic mechanisms and full user autonomy through decentralized control.
4Ease of operation
If portable user accounts are made user-controlled, then user sovereignty is enhanced, but system complexity increases
Solution Approach 1:
The patent uses cryptographic copying where users can generate and transfer copies of their identity credentials to multiple devices without duplicating their master private key. The identity wallet system allows users to create backup copies of their credentials and securely transfer them between devices, maintaining user sovereignty while managing system complexity through standardized cryptographic protocols.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Systems and methods are described that include a plurality of devices triggered to be configured with a portable user account to synchronize account events to a distributed log. Systems and methods are also described for providing decentralized access, for a plurality of devices, to a user account. The plurality of devices includes at least one device configured to trigger a query to determine access rights for the at least one other device. In response to receiving an approval response to the query, the at least one device assigns a provision status to the at least one other device, provides, for the at least one other device, access to at least a subset of the portable user account according to the assigned provision status, and updates the distributed log to include the at least one other device based on the provision status.