Virtual ID Credential Data Segmentation for Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual ID systems face challenges in selectively providing necessary information to relying parties while maintaining privacy and adhering to international standards, as they often require all data groups to be transmitted for verification, which can include sensitive information not needed for specific transactions.
Innovation Solution
The system allows for the creation of custom data groups that are separate from standard data groups, with auxiliary data elements that are not directly accessible using the standard, enabling selective release of information based on the role and context of the relying party, using digitally signed hash values and mutual authentication algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all data groups are transmitted for verification according to international standards, then verification reliability is improved, but information privacy is worsened due to transmission of sensitive information not needed for specific transactions
Solution Approach 1:
The patent segments the credential data into multiple data groups (DG1-DG16) according to ISO 18013 standards, allowing selective transmission of only the necessary segments for verification. This enables the system to maintain verification reliability by transmitting complete required data groups while avoiding transmission of sensitive information contained in other groups, thus resolving the contradiction between verification reliability and information privacy.
Solution Approach 2:
The patent extracts and transmits only the specific data groups needed for verification purposes, separating them from the complete credential data stored in the mobile device. By taking out only the necessary information elements required for the verification transaction, the system ensures verification reliability without compromising information privacy by leaving sensitive data groups untranslated and untransmitted.
2Loss of information
If custom data groups are created to selectively release information, then information privacy is improved, but device complexity is worsened due to additional data structure management
Solution Approach 1:
The patent implements a universal data group structure that serves multiple functions: it complies with ISO 18013 standards for international interoperability, enables selective information release through standard-compliant data group selection, and maintains verification integrity through digitally signed hash values. This multi-functional approach allows the system to achieve information privacy through standard mechanisms rather than requiring complex custom data structures, thus resolving the contradiction between information privacy and device complexity.
Solution Approach 2:
The patent performs preliminary organization of credential data into standardized data groups during credential issuance, with each group containing specific elements and digital signatures. This preliminary structuring enables selective transmission of only necessary groups during verification transactions, achieving information privacy without requiring complex runtime data structure management, thereby resolving the contradiction between information privacy and device complexity.
3Reliability
If digitally signed hash values are used to verify data integrity, then verification reliability is improved, but data transmission volume is worsened due to inclusion of multiple hash values and signatures
Solution Approach 1:
The patent applies partial action by including only the digitally signed hash values necessary for verifying the integrity of transmitted data groups, rather than transmitting hashes for all possible data groups. By including only the minimal required verification data for the specific transaction, the system maintains data integrity verification reliability while minimizing the additional data transmission volume, thus resolving the contradiction between verification reliability and data transmission volume.
Data Source
AI summary
Maintaining a plurality of different sets of data groups for virtualized credentials of a holder includes storing a first subset of the data groups according to a standard for storing data groups, where the standard verifies each data group in the first subset of data groups, storing a second subset of the data groups as a plurality of auxiliary data elements that are separate from the first subset, where auxiliary data elements are not directly accessible using the standard, providing at least one custom data group in the first subset that verifies each of the auxiliary data elements, and verifying at least one of the auxiliary data elements using the custom data group and verifying the custom data group using the standard. The standard may be ISO 18013. The digital signature may be provided by a party that is trusted by a relying party that receives data from the holder.


