Private-Key Access Delegation for Decentralized Node Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing centralized identity and access management systems are inefficient and vulnerable to breaches, particularly when mobile devices are shared or used by a diverse workforce, leading to unauthorized access and potential data compromises.
Innovation Solution
Implementing self-sovereign credentials on uniquely identifiable devices, using smart contracts and decentralized networks to manage access delegation without exposing private keys to the cloud, enabling secure, traceable, and revocable access privileges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized identity and access management systems are used, then ease of operation is improved, but security and vulnerability to breaches deteriorate
Solution Approach 1:
The system segments identity management by creating decentralized identity credentials that reside on individual user devices rather than in a centralized database. Each user has their own digital wallet containing verifiable credentials, eliminating the single point of failure in centralized systems while maintaining ease of access through mobile devices.
Solution Approach 2:
The patent introduces blockchain technology as an intermediary layer that enables trustless verification of credentials without requiring centralized authentication. The blockchain network acts as a mediator that validates credential authenticity through cryptographic proofs, eliminating the need for users to trust centralized identity providers while simplifying the authentication process.
2Adaptability or versatility
If mobile devices are shared or used by diverse workforce, then adaptability is improved, but unauthorized access and data compromise increase
Solution Approach 1:
The system implements local quality by storing cryptographic private keys and personal identifiable information (PII) locally on individual user devices rather than centrally. Each device has its own secure enclave where credentials are stored and managed, ensuring that even if devices are shared, each user's identity data remains isolated and protected on their specific device.
Solution Approach 2:
Users take control of their own identity credentials through self-service digital wallets on their mobile devices. The system enables users to autonomously manage, share, and revoke access to their credentials without requiring centralized approval or intervention, allowing flexible device usage while maintaining security through user-controlled credential disclosure.
3Ease of operation
If private keys are stored centrally, then ease of operation is improved, but security vulnerabilities increase
Solution Approach 1:
The patent inverts the traditional centralized credential management model by placing private keys and credentials on user devices rather than servers. Instead of users connecting to a centralized identity provider, the system enables devices to independently verify credentials through blockchain-based cryptographic proofs, eliminating the security vulnerability of centralized key storage while simplifying the architecture by removing the need for secure key distribution infrastructure.
Data Source
AI summary
The disclosed technology teaches a method for delegating user access to one of a set of decentralized networked nodes that share a private permissioned blockchain data structure or a decentralized personal ledger. The method also includes a credentialing logic configured to receive from one of a set of decentralized networked nodes, authority to access a network node to invoke services that conduct operations using a private permissioned blockchain data structure or decentralized personal ledger to which access has been limited to users authorized by one of the set of decentralized networked nodes; and an access delegation logic configured to create a delegation of at least some of the authority to access the network node for a limited duration of time and to send the delegation to a recipient identified to receive delegated authority.


