SSI Structured Messaging for Cross-Channel KYC Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Financial Institutions (FIs) face challenges in complying with Know Your Customer (KYC) regulations by verifying customer identity over insecure communications, exposing personal identifiable information (PII) to untrusted third-parties, and lacking mechanisms for secure, off-chain authentication.
Innovation Solution
Implementing self-sovereign identity (SSI) structured messaging for cross-channel authentication using Decentralized Identifiers (DIDs) to establish secure wallet-to-wallet communication, enabling encrypted and signed challenges and responses off the blockchain, allowing authentication without revealing PII over the communication channel.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Financial Institutions ask for PII over communication channels to verify customer identity, then KYC compliance is achieved, but customer PII is exposed to untrusted third-parties and security risks
Solution Approach 1:
The patent introduces Decentralized Identifiers (DIDs) and Verifiable Credentials as intermediary mechanisms that enable KYC verification without direct PII exchange. The DID acts as a mediator between the customer's identity proof and the FI's verification system, allowing authentication while keeping PII private and stored only in the customer's secure wallet.
Solution Approach 2:
The patent extracts PII from the communication channel entirely. Instead of transmitting PII over phones, emails, or web forms, the system uses cryptographic proofs derived from PII stored locally in the customer's wallet. The PII remains extracted and isolated from untrusted communication channels while still enabling verification.
2Reliability
If Financial Institutions collect and retain customer data for KYC verification, then regulatory requirements are met, but data security vulnerabilities and breach risks increase
Solution Approach 1:
The patent extracts PII from centralized FI databases and relocates it to decentralized customer-controlled wallets. The FI no longer collects or stores PII, eliminating the centralized data repository that would be vulnerable to breaches. Only cryptographic proofs and DIDs are retained by the FI, which cannot be used for identity theft.
Solution Approach 2:
The customer's wallet serves as a self-service secure storage mechanism for PII and identity credentials. The wallet autonomously manages cryptographic keys and generates verifiable proofs without requiring FI involvement in data storage, thereby eliminating FI liability for data security while maintaining verification capability.
3Ease of operation
If multiple communication channels are used for customer service, then accessibility and convenience are improved, but security vulnerabilities across channels increase
Solution Approach 1:
The DID and verifiable credential system serves as a universal authentication mechanism that functions across all communication channels (phone, email, web, mobile app). Instead of implementing separate security protocols for each channel, the same cryptographic verification process is applied universally, eliminating channel-specific security vulnerabilities.
Data Source
AI summary
A customer engages a Financial Institution (FI) for access to an account or a service associated with the account of the customer over a first channel of communication. A decentralized identifier (DID) connection is established between a FI wallet and a Self-Sovereign Identity (SSI)-enabled customer wallet. A structured message that is cryptographically signed is sent from the FI wallet to the customer wallet over a secure channel of communication. The message requests authorization of the customer or requests specific Personal Identifiable Information (PII) of the customer. The customer responds via the customer wallet and a second structured message is cryptographically signed and sent to the FI wallet over the secure channel of communication. When the second structured message is authenticated by the FI, the customer is approved for access to the account or approved for access to the service over the first channel of communication.


