Private-Key Keystores on Provisioned Devices for Credential Revocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing centralized identity and access management systems are inefficient and vulnerable to breaches, especially when mobile devices are used, as they often require insecure sharing mechanisms and expose private keys to cloud storage, leading to potential impersonation and data breaches.
Innovation Solution
A decentralized system that uses self-sovereign credentials stored locally on devices, enabling secure revocation of user credentials without exposing private keys to the cloud, leveraging private keys on provisioned devices and implementing robust revocation logic to manage access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If private keys are stored in cloud storage for centralized identity management, then credential verification can be performed remotely, but the system becomes vulnerable to breaches and impersonation attacks
Solution Approach 1:
The patent extracts the private key storage function from centralized cloud infrastructure and places it in decentralized hardware keystores on user devices. This extraction eliminates the single point of failure while maintaining remote verification capability through public key cryptography.
Solution Approach 2:
The patent introduces hardware keystores as intermediary devices that securely hold private keys and perform cryptographic operations locally. These keystores act as mediators between users and the decentralized network, enabling secure credential verification without exposing private keys to cloud storage.
2Productivity
If centralized identity management systems are used, then credential issuance and verification can be centralized, but the systems are inefficient and create single points of failure
Solution Approach 1:
The patent segments the centralized identity management function into distributed credential verification nodes across the decentralized network. Each node can independently verify credentials using smart contracts, eliminating the single point of failure while maintaining verification efficiency.
Solution Approach 2:
The patent enables self-service credential verification through automated smart contracts that execute on the decentralized network. The system performs self-verification of credentials without requiring centralized authority, improving both efficiency and resilience.
3Ease of operation
If mobile devices are used for identity management, then user accessibility is improved, but secure credential storage and revocation become more difficult
Solution Approach 1:
The patent introduces hardware keystores as intermediary devices that offload the complex security functions from mobile devices. These keystores handle secure credential storage, biometric authentication, and revocation operations, simplifying the mobile device's role while maintaining security.
Solution Approach 2:
The patent adds a hardware dimension to mobile device identity management by integrating physical security elements (biometric sensors, secure enclaves) with software-based decentralized credentials. This multi-dimensional approach enhances security while maintaining user accessibility.
Data Source
AI summary
The disclosed technology teaches a method for revocation of user credentials for controlling user access to a private permissioned blockchain data structure or decentralized personal ledger, comprising an administrative logic configured to de-configure user private keys from keystores of respective users. The administrative logic further comprises a revocation logic configured to receive a unique identifier linked to a keystore of a particular user in response to the keystore, and the revocation logic is further configured to revoke access of the keystore based on the unique identifier.


