Decentralized Identity Verification via Zero-Knowledge Proofs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, the secure management of personally identifying information is challenging due to issues like data replication, privacy concerns, and the lack of consent in information sharing across decentralized systems, leading to security breaches and privacy violations.

Innovation Solution

A decentralized identity management system using a combination of gossip protocols and zero-knowledge proofs to verify identities without sharing private information, storing the realized state of transactions in a Merkle database to reduce data replication and enable consent-based information sharing, and utilizing a federation of pools to retrieve local identity information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personally identifying information is stored and distributed across decentralized systems for identity verification, then identity verification capability is improved, but security risks and privacy leakage increase

Engineering Contradiction:
Improveidentity verification capabilityVSAvoidsecurity risks and privacy leakage
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential verification capability from personally identifying information by implementing zero-knowledge proofs. This allows the system to verify identity claims without extracting or storing the actual private information, thereby maintaining verification capability while eliminating security risks associated with data distribution.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic intermediaries (zero-knowledge proof protocols and Merkle trees) that mediate between identity verification needs and privacy protection. These intermediaries enable verification without direct exposure of sensitive data, resolving the contradiction between verification capability and security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If personal information is shared across decentralized networks for verification, then verification efficiency is improved, but user control over personal data is lost

Engineering Contradiction:
Improveverification efficiencyVSAvoiduser control over personal data
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by having users generate and retain control of their own cryptographic keys and identity credentials before any verification occurs. This allows users to maintain control over their personal data while still enabling efficient verification through pre-established cryptographic proofs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service by allowing users to autonomously manage their identity verification through cryptographic keys and zero-knowledge proofs without requiring centralized control or consent mechanisms. Users can verify their own identity claims efficiently while maintaining full control over their personal data.

Inventive Principle:
Principle #25Self-service

3Reliability

If data is replicated across distributed systems for availability, then system availability is improved, but data replication increases security breach risks

Engineering Contradiction:
Improvesystem availabilityVSAvoiddata replication volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the essential verification information from replicated data by using zero-knowledge proofs and Merkle tree roots. Instead of replicating full personal information across distributed systems, only cryptographic proofs and hash roots are replicated, maintaining system availability while minimizing data replication volume and associated security risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11082226B2Zero-knowledge identity verification in a distributed computing system
Publication Date: 2021.08.03 SALESFORCE INC
  • US11082226B2 patent drawing
  • US11082226B2 patent drawing
  • US11082226B2 patent drawing

AI summary

For each data value associated with a data object, a respective object value identification query message that includes the data value may be sent to each of a plurality of identity nodes via a network. For each of the data values, a respective object value identification response message that includes a respective network identifier corresponding with the respective data value may be received. A local identifier may be determined based on the object value identification response messages, and a response query message including the local identifier may be transmitted.