Zero-Knowledge Hash Validation for Privacy-Safe ID Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing ID card generation and authentication systems lack robust mechanisms to verify the authenticity of the user presenting the card, ensuring the information on the card is accurate and matches the user's biometric and biographic data, and to securely manage and authenticate access to secure locations.
Innovation Solution
Utilizing a zero knowledge hash function to generate a hashed data string from user information, storing it in a database, and verifying its presence during authentication, with a card authenticator sending control signals to access control devices based on the verification results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication systems store personally identifiable information for verification, then authentication can be performed, but security and privacy are compromised due to potential data breaches and misuse
Solution Approach 1:
The patent extracts only the essential verification element (hashed data string) from the complete personally identifiable information, storing only what is necessary for authentication while removing all other sensitive data elements. This extraction principle resolves the contradiction by maintaining authentication capability while eliminating privacy risks associated with storing full PII.
Solution Approach 2:
The patent introduces a hashed data string as an intermediary between the original personally identifiable information and the authentication verification process. This intermediary transforms sensitive information into a non-reversible format that can be stored and verified without exposing the underlying PII, thus resolving the security-privacy contradiction.
2Measurement precision
If comprehensive user information is stored for thorough verification, then authentication accuracy is improved, but system complexity and storage requirements increase
Solution Approach 1:
The system extracts only the critical authentication element (hashed data string derived from user information) rather than storing and processing all user data. This extraction maintains sufficient authentication accuracy while dramatically reducing system complexity and storage requirements.
Solution Approach 2:
The patent transforms the authentication approach by changing the parameter from storing raw user information to storing hashed data strings. This parameter change maintains verification accuracy through cryptographic hashing while simplifying the overall system architecture and reducing computational complexity.
3Productivity
If hashed data strings are stored in a centralized database, then verification efficiency is improved, but the system becomes more vulnerable to database breaches
Solution Approach 1:
The patent converts the potential harm of database storage into a benefit by using one-way hashing functions. The hashed data strings can be efficiently stored and queried in a centralized database for fast verification, but if the database is breached, the hashed values cannot be reversed to obtain original user information, thus turning the storage vulnerability into a security advantage.
Solution Approach 2:
The hashed data string serves as an intermediary that enables efficient centralized database storage and querying while protecting against breach consequences. The intermediary allows the system to achieve verification efficiency through centralized storage without suffering the full harm of potential database compromises.
Data Source
AI summary
Aspects of the present invention relate to machines, systems, and methods for using a zero knowledge hash function to verify validity of an ID. Certain configurations may provide machines, systems, and method for proving the ID is genuine, the information on the ID is correct, and the user presenting the ID is the same as the user in the ID. Some configurations may store a hash based on a one-way function of a data string created from information on the ID in a hashed data string database. Certain variations of the invention may query the database to verify the hashed data string exists in the database. Based on the response of the database to the query, a card authenticator may be configured to send a control transmission to an access control device to cause the access control device change from a first state to a second state.


