Decentralized identity methods and systems
The present techniques relate to, inter alia, cryptographically-verifiable insurance credentials and cryptographically-verifiable property transfer. The novel methods and systems of decentralized identity discussed herein improve user experience (whether individual or organizational) by moving control over identity from the hands of centralized entities, back to where it belongs—i.e., to the hands of individual organizations and users. In one aspect, a method includes obtaining a scanned image; processing the scanned image; transmitting a claim request; and receiving and storing an attestation response, and a computing system includes a processor; and a memory having stored thereon computer-executable instructions that, when executed by the one or more processors, cause the computing system to: receive a claim request; cryptographically verify the claim; and transmit an attestation response.
1 . A computing system for providing a cryptographically-signed credential, comprising:
one or more processors; and
one or more memories having stored thereon computer-executable instructions that, when executed by the one or more processors, cause the computing system to:
transmit an out-of-band message including instructions to establish a decentralized identifier (DID) protocol for further communication, wherein a type of the DID protocol is selected from among a plurality of DID protocols and is indicated by the instructions of the out-of-band message;
receive a decentralized identifier (DID) communication request according to the DID protocol indicated by the instructions of the out-of-band message from a mobile computing device, the DID communication request including at least a cryptographic key of a user and security data;
verify the DID communication request based upon the cryptographic key and security data; and
transmit an attestation response corresponding to the DID communication request to the mobile computing device.
2 . The computing system of claim 1 , the memories having stored thereon further instructions that, when executed by the one or more processors, cause the computing system to:
receive a verification request from the mobile computing device;
determine a set of credential proof parameters required to verify the verification request;
transmit a credential proof request to the mobile computing device, the credential proof request including the set of credential proof parameters; and
receive one or more credentials of the user, the one or more credentials corresponding to the one or more credential proof request parameters.
3 . The computing system of claim 2 , the memories having stored thereon further instructions that, when executed by the one or more processors, cause the computing system to:
verify one or more cryptographic signatures of the received credentials;
generate an electronic form including at least one field including values corresponding to the credential proof request parameters; and
transmit the electronic form to the mobile computing device.
4 . The computing system of claim 3 , the memories having stored thereon further instructions that, when executed by the one or more processors, cause the computing system to:
receive a submission of the electronic form; and
process the electronic form.
5 . The computing system of claim 1 , the memories having stored thereon further instructions that, when executed by the one or more processors, cause the computing system to:
transmit a proof-of-insurance credential to the mobile computing device.
6 . The computing system of claim 1 , the memories having stored thereon further instructions that, when executed by the one or more processors, cause the computing system to:
transmit a vehicle proof-of-insurance credential to the mobile computing device, the proof-of-insurance credential including insurance description information including at least a policy number, a named insured, a policy effective date, a policy expiration data, a vehicle identification number, a vehicle make and a vehicle year.
7 . The computing system of claim 1 , the memories having stored thereon further instructions that, when executed by the one or more processors, cause the computing system to:
transmit a homeowners' proof-of-insurance credential to the mobile computing device, the proof-of-insurance credential including insurance description information including at least a policy number, a named insured, a policy effective date, a policy expiration date, a coverage limit, a liability limit, a deductible and a policy premium.
8 . The computing system of claim 1 , the memories having stored thereon further instructions that, when executed by the one or more processors, cause the computing system to:
receive a public key and security data including a session cookie identifying an authenticated web session of the user.
9 . A non-transitory computer-readable medium having stored thereon computer-executable instructions, that when executed, cause a computer to:
transmit an out-of-band message including instructions to establish a decentralized identifier (DID) protocol for further communication, wherein a type of the DID protocol is selected from among a plurality of DID protocols and is indicated by the instructions of the out-of-band message;
receive a decentralized identifier (DID) communication request according to the DID protocol indicated by the instructions of the out-of-band message from a mobile computing device, the DID communication request including at least a cryptographic key of a user and security data;
verify the DID communication request based upon the cryptographic key and security data; and
transmit an attestation response corresponding to the DID communication request to the mobile computing device.
10 . The non-transitory computer-readable medium of claim 9 , having stored thereon further computer-executable instructions, that when executed, cause a computer to:
receive a verification request from the mobile computing device;
determine a set of credential proof parameters required to verify the verification request;
transmit a credential proof request to the mobile computing device, the credential proof request including the set of credential proof parameters; and
receive one or more credentials of the user, the one or more credentials corresponding to the one or more credential proof request parameters.
11 . The non-transitory computer-readable medium of claim 10 , having stored thereon further computer-executable instructions, that when executed, cause a computer to:
verify one or more cryptographic signatures of the received credentials;
generate an electronic form including at least one field including values corresponding to the credential proof request parameters; and
transmit the electronic form to the mobile computing device.
12 . The non-transitory computer-readable medium of claim 11 , having stored thereon further computer-executable instructions, that when executed, cause a computer to:
receive a submission of the electronic form; and
process the electronic form.
13 . The non-transitory computer-readable medium of claim 12 , having stored thereon further computer-executable instructions, that when executed, cause a computer to:
transmit a vehicle proof-of-insurance credential to the mobile computing device, the proof-of-insurance credential including insurance description information including at least a policy number, a named insured, a policy effective date, a policy expiration data, a vehicle identification number, a vehicle make and a vehicle year.
14 . The non-transitory computer-readable medium of claim 9 , having stored thereon further computer-executable instructions, that when executed, cause a computer to:
transmit a homeowners' proof-of-insurance credential to the mobile computing device, the proof-of-insurance credential including insurance description information including at least a policy number, a named insured, a policy effective date, a policy expiration date, a coverage limit, a liability limit, a deductible and a policy premium.
15 . The non-transitory computer-readable medium of claim 9 , having stored thereon further computer-executable instructions, that when executed, cause a computer to:
receive a public key and security data including a session cookie identifying an authenticated web session of the user.
16 . A computer-implemented method for providing a cryptographically-signed credential, comprising:
transmitting an out-of-band message including instructions to establish a decentralized identifier (DID) protocol for further communication, wherein a type of the DID protocol is selected from among a plurality of DID protocols and is indicated by the instructions of the out-of-band message;
receiving a decentralized identifier (DID) communication request according to the DID protocol indicated by the instructions of the out-of-band message from a mobile computing device, the DID communication request including at least a cryptographic key of a user and security data;
verifying the DID communication request based upon the cryptographic key and security data; and
transmitting an attestation response corresponding to the DID communication request to the mobile computing device.
17 . The computer-implemented method of claim 16 , further comprising:
receiving a verification request from the mobile computing device;
determining a set of credential proof parameters required to verify the verification request;
transmitting a credential proof request to the mobile computing device, the credential proof request including the set of credential proof parameters; and
receiving one or more credentials of the user, the one or more credentials corresponding to the one or more credential proof request parameters.
18 . The computer-implemented method of claim 17 , further comprising:
verifying at least one cryptographic signature of the received credentials;
generating an electronic form including at least one field including values corresponding to the credential proof request parameters; and
transmitting the electronic form to the mobile computing device.
19 . The computer-implemented method of claim 18 , further comprising:
receiving a submission of the electronic form; and
process the electronic form.
20 . The computer-implemented method of claim 16 , further comprising:
transmit a vehicle proof-of-insurance credential to the mobile computing device, the proof-of-insurance credential including insurance description information including at least a policy number, a named insured, a policy effective date, a policy expiration data, a vehicle identification number, a vehicle make and a vehicle year.