Blockchain Authentication System Replacing ActiveX Controls
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital certificate systems face issues of high costs, security vulnerabilities, and limited usability due to the need for ActiveX controls and compatibility only with Internet Explorer, making them prone to theft and hacking, and restrictive in use across various web browsers.
Innovation Solution
A blockchain-based authentication system that manages authentication information using a public key included in a blockchain transaction, where a hash value of user identification information is verified against a pre-stored hash value, allowing for secure and cost-effective user authentication without the need for ActiveX controls and supporting multiple web browsers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital certificate systems use ActiveX controls for authentication, then security is improved, but compatibility with web browsers deteriorates and device complexity increases
Solution Approach 1:
The patent replaces the ActiveX control mechanism (mechanical/software system) with a blockchain-based authentication system using public keys. Instead of requiring ActiveX controls to be installed in browsers, the system uses cryptographic key pairs stored in smart contracts on the blockchain, making it compatible with all modern web browsers without additional plugins or controls.
Solution Approach 2:
The blockchain-based authentication system provides universal compatibility across different web browsers (Internet Explorer, Chrome, Firefox, Safari, etc.) while maintaining security functions. The smart contract on the blockchain serves multiple purposes: storing public keys, verifying authentication, and managing certificate validity, replacing the need for browser-specific ActiveX controls.
2Reliability
If digital certificate systems implement advanced security systems to prevent hacking, then security is improved, but cost increases
Solution Approach 1:
The blockchain system provides self-service security through decentralized verification. The smart contract automatically verifies authentication requests using stored public keys and transaction records, eliminating the need for expensive centralized security infrastructure, manual certificate management, and advanced security systems that require ongoing maintenance and operation costs.
Solution Approach 2:
The system uses cryptographic public keys as copies of authentication credentials that can be freely distributed and verified without compromising security. Multiple copies of the public key can be stored in smart contracts and verified by any participant in the network, replacing expensive centralized certificate authorities and security verification systems.
3Ease of operation
If private key files are stored in standardized locations for ease of access, then ease of operation is improved, but security deteriorates due to easy copying and theft
Solution Approach 1:
Instead of storing and protecting private keys (which are vulnerable to theft), the system inverts the approach by storing only public keys in the blockchain smart contract. The private key remains exclusively on the user's device and never leaves it. Authentication is performed by proving knowledge of the private key through digital signatures without transmitting the key itself, thus maintaining both accessibility and security.
4Reliability
If authentication systems require installation of browser-specific controls, then security is improved, but device complexity and ease of operation worsen
Solution Approach 1:
The patent replaces the ActiveX control installation mechanism with a blockchain-based cryptographic system. The smart contract on the blockchain stores public keys and handles verification, eliminating the need for browser-specific controls, plugins, or additional software installations. This reduces device complexity while maintaining security through cryptographic verification.
Data Source
AI summary
A method for using authentication information is provided. The method includes steps of: (a) a managing server, if a request for using the authentication information is acquired, acquiring a transaction ID corresponding to a specific user's identification information; (b) the managing server acquiring an output of a specific transaction corresponding to the transaction ID from a blockchain; (c) the managing server determining revocation of the authentication information by referring to the output of the specific transaction; and (d) the managing server supporting a communication by providing the specific user's public key in the output of the specific transaction, if the authentication information is not revoked, and if (i) a hash value of the specific user's identification information included in the output of the specific transaction or its processed value corresponds to (ii) a hash value of the specific user's identification information pre-stored in a certain database or its processed value.


