Template-Based Distributed Certificate Issuance for Multi-Tenant Blockchain Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The widespread adoption of blockchain technology for business transactions is hindered by the lack of identity management and clarity regarding entities involved, their contributions, and authority, which conflicts with maintaining privacy and meeting business security needs.

Innovation Solution

An identity, attribute, and reputation management framework is introduced, using tokens attached to transactions to manage reputations and automate access control, with a token management system that verifies entity qualifications and issues tokens with public keys corresponding to private keys, enabling secure and transparent business operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If blockchain technology is used for transactions, then transparency and immutability are improved, but identity management and entity clarity deteriorate

Engineering Contradiction:
Improvetransaction transparencyVSAvoididentity management
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces certificate authorities (CAs) as intermediary entities that issue digital certificates to blockchain participants. These CAs act as mediators between the anonymous blockchain system and real-world identities, enabling entity verification without compromising blockchain's decentralized nature. The CA infrastructure provides the missing identity management layer while maintaining transaction transparency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a nested structure where digital certificates containing identity information are embedded within blockchain transactions. The certificate data (including entity identifiers, public keys, and authority signatures) is nested as part of the transaction metadata, allowing identity verification to occur at multiple levels: certificate validation, authority verification, and transaction validation.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Object-affected harmful factors

If anonymous transactions are used, then privacy is improved, but entity authority and contribution tracking deteriorate

Engineering Contradiction:
Improveprivacy protectionVSAvoidentity authority
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent applies local quality by differentiating between public and private information fields within transactions. Sensitive entity details (private keys, personal identifiers) are kept confidential and encrypted, while public verification data (certificate hashes, authority signatures, contribution records) are exposed on the blockchain. This allows privacy protection for specific data elements while maintaining entity authority tracking for others.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses digital certificates to change the 'color' or visibility of entity information dynamically. Entities can present different levels of identification information based on transaction requirements - full verification for high-value transactions, partial verification for routine operations. The certificate system enables information disclosure to be adjusted like color intensity, matching the required verification level.

Inventive Principle:
Principle #32Color changes

3Reliability

If certificate verification is implemented, then entity qualification is improved, but transaction processing complexity deteriorates

Engineering Contradiction:
Improveentity qualificationVSAvoidtransaction processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by requiring entities to obtain digital certificates from certificate authorities before participating in blockchain transactions. This pre-verification process shifts the complexity from transaction-time validation to enrollment-time setup. Once certified, entities can transact with streamlined verification, as their qualifications have already been established and recorded in the certificate.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses digital certificates as copyable verification artifacts that can be reused across multiple transactions. Instead of re-verifying entity qualifications for each transaction, the system copies and validates the certificate reference. The certificate itself serves as a portable proof of qualification that can be efficiently copied and verified without reprocessing the entire identity verification chain.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10979418B2Template-based distributed certificate issuance in a multi-tenant environment
Publication Date: 2021.04.13 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10979418B2 patent drawing
  • US10979418B2 patent drawing
  • US10979418B2 patent drawing

AI summary

One example method may include generating a template transaction certificate by one or more entities which verify proof of ownership of attributes incorporated into the template transaction certificate, and generating one or more operational transaction certificates by the one or more entities which verified proof of ownership of the template transaction certificate.