Blockchain Client Certificate Authentication Federation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication federation systems require a central authority or third-party management, limiting distributed management among multiple organizations, which hampers convenience and efficiency in user authentication across multiple services.

Innovation Solution

An authentication system that utilizes a blockchain management unit to register and authenticate client certificates, enabling distributed management of user information across multiple organizations, allowing users to access services with a single authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a central authority or third-party manages the authentication federation system, then the system can operate with centralized control, but distributed management among multiple organizations cannot be achieved

Engineering Contradiction:
Improvedistributed management capabilityVSAvoidsystem management structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication federation system into multiple independent authentication systems, each operated by different organizations. Each authentication system maintains its own user information and authentication capabilities, eliminating the need for a single central authority while enabling distributed management across multiple autonomous entities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal authentication framework where multiple authentication systems can interoperate through standardized protocols. The authentication information sharing mechanism enables any authentication system to verify user credentials from other organizations, providing multi-functional capability across the federation without requiring centralized control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If multiple client certificates are issued for users across different organizations, then authentication can be performed for each service, but user convenience deteriorates

Engineering Contradiction:
Improveuser authentication convenienceVSAvoidnumber of client certificates
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent merges multiple authentication credentials into a single client certificate that works across all participating organizations. The authentication information sharing mechanism allows one authenticated credential to be recognized by multiple authentication systems, eliminating the need for users to manage separate certificates for each organization or service.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The client certificate issued by any participating organization serves multiple functions across the entire authentication federation. A single certificate can be used to authenticate to services from multiple different organizations, providing universal access without requiring additional certificates for each service provider.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If authentication information is centrally managed by one organization, then authentication can be performed once for multiple services, but distributed management among multiple organizations is prevented

Engineering Contradiction:
Improveauthentication efficiencyVSAvoiddistributed organizational management
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication management function across multiple independent organizations rather than concentrating it in one central authority. Each organization maintains its own authentication system and user information, yet all systems can相互 recognize and validate credentials through the sharing mechanism, achieving both distribution and efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication information sharing mechanism that enables communication between independent authentication systems. This mediator layer allows any authentication system to verify credentials from other organizations without requiring direct central control, facilitating both distributed management and efficient single-sign-on functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11652647B2Authentication system and computer readable medium
Publication Date: 2023.05.16 MITSUBISHI ELECTRIC CORP
  • US11652647B2 patent drawing
  • US11652647B2 patent drawing
  • US11652647B2 patent drawing

AI summary

In an authentication system (120) of an organization that is another organization different from a first organization that a first user belongs to, a management device (200) accepts a registration transaction for a client certificate of the first user. Then, the management device registers the client certificate of the first user in a client certificate blockchain. When the first user accesses a service of another organization from a user terminal of the first organization, an authentication device (300) authenticates the first user using the client certificate of the first user in the client certificate blockchain.