Progressive User Authentication Using Blockchain Trust Events
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems face challenges in effectively managing user trust levels, leading to either excessive authentication requirements deterring users or insufficient security allowing unauthorized access, thereby compromising organizational integrity.
Innovation Solution
An authentication system that utilizes a blockchain-based database to record user trust events, incrementally elevating trust levels based on successful operations, and generates authentication metrics using cryptographic signatures to ensure secure and progressive user authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple authentication requirements are implemented, then security is improved, but user experience deteriorates
Solution Approach 1:
The authentication system dynamically adjusts authentication requirements based on the user's trust level. New users undergo stricter authentication while established users experience simplified authentication flows. This dynamic adaptation resolves the contradiction by making security requirements flexible rather than fixed, allowing the system to optimize between security and ease of operation for each user context.
Solution Approach 2:
The system changes authentication parameters (such as required verification steps, authentication methods, and security questions) based on the trust level parameter. By modifying these parameters according to the user's historical behavior and trust score, the system achieves both high security for unknown users and high ease of operation for trusted users, resolving the technical contradiction.
2Ease of operation
If authentication requirements are reduced, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The system dynamically adjusts authentication requirements based on the user's trust level. New users undergo stricter authentication while established users experience simplified authentication flows. This dynamic adaptation resolves the contradiction by making security requirements flexible rather than fixed, allowing the system to optimize between security and ease of operation for each user context.
Solution Approach 2:
The system uses feedback from user authentication history to adjust future authentication requirements. Successful authentication patterns build trust levels that reduce future authentication friction, while failed attempts increase security requirements. This feedback mechanism ensures ease of operation for legitimate users while maintaining security against bad actors.
3Productivity
If trust level is elevated quickly, then productivity is improved, but reliability deteriorates
Solution Approach 1:
The system performs preliminary authentication actions and records them in a database before fully elevating trust. These preliminary trust events accumulate to build a foundation of verified user behavior, allowing the system to elevate trust levels productively while maintaining reliability through accumulated evidence rather than rapid assumptions.
Solution Approach 2:
The system continuously monitors and records user authentication events, building trust levels through continuous verification rather than one-time judgments. This continuous action allows for progressive trust elevation that maintains both speed (through accumulated data) and reliability (through ongoing verification).
Data Source
AI summary
Systems and methods are described herein for handling authentication by elevating a user's authentication level as the user performs more operations. An authentication system may receive a first request for a first database operation. The first database operation may include first trust event data for a first trust event associated with a user to be written to a database. For example, a trust event may be a user completing some type of operation successfully. In some embodiments, the operation may be in relation to a third party. A successful operation may then be recorded in the database. As a result of the successful operation, when a trust level is calculated for the user, the trust level may be increased due to the successful operation.


