Self-Sovereign Identity Authentication via Verifiable Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods, such as password-based systems and federated authentication, are vulnerable to identity theft and unsuitable for sensitive services, as they require third-party involvement and storage of sensitive information.
Innovation Solution
A Self-Sovereign Identity (SSI) system is implemented, where a telecommunication service provider generates verifiable credentials using cryptographic signatures, allowing customers to authenticate peer-to-peer without sharing personal information with third parties, utilizing a decentralized identity framework and blockchain for secure and reliable identity management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based authentication or federated authentication is used, then authentication functionality is provided, but the system becomes vulnerable to identity theft and requires third-party involvement
Solution Approach 1:
The patent extracts the authentication verification function from third-party servers and places it directly on the user's device. The private key and authentication logic are stored locally, eliminating the need for continuous third-party involvement in the authentication process while maintaining security.
Solution Approach 2:
The device performs self-authentication using locally stored private keys and biometric data. The system serves itself by verifying authentication credentials without requiring external third-party verification, thereby reducing complexity and improving security.
2Ease of operation
If sensitive information is stored for authentication, then authentication is enabled, but the system becomes vulnerable to identity theft
Solution Approach 1:
The patent replaces traditional mechanical storage of sensitive information (passwords, PII) with cryptographic keys stored in secure hardware elements. Biometric data is transformed into cryptographic signatures through mathematical functions, eliminating the need to store actual sensitive information while maintaining authentication capability.
Solution Approach 2:
The system prepares cryptographic key pairs and secure storage structures in advance, before any authentication event occurs. The private key is generated and protected within secure hardware elements beforehand, cushioning against potential identity theft by ensuring sensitive data never exists in vulnerable forms.
3Ease of operation
If third parties store authentication data, then authentication is facilitated, but liability for improper access increases
Solution Approach 1:
The patent extracts authentication data storage and management from third-party systems and places it entirely within the user's device. This eliminates third-party liability by removing their role in storing sensitive authentication information, while authentication remains facilitated through the device's local capabilities.
Data Source
AI summary
A service provider may offer an identity proofing service that can be used to generate verifiable credentials (VCs) with customer-selected attributes. The VCs may use cryptographic signatures to indicate proof of identity certified by, for example, a telecommunications service provider. After a one-time process to obtain the VCs and associate them with a shell identity, the customer with a client device may use the VCs as a form of authentication for relying parties in a two-way (e.g., peer-to-peer) authentication process.


