Decentralized Gateway Credential Validation for Cross-System Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity and access management systems in computer networks lack efficient, cost-effective, and versatile solutions for user authentication and authorization, particularly when managing access to multiple systems, often requiring extensive custom code and centralized credential management.

Innovation Solution

A decentralized gateway computing system that interacts with a distributed ledger to validate user credentials, supporting self-sovereign identity credentials, reducing the need for diverse protocols and enabling efficient, secure access management across networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing gateways are used for identity and access management, then basic traffic proxying is achieved, but authentication support is minimal or non-existent requiring extensive custom code

Engineering Contradiction:
Improveauthentication supportVSAvoidcustom code requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway is enhanced to perform multiple functions: it acts as both a traffic proxy and an authentication server. The gateway includes an authentication module that can independently handle user authentication requests, eliminating the need for extensive custom code while providing comprehensive authentication support including user verification, credential validation, and session management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines the authentication functionality with the gateway server, merging what were previously separate functions. The authentication module is integrated into the gateway, allowing it to handle both proxying and authentication in a unified system, reducing complexity while increasing versatility.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If centralized credential management is used, then access control is simplified, but managing permissions across multiple systems becomes inefficient

Engineering Contradiction:
Improvecross-system access management efficiencyVSAvoidmulti-system access capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The authentication module is designed to work with multiple identity and access management systems simultaneously. It can issue and validate credentials from different authorities, enabling users to access multiple systems through a single gateway without requiring separate credential management for each system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The gateway acts as an intermediary between users and multiple protected systems. It handles credential validation and permission checking centrally, mediating access requests to multiple different identity and access management systems, thereby simplifying cross-system access management while maintaining versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If servers handle user authentication directly, then authentication logic is simple, but gateway functionality is underutilized and security is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidgateway functionality
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway is transformed from a simple traffic proxy into a multi-functional security appliance. It includes authentication module, session management capabilities, and credential validation functionality, making it a comprehensive security gateway that enhances overall system security while utilizing gateway functionality fully.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12425407B2Identity and access management using a decentralized gateway computing system
Publication Date: 2025.09.23 THE BOEING CO
  • US12425407B2 patent drawing
  • US12425407B2 patent drawing
  • US12425407B2 patent drawing

AI summary

An example method is performed by one or more processors of a gateway computing system. The method includes receiving, from a user computing system, a request to access a software application hosted on a server with which the gateway computing system is in communication. The method also includes in response to receiving the request, communicating with the user computing system to obtain a credential for the software application issued to a user of the user computing system. The method also includes comparing the credential to credential data stored on a distributed ledger to determine whether the credential meets a set of conditions. The method also includes in response to determining that the credential meets the set of conditions, establishing an authorized session between the user computing system and the server such that communication between the user computing system and the server passes through the gateway computing system.