High-Assurance Identity Enrollment Through PII Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enrollment processes expose users to excessive sharing of personal identifiable information (PII) during identity verification, compromising privacy and security.

Innovation Solution

A trusted source intermediary system that securely stores user PII and provides attestations of specific facts related to the user, minimizing the sharing of actual PII by replacing it with binary confirmations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional enrollment processes are used to verify user identity, then identity verification can be performed, but excessive personal identifiable information (PII) is shared with requesting authorities

Engineering Contradiction:
Improveidentity verification assuranceVSAvoidPII exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

A trusted source server acts as an intermediary between the user and the requesting authority. The server receives PII from the user, stores it securely, and provides attestations to the requesting authority without sharing the actual PII. This mediator approach allows identity verification while minimizing information exposure to unauthorized parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system extracts only the necessary factual information from the user's PII and provides it as attestations to the requesting authority. Instead of sharing complete PII datasets, the system extracts and transmits only the specific facts needed for verification (e.g., age, citizenship status), leaving the rest of the sensitive information secured with the user.

Inventive Principle:
Principle #2Taking out (Extraction)

2Loss of information

If minimal PII sharing is implemented through attestations, then user privacy is protected, but the system complexity increases

Engineering Contradiction:
ImprovePII sharing minimizationVSAvoidenrollment system structure
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The trusted source server simplifies the overall system architecture by centralizing the complex tasks of PII storage, verification, and attestation generation. This mediator handles the complexity internally, presenting a simple interface to both users and requesting authorities, thus reducing the perceived system complexity despite the sophisticated underlying mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a simplified representation of user information in the form of attestations rather than copying the entire PII dataset. These attestation copies contain only the necessary factual information needed for verification purposes, reducing the complexity of information handling while maintaining verification functionality.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12443753B2High assurance enrollment for identities
Publication Date: 2025.10.14 TYCO FIRE & SECURITY GMBH
  • US12443753B2 patent drawing
  • US12443753B2 patent drawing
  • US12443753B2 patent drawing

AI summary

A method and apparatus for facilitating user enrollment by a secure server of a trusted source includes receiving, from a user device, personal identifiable information (PII) of the user. The aspects include securely storing the PII. The aspects include receiving, from a requesting authority that is attempting to enroll the user, an identifier of the user and a request for an attestation of a fact attributable to the user that is evaluated for enrollment. The aspects include comparing the identifier of the user and the fact attributable to the user to the PII to find a match. The aspects include minimizing a sharing of the PII user with the requesting authority by confirming, to the requesting authority, the attestation of the fact attributable to the user together with the identifier of the user in place of at least some of the PII, responsive to a comparison result indicating the match.