Virtual Credential Verification via Offline Cryptogram
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual ID card systems face challenges in verifying credentials without access to a centralized network, as malicious users can create fraudulent images, and relying parties may not always have connectivity to verify information.
Innovation Solution
A system that allows virtualized credential information to be provided directly to a relying party device, either online or offline, using a credential verification cryptogram and URL from a network/cloud infrastructure, ensuring secure and efficient verification processes, even in offline conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If credential verification is performed online through centralized location, then verification reliability is improved, but system complexity and network dependency increase
Solution Approach 1:
The verification system is segmented into two modes: online verification through centralized location and offline verification using pre-provisioned credentials. This segmentation allows the system to maintain high reliability through centralized verification when available, while reducing complexity and network dependency when operating offline.
Solution Approach 2:
The system dynamically switches between online and offline verification modes based on network availability and operational context. This dynamic adaptation allows the system to optimize between verification reliability and system complexity/network dependency according to real-time conditions.
2Loss of information
If all credential information is released to relying party, then verification completeness is improved, but information privacy and security worsen
Solution Approach 1:
The system extracts and releases only the specific credential information necessary for verification purposes, rather than providing all credential data. This selective extraction ensures verification completeness while minimizing information privacy risks by limiting data exposure to only what is needed.
Solution Approach 2:
Different levels of credential information are provided based on the specific verification context and requirements. The system applies local quality by tailoring the information release to the particular situation, ensuring completeness where needed while protecting privacy where not required.
3Ease of operation
If offline verification is enabled, then system accessibility and ease of operation are improved, but verification security and reliability may worsen
Solution Approach 1:
Credential verification data is pre-provisioned to the license holder device during offline periods or when connectivity is available. This preliminary action ensures that the device has necessary verification credentials ready, enabling secure offline verification operations without compromising security while improving accessibility.
Solution Approach 2:
The system prepares and stores backup verification credentials and cryptographic data in advance, cushioning against potential network unavailability. This beforehand preparation ensures that offline operations can proceed securely without compromising verification security, while maintaining high system accessibility.
Data Source
AI summary
Providing virtualized credential information includes determining whether a relying party device has access to a network/cloud infrastructure that contains at least some of the credential information, a license holder device providing the virtualized credential information directly to the relying party device in response to the relying party device not having access to the network/cloud infrastructure, and displaying at least some of the subset of credential data on a screen of the device of the relying party. Providing virtualized credential information may also include the license holder device providing authorization data to the relying party device in response to the relying party device having access to the network/cloud infrastructure and determining a preference for the relying party device to receive at least some of the virtualized credential information from the network/cloud infrastructure.


