Blockchain Authentication System Resolving Security-Convenience Trade-off

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication (MFA) systems for online non-face-to-face transactions face challenges such as data breaches, inability to authenticate clients with full confidence, vulnerability to man-in-the-middle attacks, and the need for physical presence for transaction execution, which compromises security and convenience.

Innovation Solution

The use of Blockchain technology, Digital Certificates, and live video clips, combined with Biometric and Biographical data, to create a secure authentication process through the Data Analytics Authentication Processor (DAAP), ensuring data immutability and integrity, and enabling machine-to-machine transactions without human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If multi-factor authentication systems are used for online non-face-to-face transactions, then transaction convenience is improved, but security and reliability deteriorate due to data breaches and man-in-the-middle attacks

Engineering Contradiction:
Improvetransaction convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent verification components: biometric data verification, biographical data verification, blockchain transaction verification, and digital certificate verification. Each component operates independently and contributes to the overall authentication decision, preventing single-point failures and enhancing security without compromising convenience

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted third-party verification system is introduced as an intermediary between the client and service provider. This intermediary uses blockchain technology and digital certificates to mediate the authentication process, verifying client identity without requiring physical presence while maintaining high security standards through multiple verification layers

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical presence is required for transaction execution, then authentication reliability is improved, but transaction convenience and speed deteriorate

Engineering Contradiction:
Improveauthentication confidenceVSAvoidtransaction convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mechanical requirement of physical presence is replaced with electronic verification mechanisms. Biometric data (fingerprint, facial recognition), digital signatures, and blockchain-verified credentials substitute for physical appearance, maintaining authentication reliability while enabling remote non-face-to-face transactions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication parameters are changed from physical presence verification to digital credential verification. The system verifies identity through biometric templates, cryptographic signatures, and blockchain-recorded credentials rather than requiring the client's physical appearance, thus maintaining security while enabling remote transactions

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If traditional data storage methods are used, then system simplicity is maintained, but data security and integrity deteriorate due to vulnerabilities to hacking and data breaches

Engineering Contradiction:
Improvesystem simplicityVSAvoiddata breach vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system transitions from traditional single-dimension data storage to multi-dimensional verification by integrating blockchain technology. Client credentials are stored and verified across distributed blockchain ledgers, adding a new dimension of security through cryptographic hashing and distributed consensus, which prevents hacking and data breaches while maintaining operational simplicity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10810290B2Robust method and an apparatus for authenticating a client in non-face-to-face online interactions based on a combination of live biometrics, biographical data, blockchain transactions and signed digital certificates
Publication Date: 2020.10.20 NTAKE PASTEUR DR
  • US10810290B2 patent drawing
  • US10810290B2 patent drawing

AI summary

This invention describes a method, and an apparatus for identifying and authenticating an Individual Client (IC), or a Secure-Computing-Device online while ensuring the privacy of the IC's personal data, (IPD), and information against identity theft and fraud by using a combination of prior art Blockchain technology, public key cryptography, and a newly created Biometric Digital Certificate issued by an accredited Biometric Certification Authority. The IC's transactions data are dynamically updated, cryptographically signed for integrity and stored in an immutable blockchain each time the IC requests service from a Service Provider and provides an accurate and traceable audit trail. During online access, the IC transactions data stored in the Blockchain Databases are processed by a Data Analytics Authentication Processor to generate the Service-Access-Authentication-Tag, which is an algorithmic score that determines the IC's eligibility to access online services offered by a plurality of Services Providers.