Private-Key Access Delegation for Decentralized Node Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing centralized identity and access management systems are inefficient and vulnerable to breaches, particularly when mobile devices are shared or used by a diverse workforce, leading to unauthorized access and potential data compromises.

Innovation Solution

Implementing self-sovereign credentials on uniquely identifiable devices, using smart contracts and decentralized networks to manage access delegation without exposing private keys to the cloud, enabling secure, traceable, and revocable access privileges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized identity and access management systems are used, then ease of operation is improved, but security and vulnerability to breaches deteriorate

Engineering Contradiction:
Improveaccess managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments identity management by creating decentralized identity credentials that reside on individual user devices rather than in a centralized database. Each user has their own digital wallet containing verifiable credentials, eliminating the single point of failure in centralized systems while maintaining ease of access through mobile devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces blockchain technology as an intermediary layer that enables trustless verification of credentials without requiring centralized authentication. The blockchain network acts as a mediator that validates credential authenticity through cryptographic proofs, eliminating the need for users to trust centralized identity providers while simplifying the authentication process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If mobile devices are shared or used by diverse workforce, then adaptability is improved, but unauthorized access and data compromise increase

Engineering Contradiction:
Improvedevice usage flexibilityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements local quality by storing cryptographic private keys and personal identifiable information (PII) locally on individual user devices rather than centrally. Each device has its own secure enclave where credentials are stored and managed, ensuring that even if devices are shared, each user's identity data remains isolated and protected on their specific device.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Users take control of their own identity credentials through self-service digital wallets on their mobile devices. The system enables users to autonomously manage, share, and revoke access to their credentials without requiring centralized approval or intervention, allowing flexible device usage while maintaining security through user-controlled credential disclosure.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If private keys are stored centrally, then ease of operation is improved, but security vulnerabilities increase

Engineering Contradiction:
Improvecredential managementVSAvoidsecurity architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent inverts the traditional centralized credential management model by placing private keys and credentials on user devices rather than servers. Instead of users connecting to a centralized identity provider, the system enables devices to independently verify credentials through blockchain-based cryptographic proofs, eliminating the security vulnerability of centralized key storage while simplifying the architecture by removing the need for secure key distribution infrastructure.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS12470415B1Access delegation leveraging private keys on keystores read by provisioned devices
Publication Date: 2025.11.11 LEDGERDOMAIN INC
  • US12470415B1 patent drawing
  • US12470415B1 patent drawing
  • US12470415B1 patent drawing

AI summary

The disclosed technology teaches a method for delegating user access to one of a set of decentralized networked nodes that share a private permissioned blockchain data structure or a decentralized personal ledger. The method also includes a credentialing logic configured to receive from one of a set of decentralized networked nodes, authority to access a network node to invoke services that conduct operations using a private permissioned blockchain data structure or decentralized personal ledger to which access has been limited to users authorized by one of the set of decentralized networked nodes; and an access delegation logic configured to create a delegation of at least some of the authority to access the network node for a limited duration of time and to send the delegation to a recipient identified to receive delegated authority.