Shared Proof of Knowledge for Cross-Service Identity Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for initial user account provisioning lack a balance between convenience and reliability, with email verification being unreliable and physical identification being inconvenient, necessitating a more efficient method to authenticate users across different online services.
Innovation Solution
Implementing a system that allows users to share Proofs of Knowledge (PoK) between Relying Party servers, enabling reuse of PoK credentials for authentication and providing crowdsourced identification through a network of accepting servers, using Password Service and Cognition Service servers to manage and verify these credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If email verification is used for initial provisioning, then convenience is improved, but reliability deteriorates because it does not truly verify identity
Solution Approach 1:
The patent introduces a trusted third-party service provider that issues digital identity credentials (proofs of knowledge) to users. This intermediary validates user identity through cognitive tests and issues verifiable credentials that users can present to multiple relying parties, eliminating the need for each service to perform its own verification while maintaining high reliability through cryptographic proof.
Solution Approach 2:
The patent creates digital copies of verified identity information in the form of proofs of knowledge (cryptographic tokens). Once a user's identity is verified by the trusted service provider, the resulting proof of knowledge can be copied and presented across multiple platforms without requiring repeated verification, thus improving both convenience and reliability simultaneously.
2Reliability
If physical identification systems are used for initial provisioning, then reliability is improved, but convenience deteriorates due to the need to visit designated centers
Solution Approach 1:
The patent replaces physical identification systems (requiring visits to centers with officials) with electronic cryptographic verification systems. The trusted service provider uses cognitive tests and digital token issuance to verify and authenticate user identity, eliminating the need for physical presence while maintaining or enhancing verification reliability through cryptographic proofs.
Solution Approach 2:
The patent creates a universal digital identity credential (proof of knowledge) that can be used across multiple different platforms and services. This single verified credential serves multiple functions and can be presented to any relying party in the network, replacing the need for service-specific verification processes and providing both high reliability and convenience.
3Reliability
If multiple different passwords are required for different services, then security is improved through varying complexities, but ease of operation deteriorates due to the burden of remembering and managing passwords
Solution Approach 1:
The patent extracts the password management burden from the user by introducing a trusted service provider that handles credential issuance and verification. Instead of users creating and remembering multiple complex passwords, the system issues cryptographic proofs of knowledge that automatically handle authentication, removing the harmful element of password complexity management while maintaining security.
Solution Approach 2:
The patent enables self-service authentication where users present their own cryptographic proofs of knowledge to proving parties without requiring manual password entry or management. The proofs of knowledge automatically verify user identity through cryptographic validation, eliminating the need for users to remember or manage multiple passwords while maintaining strong security through cryptographic verification.
Data Source
AI summary
Systems and methods for initial provisioning through shared Proofs of Knowledge (PoKs) and crowdsourced identification are provided. In some embodiments, a method of sharing a PoK between a first Relying Party (RP) server and a second RP server includes receiving, by the first RP server, a request from a client device by a user for sharing the PoK. The method also includes causing, by the first RP server, the PoK to be provided to the client device and receiving, by the second RP server, a request from the client device to use the shared PoK for authentication of the user. In this way, the user may be provided additional convenience by allowing the reuse of the shared PoK. Also, depending on the number of RP servers that accept the shared PoK, the user may also be provided a degree of crowdsourced identification.


