Blockchain Client Certificate Authentication Federation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication federation systems require a central authority or third-party management, limiting distributed management among multiple organizations, which hampers convenience and efficiency in user authentication across multiple services.
Innovation Solution
An authentication system that utilizes a blockchain management unit to register and authenticate client certificates, enabling distributed management of user information across multiple organizations, allowing users to access services with a single authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a central authority or third-party manages the authentication federation system, then the system can operate with centralized control, but distributed management among multiple organizations cannot be achieved
Solution Approach 1:
The patent segments the authentication federation system into multiple independent authentication systems, each operated by different organizations. Each authentication system maintains its own user information and authentication capabilities, eliminating the need for a single central authority while enabling distributed management across multiple autonomous entities.
Solution Approach 2:
The patent creates a universal authentication framework where multiple authentication systems can interoperate through standardized protocols. The authentication information sharing mechanism enables any authentication system to verify user credentials from other organizations, providing multi-functional capability across the federation without requiring centralized control.
2Ease of operation
If multiple client certificates are issued for users across different organizations, then authentication can be performed for each service, but user convenience deteriorates
Solution Approach 1:
The patent merges multiple authentication credentials into a single client certificate that works across all participating organizations. The authentication information sharing mechanism allows one authenticated credential to be recognized by multiple authentication systems, eliminating the need for users to manage separate certificates for each organization or service.
Solution Approach 2:
The client certificate issued by any participating organization serves multiple functions across the entire authentication federation. A single certificate can be used to authenticate to services from multiple different organizations, providing universal access without requiring additional certificates for each service provider.
3Productivity
If authentication information is centrally managed by one organization, then authentication can be performed once for multiple services, but distributed management among multiple organizations is prevented
Solution Approach 1:
The patent segments the authentication management function across multiple independent organizations rather than concentrating it in one central authority. Each organization maintains its own authentication system and user information, yet all systems can相互 recognize and validate credentials through the sharing mechanism, achieving both distribution and efficiency.
Solution Approach 2:
The patent introduces an intermediary authentication information sharing mechanism that enables communication between independent authentication systems. This mediator layer allows any authentication system to verify credentials from other organizations without requiring direct central control, facilitating both distributed management and efficient single-sign-on functionality.
Data Source
AI summary
In an authentication system (120) of an organization that is another organization different from a first organization that a first user belongs to, a management device (200) accepts a registration transaction for a client certificate of the first user. Then, the management device registers the client certificate of the first user in a client certificate blockchain. When the first user accesses a service of another organization from a user terminal of the first organization, an authentication device (300) authenticates the first user using the client certificate of the first user in the client certificate blockchain.


