Blockchain-Based Login Delegation Using PKI Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional OAuth authentication methods are vulnerable to stolen user IDs and passwords, and require costly and inconvenient public certificates for enhanced security, lacking the security and usability provided by blockchain-based solutions.

Innovation Solution

A method utilizing a blockchain database for login delegation based on PKI, involving multi-signed signature verification, temporary IDs, and storing authentication results in a private/public blockchain to enhance security and usability, replacing conventional OAuth protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional public certificates are used for enhanced security, then security is improved, but cost and usability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent uses blockchain copies of certificate data instead of original public certificates. The authentication server stores hash values of certificates in the blockchain, allowing verification through cryptographic copying without requiring expensive physical certificate management infrastructure.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical certificate verification system with a cryptographic blockchain-based system. Instead of physical certificate exchanges and manual verification processes, the system uses distributed ledger technology with cryptographic hashing and consensus mechanisms to verify authentication data.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If conventional public certificates are used for enhanced security, then security is improved, but usability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The blockchain network performs automatic verification of authentication data through its consensus mechanism. The system self-validates certificate integrity and authenticity without requiring manual intervention from users or administrators, improving usability while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The blockchain-based authentication system serves multiple functions: it stores certificate hashes, verifies authentication data, maintains audit trails, and enables cross-service recognition. This multi-functional approach consolidates what would otherwise require separate systems, improving overall usability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If basic authentication (ID and password) is used, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into multiple independent verification stages: initial login verification, blockchain-based certificate validation, and multi-factor authentication checks. This segmentation allows the system to maintain user-friendly interfaces while implementing layered security measures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The blockchain acts as an intermediary between the user and the authentication server. It mediates the verification process by providing a trusted, decentralized record of certificate validity, enabling strong security without requiring users to directly manage complex cryptographic keys or certificate files.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If OAuth 2.0 protocol is used for login delegation, then adaptability is improved, but security deteriorates due to vulnerability to stolen credentials

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary verification of authentication data against the blockchain-stored certificate hashes before granting access tokens. This preliminary action ensures that even if credentials are stolen during OAuth flow, the blockchain verification will detect the invalidity, preventing unauthorized access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The blockchain provides continuous feedback on certificate validity to the authentication server. When verifying OAuth tokens, the server queries the blockchain for current certificate status, receiving real-time feedback on whether the associated credentials are still valid, thereby detecting stolen credentials even after initial authentication.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10659236B2Method for superseding log-in of user through PKI-based authentication by using blockchain database of UTXO-based protocol, and server employing same
Publication Date: 2020.05.19 CPLABS INC
  • US10659236B2 patent drawing
  • US10659236B2 patent drawing
  • US10659236B2 patent drawing

AI summary

The present disclosure provides a method for superseding a log-in through PKI-based authentication with respect to a log-in request of a user by using a blockchain database. According to the method, once authentication request information requesting superseding of a log-in through an authentication app is obtained from a service provision app executed on a user terminal, a service provision server transfers authentication request response information to the service provision app and, after an authentication redirection request thereof is transferred to the authentication app and then server challenge request information is obtained, server challenge request response information is transferred to the authentication app, an authentication result message including information on whether certificates of the server and the app are valid is obtained from an authentication server, a predetermined access token is transferred to the service provision app, and thereby the log-in is handled such that a service can be used.