Machine-Readable Quality Attributes for Cryptographic Identities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital identities in electronic transactions lack a means to indicate variations in risk and quality, making it difficult for participants to assess the reliability of identities and assume liability, as they are not machine readable and do not reflect the conditions under which they were issued or used.

Innovation Solution

A method and system that assigns quality attributes to cryptographic identities, making them machine readable, allowing participants to evaluate risk and potentially insure against it by analyzing these attributes along with transaction details, using extensions of existing standards like X.509 and XrML certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic identities are issued with varying security provisions and practices, then the quality and reliability of identities vary, but there is no machine-readable indication of these variations making risk assessment difficult

Engineering Contradiction:
Improveidentity qualityVSAvoidrisk information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the identity information into distinct machine-readable attributes within the certificate structure, separating the quality indicators from the basic identity data. This allows different aspects of identity quality (issuer reliability, security provisions, intended use) to be independently evaluated and assessed by transaction participants.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary evaluation mechanism where certificate attributes serve as mediators between the identity issuer and the transaction participant. These attributes translate the issuer's security practices and identity quality into machine-readable forms that participants can automatically assess without directly accessing or interpreting CPS documents.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If certificate issuers use different practices and procedures, then identity quality varies, but participants cannot easily determine the conditions under which identities were issued

Engineering Contradiction:
Improveissuer practice variationVSAvoididentity issuance conditions
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent changes the parameters of certificate information by encoding issuance conditions as structured machine-readable attributes with specific data types and formats. This allows varying issuer practices to be represented as comparable parameter sets that can be automatically measured and evaluated against transaction requirements.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a universal attribute structure that can accommodate different issuer practices and procedures while maintaining a consistent evaluation framework. The same certificate attribute structure serves multiple functions: recording issuer practices, enabling machine-readable assessment, and supporting risk evaluation across diverse transaction types and participants.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If digital identities are used as gating factors for access, then authentication is enabled, but participants cannot assess the risk introduced by the identity quality

Engineering Contradiction:
Improveauthentication processVSAvoidrisk assessment capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary risk assessment by embedding quality attributes in the certificate itself, allowing participants to evaluate identity quality before completing the authentication process. This enables risk-informed access decisions to be made in advance, rather than relying solely on binary authentication outcomes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8966245B2System and method for assigning quality to cryptographic identities used in a digital transaction
Publication Date: 2015.02.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8966245B2 patent drawing
  • US8966245B2 patent drawing
  • US8966245B2 patent drawing

AI summary

A method of assessing risk in an electronic transaction involves assignment of quality attributes to cryptographic identities presented in a digital transaction. The quality assignment supports assessment of risk in the transaction. The evaluation of risk in the transaction is made by assessing machine readable attributes of the digital identities along with transaction details. The digital identity attributes may be constructed using extensions of existing standards. A guarantee against risk of loss may be obtained by procuring insurance on the transaction before execution. Third party insurers may analyze the risk of loss in a transaction by assessing the attributes of digital identities along with transaction details and may provide a requestor with an insurance premium quote. Based on the value of the quote, the transaction participants may decide whether or not to execute the transaction.