Rich Credential Selective Disclosure for Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for remote identification in high-security Internet transactions are inadequate as they often rely on non-authoritative sources, compromise privacy, and fail to provide multiple verification factors, especially in security and privacy-sensitive transactions.
Innovation Solution
A rich credential system that includes a secret portion with a private key and a disclosable portion with a typed hash tree containing attributes and verification data, allowing selective disclosure and presentation of verification factors, including biometric data, to a verifying server for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If federated identity protocols are used for remote identification, then large numbers of login transactions can be supported, but the identity provider gains knowledge of transaction parties and timing, impinging on subject privacy
Solution Approach 1:
The credential is segmented into multiple independent verification factors (something the subject has, knows, and is) stored in a structured format. This allows selective presentation of only necessary factors for each transaction, reducing privacy loss while maintaining authentication capability.
Solution Approach 2:
The patent extracts only the necessary verification factors and attribute data needed for authentication from the complete credential set. By taking out and presenting only what is required for the specific transaction, the system maintains productivity while minimizing privacy intrusion.
2Loss of information
If traditional cryptographic credentials like X.509 certificates are used, then the issuer is not involved in credential presentation, but only one identity verification factor (proof of private key possession) is provided
Solution Approach 1:
The credential structure combines multiple types of verification factors (cryptographic proof, knowledge-based authentication, biometric data) into a single composite credential. This maintains the benefit of issuer non-involvement while significantly enhancing reliability through multiple independent verification mechanisms.
3Reliability
If biometric samples are presented for verification, then multiple verification factors are provided, but the biometric sample must be presented directly to the verifier for presentation attack detection
Solution Approach 1:
The patent merges the biometric verification process with the existing credential presentation flow. The biometric sample is collected and verified as part of the same authentication transaction, combining multiple verification factors without requiring separate complex authentication processes.
4Loss of information
If selective disclosure of attributes is required for privacy-sensitive transactions, then subject privacy is protected, but existing identification methods cannot provide selective presentation of verification factors
Solution Approach 1:
The credential system is designed to be dynamic and adaptable, allowing the subject to selectively disclose different verification factors and attribute subsets based on the specific transaction requirements. The system can adjust which parts of the credential are presented depending on the verifier's needs and the sensitivity of the transaction.
Data Source
AI summary
A method and system are provided for multifactor identification of a subject over a network using a rich credential, with selective disclosure of attributes and selective presentation of verification factors. A credential presentation application negotiates with a verifying server to agree on attributes to be disclosed and verification factors to be presented, and removes unneeded attributes and verification data from the rich credential by pruning subtrees from a typed hash tree without invalidating a signature that covers the root label of the tree. The credential presentation application proves knowledge of a private key, and as agreed upon may prove knowledge of a password and may arrange for biometric presentation applications to present one or more biometric samples to the verifier, which performs presentation attack detection and verifies the samples against verification data in the rich credential.


