Blockchain Authentication Token Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital certificate systems face issues of high costs, security vulnerabilities, and limited usability due to the need for ActiveX controls and centralized management, which can lead to financial damages and restricted browser compatibility.

Innovation Solution

A blockchain-based authentication information system that generates and manages public and private keys on a user device, storing them in an e-wallet within a distributed database, eliminating the need for ActiveX controls and allowing compatibility with various web browsers, while using a peer-to-peer network for secure key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates are used with ActiveX controls for user authentication, then security is improved, but device complexity and ease of operation deteriorate due to mandatory installation requirements and browser compatibility issues

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from the browser environment and ActiveX controls, moving it to a standalone token device. The token generates and stores cryptographic keys independently, eliminating the need for browser plugins while maintaining security through hardware-based key protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a token device as an intermediary between the user and the authentication system. This token acts as a mediator that handles key generation, storage, and cryptographic operations, freeing the browser from security-critical functions and improving both security and compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If ActiveX controls are installed for digital certificate authentication, then authentication security is improved, but ease of operation worsens due to lowered PC security levels and vulnerability to hacking

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The token device performs self-service by autonomously generating and managing cryptographic keys without requiring user intervention for security-sensitive operations. The device handles key protection and authentication internally, eliminating the need for users to lower their PC security settings or install vulnerable ActiveX controls.

Inventive Principle:
Principle #25Self-service

3Reliability

If centralized digital certificate issuing systems are implemented, then authentication reliability is improved, but cost increases due to advanced security systems and operational maintenance requirements

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent uses cryptographic key pairs as digital copies that can be replicated and distributed without compromising security. Each user receives their own private key on a token device, and the corresponding public key is registered with service providers, eliminating the need for expensive centralized certificate authorities while maintaining authentication reliability.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11514440B2Method for issuing authentication information and blockchain-based server using the same
Publication Date: 2022.11.29 CPLABS INC
  • US11514440B2 patent drawing
  • US11514440B2 patent drawing
  • US11514440B2 patent drawing

AI summary

A method for issuing authentication information is provided. The method includes steps of: (a) a managing server, if identification information of a specific user is acquired from a user device in response to a request for issuing the authentication information and the identification information is determined to be registered, creating a transaction whose output includes: (i) the specific user's public key and (ii) a hash value of the identification information or its processed value to thereby record or support other device to record it on a blockchain; and (b) the managing server acquiring a transaction ID representing location information of the transaction recorded on the blockchain.