Nonlinkable Digital Credentials with Request-Specific Security Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital credentials can be linked across different requestors, compromising user privacy and allowing unauthorized sharing of personal information.

Innovation Solution

Generating multiple instances of digital credentials with unique mobile security objects (MSOs) for each request, ensuring that different instances are used for different requestors to prevent linkability and maintain privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single digital credential is used across multiple requestors, then operational simplicity is improved, but user privacy is compromised due to linkability

Engineering Contradiction:
Improveoperational simplicityVSAvoiduser privacy
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The digital credential system is segmented into multiple independent instances, each with its own unique mobile security object (MSO). Instead of using a single credential across all requestors, the system divides the credential into separate instances that can be independently presented to different requestors, thereby preventing linkability while maintaining ease of use.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each instance of the digital credential is assigned local quality through a unique mobile security object (MSO) that is specific to that instance and the particular requestor. This local differentiation ensures that while each credential instance serves its specific purpose, the overall system maintains privacy by preventing cross-instance linking.

Inventive Principle:
Principle #3Local quality

2Loss of information

If multiple instances of digital credentials are generated with unique mobile security objects, then user privacy is protected by preventing linkability, but device complexity increases

Engineering Contradiction:
Improveuser privacyVSAvoiddevice complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system implements self-service through automated instance selection and management. The digital credential system automatically determines which credential instance to use based on the requestor, eliminating the need for manual user intervention. This automation manages the complexity of multiple credential instances while maintaining user privacy protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The digital credential system achieves multi-functionality by using a single credential template that can generate multiple instances, each serving different requestors. This universal approach allows the system to handle various requestors with a unified credential structure, reducing overall device complexity while maintaining privacy through instance differentiation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If the same digital credential instance is reused across requests, then productivity is improved, but security is compromised due to unauthorized information sharing

Engineering Contradiction:
Improvecredential reuse efficiencyVSAvoidunauthorized information sharing
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The credential system segments the credential into multiple independent instances, each with unique mobile security objects. This segmentation allows efficient credential presentation to different requestors while preventing unauthorized information sharing, as each instance is isolated and cannot be used to derive information about other instances.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the mobile security object parameter for each credential instance, creating cryptographic differentiation. This parameter change enables the system to maintain productivity through efficient credential presentation while ensuring security by making each instance cryptographically unique and non-linkable to others.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12373534B2Techniques for generating and using nonlinkable digital credentials
Publication Date: 2025.07.29 APPLE INC
  • US12373534B2 patent drawing
  • US12373534B2 patent drawing
  • US12373534B2 patent drawing

AI summary

A computing device can generate a set of transaction keys, the computing device configured to present a digital credential to a requesting device. The computing device can generate a request bundle. The request bundle can include the set of transaction keys. The computing device can transmit, to a first server, the request bundle. The first server can be configured to verify the request bundle. The first server can be configured to send the request bundle to a second server with a request for a set of credentials. Each credential of the set of credentials can correspond to a transaction key of the set of transaction keys. Each credential can include data elements and a security object. The data elements for each credential can be the same. The security object for each credential can be different. The computing device can receive, from the first server, the set of credentials. The computing device can store the set of credentials. The computing device can be configured to generate a response based on a particular credential of the set of credentials when a requesting device requests the digital credential.