Decentralized Identity Authentication via Blockchain Ledger

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods rely on centralized management, posing security risks due to exposed IDs and passwords, and are inflexible and complex to implement across multiple organizations or communities.

Innovation Solution

A decentralized and self-sovereign identity authentication system using blockchain technology, where digital certificates with verifiable credentials are validated through a blockchain ledger network, enabling authorization without central governance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized authentication management is used, then authentication can be controlled by a single authority, but security risks increase due to exposed credentials and privacy concerns

Engineering Contradiction:
Improveauthentication securityVSAvoidcredential exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts authentication credentials from centralized databases and distributes them to individual users via digital wallets. Each user holds their own verifiable credentials independently, eliminating the central database that stores all credentials. This extraction of credential storage from central authority directly addresses the security risk of credential exposure while maintaining authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system enables users to manage their own authentication credentials through self-sovereign identity. Users control their digital wallets and credentials independently without requiring central authority intervention for authentication decisions. This self-service approach eliminates the need for centralized credential management, reducing security risks associated with central database breaches.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If centralized credential management is implemented, then authentication control is simplified, but system complexity increases when implementing across multiple organizations

Engineering Contradiction:
Improveauthentication managementVSAvoidmulti-organization implementation complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework where verifiable credentials can be issued and validated across multiple different organizations and systems. The standardized protocol allows any organization to issue credentials that can be validated by any other organization, eliminating the need for separate authentication systems for each organization. This multi-functionality directly reduces implementation complexity across multi-organization environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces verifiable credentials as an intermediary layer between authentication authorities and resource systems. Instead of direct point-to-point authentication integrations between multiple organizations, the verifiable credential acts as a universal mediator that standardizes communication. This intermediary mechanism simplifies multi-organization implementation by providing a common protocol layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If traditional authentication systems are used, then existing infrastructure can be leveraged, but flexibility and adaptability are reduced across different organizations

Engineering Contradiction:
Improvecross-organization flexibilityVSAvoidsystem implementation ease
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements dynamic authentication where verifiable credentials can be issued, validated, and revoked in real-time based on current policies and conditions. The system allows for dynamic credential issuance without requiring system reconfiguration, enabling flexible adaptation to changing organizational requirements. This dynamic capability provides cross-organization flexibility while maintaining implementation ease through standardized protocols.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250184320A1Consortium-based infrastructure and platform for user authentication
Publication Date: 2025.06.05 KYNDRYL INC
  • US20250184320A1 patent drawing
  • US20250184320A1 patent drawing
  • US20250184320A1 patent drawing

AI summary

In an aspect of the disclosure, a method includes: obtaining, by a computing device, a user request to access at least one system resource; obtaining, by the computing device, a digital certificate of the user requesting access to the at least one system resource; obtaining, by the computing device, a validation result associated with the digital certificate from a blockchain ledger network; determining, by the computing device, whether the validation result authorizes access to an authorization service; and sending the authorization to the authorization service to deny or permit the user access to the at least one system resource based on the validation result.