Private-Key Keystores on Provisioned Devices for Credential Revocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing centralized identity and access management systems are inefficient and vulnerable to breaches, especially when mobile devices are used, as they often require insecure sharing mechanisms and expose private keys to cloud storage, leading to potential impersonation and data breaches.

Innovation Solution

A decentralized system that uses self-sovereign credentials stored locally on devices, enabling secure revocation of user credentials without exposing private keys to the cloud, leveraging private keys on provisioned devices and implementing robust revocation logic to manage access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If private keys are stored in cloud storage for centralized identity management, then credential verification can be performed remotely, but the system becomes vulnerable to breaches and impersonation attacks

Engineering Contradiction:
Improveremote credential verificationVSAvoidsecurity against breaches and impersonation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the private key storage function from centralized cloud infrastructure and places it in decentralized hardware keystores on user devices. This extraction eliminates the single point of failure while maintaining remote verification capability through public key cryptography.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces hardware keystores as intermediary devices that securely hold private keys and perform cryptographic operations locally. These keystores act as mediators between users and the decentralized network, enabling secure credential verification without exposing private keys to cloud storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If centralized identity management systems are used, then credential issuance and verification can be centralized, but the systems are inefficient and create single points of failure

Engineering Contradiction:
Improvecredential management efficiencyVSAvoidresilience to server breaches
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the centralized identity management function into distributed credential verification nodes across the decentralized network. Each node can independently verify credentials using smart contracts, eliminating the single point of failure while maintaining verification efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables self-service credential verification through automated smart contracts that execute on the decentralized network. The system performs self-verification of credentials without requiring centralized authority, improving both efficiency and resilience.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If mobile devices are used for identity management, then user accessibility is improved, but secure credential storage and revocation become more difficult

Engineering Contradiction:
Improveuser accessibilityVSAvoidsecure credential storage and revocation
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces hardware keystores as intermediary devices that offload the complex security functions from mobile devices. These keystores handle secure credential storage, biometric authentication, and revocation operations, simplifying the mobile device's role while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a hardware dimension to mobile device identity management by integrating physical security elements (biometric sensors, secure enclaves) with software-based decentralized credentials. This multi-dimensional approach enhances security while maintaining user accessibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250232025A1Credential revocation leveraging private keys on keystores read by provisioned devices
Publication Date: 2025.07.17 LEDGERDOMAIN INC
  • US20250232025A1 patent drawing
  • US20250232025A1 patent drawing
  • US20250232025A1 patent drawing

AI summary

The disclosed technology teaches a method for revocation of user credentials for controlling user access to a private permissioned blockchain data structure or decentralized personal ledger, comprising an administrative logic configured to de-configure user private keys from keystores of respective users. The administrative logic further comprises a revocation logic configured to receive a unique identifier linked to a keystore of a particular user in response to the keystore, and the revocation logic is further configured to revoke access of the keystore based on the unique identifier.