Trusted Identity Management via Certification Authority Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trusted computing platforms lack the ability to allow users to control, create, or combine trusted user identities with associated personal data to access benefits such as discounts or credits from third parties, while maintaining privacy and ensuring the trustworthiness of the new identity.

Innovation Solution

A method involving a certification authority that verifies existing identity certificates and personal data, generating a new identity certificate incorporating personal data, which can be used to create a new trusted identity that is anonymous and unlinkable from the original identities, allowing users to combine or transfer personal credentials and trust values across identities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple identity certificates are created for a user, then the user can interact with different parties using different identities, but the user cannot control or combine personal data across these identities

Engineering Contradiction:
Improveidentity management flexibilityVSAvoididentity control mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A certification authority is introduced as an intermediary between the user and multiple identity certificates. The CA receives requests from the user to create new identities by selecting personal data from existing certificates, verifies the request, and issues new certificates. This mediator enables flexible identity management without requiring complex user-side control mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If personal data is included in identity certificates, then users can access benefits like discounts and credits, but third parties cannot verify trustworthiness of the new identity

Engineering Contradiction:
Improvepersonal data utilizationVSAvoididentity verification trust
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The certification authority provides feedback verification by checking existing identity certificates and personal data before issuing new certificates. This feedback loop ensures that new identities are trustworthy by validating them against previously verified identities, allowing third parties to trust the new identity through the CA's verification process.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If existing identity certificates are used to create new identities, then users can transfer trust values between identities, but the relationship between identities may be revealed compromising privacy

Engineering Contradiction:
Improvetrust value transferabilityVSAvoiduser privacy
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The user selects and extracts only the specific personal data needed for the new identity from existing certificates, rather than copying entire certificates or revealing all associations. This selective extraction allows trust value transfer while minimizing privacy loss by not exposing the relationship between identities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8370631B2Trusted identities on a trusted computing platform
Publication Date: 2013.02.05 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8370631B2 patent drawing
  • US8370631B2 patent drawing
  • US8370631B2 patent drawing

AI summary

A trusted certification authority service allows a user to control a combination or a subset of personal credentials associated with different trusted identities of the user to create a new identity that may be used by the user to entitle him to access or obtain a third party service. The copying and/or transfer of trust values (such as bank balances or loyalty points) between different trusted identities in order can maintain the anonymity of a person having one or more of said identities.