Verifiable Credential Contracts for Cross-Network Data Portability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data portability systems across multiple disparate networks lack security, user control, and automated verification of data usage, failing to comply with regulations like GDPR and PSD2, and are prone to unauthorized data access and misuse.

Innovation Solution

A system employing JSON-LD link contracts and PKI public/private key pairs for secure, automated data transfers, enabling users to set access controls and permissions, and ensuring compliance with GDPR and PSD2 through cryptographically signed agreements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transferred across multiple disparate networks without centralized control, then data portability and user autonomy are improved, but security and compliance verification deteriorate

Engineering Contradiction:
Improvedata portabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a distributed network of Notary Servers as intermediaries between data subjects and data controllers. These notaries verify digital signatures and credentials without centralizing control, enabling secure verification across disparate networks while maintaining data portability and user autonomy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where notary servers provide verification results and compliance status back to the data transfer process. This enables real-time validation of digital signatures and credentials, ensuring security and compliance while maintaining decentralized data portability.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If traditional authentication methods are used, then ease of operation is improved, but compliance with GDPR and PSD2 deteriorates

Engineering Contradiction:
Improveauthentication simplicityVSAvoidregulatory compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by requiring data subjects to obtain verifiable credentials and digital signatures before data transfer occurs. This advance preparation ensures GDPR and PSD2 compliance is built into the authentication process itself, maintaining ease of operation while guaranteeing regulatory adherence.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces traditional mechanical authentication methods with cryptographic digital signatures and verifiable credentials. This substitution maintains user-friendly operation while ensuring compliance with GDPR and PSD2 through mathematically secure verification mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If manual verification of data usage permissions is performed, then measurement precision is improved, but productivity deteriorates

Engineering Contradiction:
Improvepermission verification accuracyVSAvoiddata transfer efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements self-service through automated verification of digital signatures and verifiable credentials by notary servers. The system automatically validates data usage permissions without manual intervention, achieving both high measurement precision in permission verification and high productivity in data transfer efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual verification processes are replaced with automated cryptographic verification mechanisms. Digital signatures and verifiable credentials enable machine-to-machine validation of data usage permissions, achieving both precise permission verification and high data transfer productivity through automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If centralized data control is implemented, then security is improved, but adaptability across disparate networks deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork interoperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the verification function from data control, distributing notary servers across multiple networks while maintaining security through cryptographic verification. This segmentation enables both high security through distributed verification and high adaptability across disparate networks through standardized digital signature validation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universality through standardized digital signature and verifiable credential mechanisms that work across disparate networks. The notary servers provide multi-functional verification services that maintain security while enabling broad network interoperability and data portability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12463823B2Systems and methods for digitally signed contracts with verifiable credentials
Publication Date: 2025.11.04 PORTABLE DATA CORP
  • US12463823B2 patent drawing
  • US12463823B2 patent drawing
  • US12463823B2 patent drawing

AI summary

A method for seamlessly and automatically granting tailored permission for use and transference of internet data between databases with comprehensive consent is described. The method employs a graph language such as JSON-LD to integrate and employ cryptographically signed Information Sharing Agreements (ISAs) between parties. Data is serialized to be easily transferred between databases when appropriate permission is obtained. Granular data exchange under usage control contacts can be automated among any number of parties on the internet. As such, the method provides a means by which users may control not only what may be done with their data, but to what entity or entities the data may be transferred. Advertisements may then be served to the user according to his or her preferences as defined within a web or desktop app, which is then applied to all related ad publishers publishing to the domains visited by the user.