Blockchain Distributed Authentication for Data Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized trust-based security protocols in data storage systems are resource-intensive and vulnerable to attacks like spoofing and rollback, with traditional cryptosystems susceptible to processing power-based breaches.

Innovation Solution

A blockchain-based authentication mechanism that uses a decentralized, anonymous, and trustless network with a public ledger to validate transactions and ensure consensus among nodes, employing a lottery schema for block creation and validation, and a credit/debit system for managing access and operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized trust-based security protocols are used, then authentication can be performed, but the system becomes resource-intensive and vulnerable to attacks

Engineering Contradiction:
Improvesecurity authenticationVSAvoidsystem resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the centralized authentication system into a decentralized network of nodes that collectively perform security operations. Each node independently validates transactions and contributes to consensus, distributing the resource burden across multiple participants rather than concentrating it in a single centralized authority.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a block chain as an intermediary data structure that mediates between authentication requests and the distributed network. This block chain serves as a public ledger that records and validates security operations, eliminating the need for resource-intensive centralized trust verification while maintaining security integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized trust-based security protocols are used, then authentication can be performed, but the system becomes vulnerable to spoofing and rollback attacks

Engineering Contradiction:
Improvesecurity authenticationVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary anti-action by requiring consensus validation from multiple network nodes before any security operation is executed. This preemptive distributed verification prevents spoofing and rollback attacks by ensuring that no single entity can unilaterally compromise security, and all operations are recorded immutably in the block chain.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent establishes a feedback mechanism where the block chain publicly records all security operations and their validation status. This transparent ledger provides continuous feedback to the network, allowing nodes to verify the integrity of authentication operations and detect any attempted attacks, thereby enhancing system resilience against spoofing and rollback vulnerabilities.

Inventive Principle:
Principle #23Feedback

3Reliability

If traditional cryptosystems are used, then security operations can be performed, but the system is susceptible to processing power-based breaches

Engineering Contradiction:
Improvecryptographic securityVSAvoidprocessing requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cryptographic verification process across multiple distributed nodes in the network. Instead of requiring a single entity to perform all cryptographic operations, the workload is divided among nodes that collectively validate transactions, reducing the processing burden on any single device while maintaining strong cryptographic security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal block chain data structure that serves multiple functions: it records transactions, validates security operations, provides timestamps, and enables consensus verification. This multi-functional approach eliminates the need for separate complex cryptographic systems for each function, simplifying the overall processing requirements while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If decentralized blockchain authentication is used, then resistance to spoofing and rollback attacks is achieved, but processing requirements are distributed across the network

Engineering Contradiction:
Improveattack resistanceVSAvoiddistributed processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling each node in the decentralized network to independently validate transactions and contribute to consensus without requiring centralized coordination. Nodes autonomously verify block chain entries and security operations, reducing the complexity of centralized management while maintaining strong attack resistance through distributed verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11251975B1Block chain based trusted security infrastructure
Publication Date: 2022.02.15 SEAGATE TECH LLC
  • US11251975B1 patent drawing
  • US11251975B1 patent drawing
  • US11251975B1 patent drawing

AI summary

Apparatus and method for distributed authentication in a data storage system using block chain technology. In some embodiments, a requested transaction is generated to perform a selected security operation upon a data processing device in a computer network. The requested transaction is validated and propagated to a plurality of nodes. The nodes use a consensus mechanism to quasi-randomly select a particular node to generate a new block listing the requested transaction. The new block is validated, propagated among the plurality of nodes, and added to a block chain data structure. A processing node processes the requested transaction from the block chain data structure to authorize the selected security operation. Credits may be debited and credited between requesting nodes and the processing node for each transaction. Different types of credits may be used for different types of security operations.