Browser Authentication Using DNS Identity Records and Digital Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing password-based and centralized authentication schemes are vulnerable to attacks, lead to password fatigue, and lack universality and privacy, while decentralized alternatives suffer from centralization issues and fragmentation.
Innovation Solution
A browser-based decentralized authentication scheme using zero-knowledge proofs and asymmetric cryptography, allowing users to authenticate through their web browser without a central authority, enabling device-based authentication, secure end-to-end encryption, and decentralized identity management using domain name system records.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If password-based authentication is used, then implementation simplicity is improved, but security is worsened
Solution Approach 1:
The patent replaces the mechanical/password-based authentication system with a cryptographic system using asymmetric cryptography. The authentication provider application generates cryptographic key pairs and uses digital signatures to verify user identity, substituting the manual password verification mechanism with automated cryptographic verification that is both secure and simple to implement.
Solution Approach 2:
The patent introduces an authentication provider application as an intermediary between the user and the service provider. This intermediary handles the cryptographic operations, key management, and authentication verification, simplifying the implementation for both users and service providers while maintaining high security through standardized cryptographic protocols.
2Ease of operation
If centralized authentication schemes are used, then ease of operation is improved, but security and privacy are worsened
Solution Approach 1:
The patent segments the centralized authentication authority into distributed authentication provider applications that run locally on user devices. Each authentication provider instance operates independently, eliminating the single point of failure and centralization risks while maintaining ease of operation through standardized authentication flows.
Solution Approach 2:
The authentication provider application performs self-service by generating its own cryptographic key pairs, managing its own authentication credentials, and verifying user identity locally without requiring a central authentication server. This self-service capability maintains operational simplicity while eliminating centralization security risks.
3Reliability
If decentralized authentication is used, then security is improved, but device complexity is worsened
Solution Approach 1:
The authentication provider application is designed as a universal, multi-functional component that can be deployed across different devices and platforms. It provides key generation, signature verification, and authentication management in a single standardized package, reducing device complexity through reuse rather than requiring custom implementations.
Solution Approach 2:
The patent changes the parameters of authentication from human-managed passwords to machine-generated cryptographic keys and signatures. This parameter change automates complex security operations, reducing the apparent device complexity while maintaining high security through cryptographic mechanisms.
4Ease of operation
If social login is used, then ease of operation is improved, but centralization and privacy are worsened
Solution Approach 1:
The patent inverts the traditional social login model where users depend on third-party providers. Instead, users run their own authentication provider applications that they control, reversing the dependency relationship and eliminating centralization while maintaining the convenience of single-sign-on-like functionality.
Data Source
AI summary
Disclosed herein is a method performed by a client application of an authentication provider application. The method includes deriving a reference to a domain name based on an identity handle of a user, querying a domain name system to obtain one or more identity records associated with the identity handle, obtaining one or more public keys based on the one or more identity records, and deriving an authentication endpoint web address based on the identity handle. The authentication endpoint web address is usable to access the authentication provider application. The method further includes sending data to the authentication provider application using the authentication endpoint web address, wherein the authentication provider application is able to access one or more private keys corresponding to the one or more public keys for generating digital signatures. The method further includes receiving, from the authentication provider application, one or more digital signatures.


