Blockchain Cross-Entity Authentication via Decentralized Identifiers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional identity management systems face security risks, inefficiencies, and user-unfriendliness due to centralized authority reliance, especially in cross-entity authentication, which lacks a common protocol for secure information sharing and is vulnerable to privacy leaks and complex authorization processes.
Innovation Solution
A blockchain-based system for cross-entity authentication that uses decentralized identifiers (DIDs) and verifiable claims (VCs) to enable secure, efficient, and scalable authentication by allowing entities to access authentication information stored on the blockchain, reducing reliance on centralized authorities and enhancing user control over their identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized authorities are used to manage identity data, then identity management can be centralized and controlled, but security risks increase and user control over identities is lost
Solution Approach 1:
The patent segments the centralized identity management system into distributed components. Identity data is divided into verifiable claims that can be independently verified, and the system architecture is split across multiple decentralized entities (blockchain nodes, issuers, holders) rather than relying on a single centralized authority. This segmentation eliminates the single point of failure while maintaining identity management functionality.
Solution Approach 2:
The patent introduces blockchain technology as an intermediary layer between identity issuers and holders. The blockchain serves as a trusted mediator that enables verification of identity claims without requiring direct trust between parties or reliance on centralized authorities. Smart contracts act as automated intermediaries that enforce verification rules and facilitate cross-entity authentication.
2Adaptability or versatility
If cross-entity authentication is implemented without a common protocol, then different authorities can maintain their own systems, but information sharing becomes insecure and privacy leakage occurs
Solution Approach 1:
The patent creates a universal verification mechanism using standardized verifiable claims and blockchain-based authentication protocols. These protocols can be applied across different entities and use cases (access control, authentication, credential verification) providing a multi-functional solution that enables secure cross-entity authentication without requiring entities to adopt proprietary or incompatible systems.
Solution Approach 2:
The patent changes the fundamental parameters of authentication by transitioning from centralized database-based verification to blockchain-based cryptographic verification. This involves changing from trusting centralized authorities to trusting decentralized consensus mechanisms, and from sharing raw identity data to sharing verified cryptographic proofs, thereby improving security while enabling cross-entity authentication.
3Ease of manufacture
If traditional centralized systems are used for identity management, then implementation is straightforward, but the systems are user-unfriendly and inefficient for cross-entity authentication
Solution Approach 1:
The patent empowers users to self-manage their own identity data through cryptographic key pairs. Users can generate, store, and control their own verifiable claims without requiring centralized account management. This self-service approach gives users direct control over their identities while simplifying cross-entity authentication, as users can present verified credentials directly to any entity that accepts the standardized format.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for blockchain-based cross-entity authentication are provided. One of the methods includes: obtaining, from a blockchain, a blockchain transaction comprising an authentication request by a first entity for authenticating a user, wherein the authentication request comprises a decentralized identifier (DID) of the user; in response to determining that the first entity is permitted to access authentication information of the user endorsed by a second entity, obtaining an authentication result of the user by the second entity in response to the obtained blockchain transaction, wherein the authentication result is associated with the DID; generating a different blockchain transaction comprising the authentication result; and transmitting the different blockchain transaction to a blockchain node for adding to the blockchain.


