Verifiable Credentials for Message Provenance and Identity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods, particularly passwordless systems like magic links, are vulnerable to security risks such as reliance on insecure messaging systems and man-in-the-middle attacks, and lack interoperability between disparate systems.

Innovation Solution

The technology leverages decentralized identity authentication using verifiable credentials (VCs) to enable bidirectional authentication between actors through a messaging platform, incorporating a chain of plums to secure message content provenance and authenticate identities without relying on centralized services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If passwordless authentication methods like magic links are used, then ease of operation is improved, but security is worsened due to vulnerability to man-in-the-middle attacks and reliance on insecure messaging systems

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces Verifiable Credentials as an intermediary layer between the messaging system and the authentication process. These credentials act as self-contained proof of identity that can be verified without relying on the security of the messaging channel, thereby resolving the contradiction between ease of operation and security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication by verifying Verifiable Credentials before establishing the messaging connection. This preliminary verification ensures that even if the messaging channel is compromised, the identities of the participants have already been authenticated through a separate, secure process

Inventive Principle:
Principle #10Preliminary action

2Reliability

If centralized authentication services are used, then reliability is improved, but adaptability is worsened due to lack of interoperability between disparate systems

Engineering Contradiction:
Improveauthentication securityVSAvoidinteroperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements Verifiable Credentials using widely-adopted standards (such as W3C Verifiable Credentials) that can be universally accepted across different systems and organizations. This allows the authentication mechanism to function reliably across disparate platforms without requiring system-specific integration, thereby achieving both reliability and adaptability

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If verifiable credentials with chain of plums are used, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct, independent components: Verifiable Credentials for identity proof, chains of plums for message integrity, and separate verification logic. This segmentation allows each component to be implemented and verified independently, reducing the perceived complexity while maintaining high security

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250225271A1Verifiable credentialling and message content provenance authentication
Publication Date: 2025.07.10 LEDGERDOMAIN INC
  • US20250225271A1 patent drawing
  • US20250225271A1 patent drawing
  • US20250225271A1 patent drawing

AI summary

The technology disclosed allows for leveraging decentralized credentials to achieve bidirectional authentication between two actors leveraging a messaging platform/system, such as email or another text-based system, verifiable credentials (VCs), and secure web endpoints. It empowers one party (“Sender”) to send a message enclosed with a Verifiable Presentation which allows another party (“Recipient”) to authenticate the message's provenance and the identity of the sender. Moreover, the message contains a link to a secure web endpoint, where the recipient can submit a response signed by their own Verifiable Presentation, allowing the Sender to authenticate the identity of the Recipient. In this way, both participants are able to authenticate each other's identities with an additional factor of authentication, with neither participant being required to share a single service.