Relative Identity Establishment via Cryptographic Agent Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern digital communications face challenges in protecting identities from theft, particularly in organizational contexts, as existing security solutions fail to effectively prevent identity misappropriation and fraud, despite advancements in cryptography and biometrics.

Innovation Solution

A system is established using agents bound to computing devices, which create and verify relative identities through unique relationships, ensuring secure and trustworthy communication channels by exchanging information derived from relative identities without disclosing actual identity information, utilizing encryption keys and intermediate keys generated from absolute and partial relative keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identity information is transmitted over the network for authentication, then authentication can be performed, but identity theft and fraud become possible

Engineering Contradiction:
Improveauthentication reliabilityVSAvoididentity theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary authentication capability from identity information without transmitting the actual identity data. Agents exchange cryptographic proofs and signatures that verify identity without revealing the underlying identity information, thus achieving authentication while eliminating identity theft risk

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic intermediaries (signatures, hashes, and verification protocols) between communicating parties. These intermediaries enable authentication by verifying identity claims without requiring direct exposure of identity information, thus mediating between authentication needs and security protection

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If absolute identity labels are used for authentication, then identity verification is straightforward, but the system becomes vulnerable to identity theft

Engineering Contradiction:
Improveauthentication simplicityVSAvoididentity security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments identity verification into multiple cryptographic operations (signature generation, hashing, verification) rather than transmitting a single identity label. This segmentation maintains operational simplicity while enhancing security through layered verification mechanisms

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses cryptographic copies (signatures and hashes) of identity information instead of the actual identity data. These copies can be verified for authenticity without exposing the original identity information, thus maintaining verification simplicity while improving security

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If traditional security safeguards are implemented, then some fraud is reduced, but identity theft remains effective

Engineering Contradiction:
Improvefraud reductionVSAvoididentity protection
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent inverts the traditional approach by not protecting identity information directly but rather by proving identity without exposure. Instead of safeguarding identity data from theft, the system makes identity theft impossible by never transmitting or storing transmittable identity information

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS7949869B2Establishing relative identity
Publication Date: 2011.05.24 UNIKEN
  • US7949869B2 patent drawing
  • US7949869B2 patent drawing
  • US7949869B2 patent drawing

AI summary

There are disclosed a method, computing device, and storage medium for establishing relative identity between a first agent on a first computing device and a second agent on a second computing device. An absolute key and a partial relative key may be generated for the first agent, wherein the absolute key and the partial relative key define a relative identity of the first agent, wherein the relative identity is unique for a relationship between the first agent and the second agent.