Authentication Object Ledger for Forgery Detection in Zero Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current zero trust network security implementations lack stateful, deterministic means for detecting authentication forgeries and fail to track all authentication objects, leading to vulnerabilities in protocols like SAML, Kerberos, and OAuth2, which are exploited by attackers for unauthorized access.

Innovation Solution

Implement a system with a master ledger to store all authentication objects and install authentication object agents at domain controllers and local hosts to track and compare authentication objects in real-time, using stateful deterministic methods to detect and prevent forged authentication attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional authentication and authorization processes are used in perimeter-based networks, then users and devices inside the perimeter can access network resources based on traditional authentication, but the security is inadequate when networks span multiple geographic regions and physical environments

Engineering Contradiction:
Improvenetwork coverageVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication verification process into multiple independent components: a master ledger storing authentication objects at domain controllers, local host log extensions at individual hosts, and a verification system that queries both sources. This segmentation allows the system to maintain security across distributed geographic regions by verifying authentication objects locally and centrally without relying on a single perimeter defense.

Inventive Principle:
Principle #1Segmentation

2Reliability

If current zero trust network security implementations are used, then network security is improved, but there is no stateful, deterministic means for detecting authentication forgeries

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication forgery detection
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the verification system continuously queries the master ledger and local host log extensions to verify authentication objects. When a mismatch or forgery is detected, the system provides feedback by flagging the authentication attempt as suspicious and can trigger alerts or blocking actions. This stateful verification process maintains deterministic detection capability while preserving zero trust security architecture.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary verification system that acts as a mediator between authentication requests and network resource access. This intermediary queries both the master ledger and local host log extensions to verify authentication objects before granting access, providing deterministic detection of forgeries without requiring changes to the underlying zero trust security implementation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If authentication objects are tracked and verified in real-time across the network, then detection of forged authentications is improved, but resource strain on network assets increases

Engineering Contradiction:
Improveauthentication object verificationVSAvoidresource strain
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary actions by pre-storing authentication objects in the master ledger at domain controllers and maintaining local host log extensions at each host before authentication requests occur. When authentication requests are made, the verification system queries these pre-populated sources rather than generating or verifying authentication objects in real-time, significantly reducing computational resource strain during actual authentication operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates copies of authentication objects by storing them in both the master ledger at domain controllers and in local host log extensions at individual hosts. This copying strategy allows the verification system to query local copies first, reducing network traffic and centralized processing requirements, while maintaining the ability to verify authentication objects with high measurement precision.

Inventive Principle:
Principle #26Copying

4Ease of operation

If protocols like SAML, Kerberos, and OAuth2 are used for authentication, then single-sign-on capability is achieved, but vulnerabilities exist that are exploited by attackers for unauthorized access

Engineering Contradiction:
Improvesingle-sign-onVSAvoidauthentication vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing a verification system that proactively checks authentication objects against the master ledger and local host log extensions before attackers can exploit vulnerabilities in SAML, Kerberos, or OAuth2 protocols. This preliminary verification prevents unauthorized access by detecting forged authentication objects early in the authentication process, countering potential attacks before they can compromise single-sign-on functionality.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS12580898B2Master ledger and local host log extension detection and mitigation of forged authentication attacks
Publication Date: 2026.03.17 QOMPLX INC
  • US12580898B2 patent drawing
  • US12580898B2 patent drawing
  • US12580898B2 patent drawing

AI summary

A system and method for implementation of zero trust computer network security combined with stateful authentication object tracking, authentication object manipulation and forgery detection, and assessment of authentication and identity attack surface. The methodology involves gathering all authentication objects issued by a network, storing the authentication objects in a master ledger for use in stateful deterministic authentication object tracking, and running detection functions that compare authentication objects presented for access to network resources with the master ledger. In an embodiment, an authentication object agent is installed at the domain controller level. In another embodiment, a log extension utility is installed at the local host computer level to provide additional log data for additional cyberattack detections.