Verifiable Credentials for Message Provenance and Identity Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods, particularly passwordless systems like magic links, are vulnerable to security risks such as reliance on insecure messaging systems and man-in-the-middle attacks, and lack interoperability between disparate systems.
Innovation Solution
The technology leverages decentralized identity authentication using verifiable credentials (VCs) to enable bidirectional authentication between actors through a messaging platform, incorporating a chain of plums to secure message content provenance and authenticate identities without relying on centralized services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If passwordless authentication methods like magic links are used, then ease of operation is improved, but security is worsened due to vulnerability to man-in-the-middle attacks and reliance on insecure messaging systems
Solution Approach 1:
The patent introduces Verifiable Credentials as an intermediary layer between the messaging system and the authentication process. These credentials act as self-contained proof of identity that can be verified without relying on the security of the messaging channel, thereby resolving the contradiction between ease of operation and security
Solution Approach 2:
The system performs preliminary authentication by verifying Verifiable Credentials before establishing the messaging connection. This preliminary verification ensures that even if the messaging channel is compromised, the identities of the participants have already been authenticated through a separate, secure process
2Reliability
If centralized authentication services are used, then reliability is improved, but adaptability is worsened due to lack of interoperability between disparate systems
Solution Approach 1:
The patent implements Verifiable Credentials using widely-adopted standards (such as W3C Verifiable Credentials) that can be universally accepted across different systems and organizations. This allows the authentication mechanism to function reliably across disparate platforms without requiring system-specific integration, thereby achieving both reliability and adaptability
3Reliability
If verifiable credentials with chain of plums are used, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent segments the authentication system into distinct, independent components: Verifiable Credentials for identity proof, chains of plums for message integrity, and separate verification logic. This segmentation allows each component to be implemented and verified independently, reducing the perceived complexity while maintaining high security
Data Source
AI summary
The technology disclosed allows for leveraging decentralized credentials to achieve bidirectional authentication between two actors leveraging a messaging platform/system, such as email or another text-based system, verifiable credentials (VCs), and secure web endpoints. It empowers one party (“Sender”) to send a message enclosed with a Verifiable Presentation which allows another party (“Recipient”) to authenticate the message's provenance and the identity of the sender. Moreover, the message contains a link to a secure web endpoint, where the recipient can submit a response signed by their own Verifiable Presentation, allowing the Sender to authenticate the identity of the Recipient. In this way, both participants are able to authenticate each other's identities with an additional factor of authentication, with neither participant being required to share a single service.


