Blockchain Network Authentication for Decentralized Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional Authentication, Authorization, and Accounting (AAA) protocols rely on centralized data sources, which can be vulnerable and inefficient, lacking decentralized and secure methods for user authentication and authorization in network access.
Innovation Solution
The implementation of a decentralized approach using blockchain technology, where clients are authenticated using their blockchain addresses and authorized through smart contracts, allowing for secure and differentiated network access without requiring clients to carry out transactions on the blockchain for authentication, and enabling the use of pledged cryptocurrency for service levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized data sources are used for authentication and authorization, then the system is easier to manage and control, but the system becomes vulnerable to security breaches and single points of failure
Solution Approach 1:
The patent segments the centralized authentication system into a distributed blockchain network where authentication data is divided across multiple nodes. Each node maintains a copy of the authentication credentials, eliminating the single point of failure while maintaining system-wide security through cryptographic verification of segmented data portions.
Solution Approach 2:
The patent introduces smart contracts as intermediaries that mediate authentication and authorization operations between clients and the blockchain network. These self-executing contracts handle credential verification and access control logic, reducing direct reliance on centralized administrative systems while improving security through automated, transparent enforcement rules.
2Reliability
If decentralized blockchain technology is used for authentication, then security and resistance to single points of failure are improved, but system complexity and implementation difficulty increase
Solution Approach 1:
The patent implements a universal smart contract framework that handles multiple authentication and authorization functions through a single standardized interface. The smart contracts support various credential types, access control policies, and authorization scenarios using consistent deployment and execution mechanisms, reducing implementation complexity through multi-functional standardization.
Solution Approach 2:
The patent enables flexible parameter configuration in smart contracts for authentication thresholds, authorization levels, and access policies. By allowing parameters to be modified through contract updates rather than redeployment, the system adapts to changing security requirements while maintaining the same underlying blockchain infrastructure, reducing re-implementation complexity.
3Adaptability or versatility
If traditional AAA protocols are used, then compatibility with existing systems is maintained, but the system lacks flexibility for differentiated service levels and modern access control models
Solution Approach 1:
The patent implements dynamic authorization in smart contracts that can adjust access levels, service tiers, and permission scopes based on real-time conditions such as user credentials, service level agreements, and resource availability. This dynamic control enables differentiated service levels while maintaining security through automated enforcement of changing authorization policies without requiring protocol changes.
Data Source
AI summary
Some implementations of the disclosure are directed to receiving, at an authentication server system, a distributed ledger address transmitted by a client device to identify itself during an authentication process for accessing a network, where the distributed ledger address corresponds to a distributed ledger network; transmitting an authentication challenge message from the authentication server to the client device; in response to transmitting the authentication challenge message from the authentication server to the client device, receiving at the authentication server, a response to the challenge message including a signature; and using at least the distributed ledger network to determine if the signature used to sign the response to the challenge message is associated with the distributed ledger address transmitted by the client device.


