Self-Sovereign Identity Authentication via Verifiable Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods, such as password-based systems and federated authentication, are vulnerable to identity theft and unsuitable for sensitive services, as they require third-party involvement and storage of sensitive information.

Innovation Solution

A Self-Sovereign Identity (SSI) system is implemented, where a telecommunication service provider generates verifiable credentials using cryptographic signatures, allowing customers to authenticate peer-to-peer without sharing personal information with third parties, utilizing a decentralized identity framework and blockchain for secure and reliable identity management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password-based authentication or federated authentication is used, then authentication functionality is provided, but the system becomes vulnerable to identity theft and requires third-party involvement

Engineering Contradiction:
Improveauthentication securityVSAvoidthird-party involvement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication verification function from third-party servers and places it directly on the user's device. The private key and authentication logic are stored locally, eliminating the need for continuous third-party involvement in the authentication process while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The device performs self-authentication using locally stored private keys and biometric data. The system serves itself by verifying authentication credentials without requiring external third-party verification, thereby reducing complexity and improving security.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If sensitive information is stored for authentication, then authentication is enabled, but the system becomes vulnerable to identity theft

Engineering Contradiction:
Improveauthentication capabilityVSAvoididentity theft risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional mechanical storage of sensitive information (passwords, PII) with cryptographic keys stored in secure hardware elements. Biometric data is transformed into cryptographic signatures through mathematical functions, eliminating the need to store actual sensitive information while maintaining authentication capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system prepares cryptographic key pairs and secure storage structures in advance, before any authentication event occurs. The private key is generated and protected within secure hardware elements beforehand, cushioning against potential identity theft by ensuring sensitive data never exists in vulnerable forms.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Ease of operation

If third parties store authentication data, then authentication is facilitated, but liability for improper access increases

Engineering Contradiction:
Improveauthentication processVSAvoidthird-party liability
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent extracts authentication data storage and management from third-party systems and places it entirely within the user's device. This eliminates third-party liability by removing their role in storing sensitive authentication information, while authentication remains facilitated through the device's local capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12052246B2Personal identity system
Publication Date: 2024.07.30 VERIZON PATENT & LICENSING INC
  • US12052246B2 patent drawing
  • US12052246B2 patent drawing
  • US12052246B2 patent drawing

AI summary

A service provider may offer an identity proofing service that can be used to generate verifiable credentials (VCs) with customer-selected attributes. The VCs may use cryptographic signatures to indicate proof of identity certified by, for example, a telecommunications service provider. After a one-time process to obtain the VCs and associate them with a shell identity, the customer with a client device may use the VCs as a form of authentication for relying parties in a two-way (e.g., peer-to-peer) authentication process.