Distributed Identity Authorization via Dynamic Credibility Scores
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems are vulnerable to credential harvesting and require users to manage multiple passwords, lacking efficient passwordless and distributed authentication solutions, especially in large networks like IoT sensors, which need granular, policy-based authorization.
Innovation Solution
A distributed ledger system, such as blockchain, is used to store credibility scores based on user interactions across multiple sensors, allowing authorization without traditional credentials by calculating a dynamic credibility score through consensus among verification services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a centralized credential repository is used for authentication, then usability is improved through single sign-on, but security deteriorates due to vulnerability to credential harvesting attacks
Solution Approach 1:
The patent divides the centralized credential repository into distributed verification services across multiple independent nodes. Each node maintains its own copy of verification data, eliminating the single point of failure. When authentication is needed, requests are distributed to multiple verification services that independently evaluate credentials, preventing credential harvesting attacks while maintaining single sign-on usability.
Solution Approach 2:
The patent introduces a distributed ledger as an intermediary between users and verification services. The ledger stores verification data in a decentralized manner, with each verification service maintaining a copy. This intermediary layer enables authentication without requiring direct access to a centralized database, thus improving security while preserving usability through distributed verification.
2Reliability
If multiple distributed verification services are used for authentication, then security is improved by eliminating single-point vulnerabilities, but device complexity increases
Solution Approach 1:
The patent merges multiple distributed verification services into a unified authentication system that operates through a common distributed ledger. All verification services share the same ledger structure and authentication protocols, allowing them to function independently yet cooperatively. This merging approach improves security through distribution while managing complexity by establishing standardized interfaces and shared data structures.
Solution Approach 2:
The patent creates a universal authentication framework where the distributed ledger serves multiple verification services simultaneously. The same ledger infrastructure supports various verification services with different credential types and verification logic, allowing a single system to handle multiple authentication scenarios without proportionally increasing complexity.
3Ease of operation
If traditional password-based authentication is used, then ease of operation is maintained with familiar login methods, but security deteriorates due to credential storage vulnerabilities
Solution Approach 1:
The patent extracts authentication credentials from traditional password-based systems and stores them in the distributed ledger as verification data. Instead of storing passwords in centralized databases or on user devices, the system extracts and stores only the necessary verification information in the decentralized ledger, eliminating vulnerabilities associated with credential storage while maintaining authentication functionality.
Solution Approach 2:
The patent implements self-service authentication where users authenticate themselves through the distributed verification services without requiring manual password entry or credential management. The system automatically retrieves verification data from the distributed ledger and performs authentication decisions, eliminating the need for users to manage passwords while maintaining convenient authentication access.
4Measurement precision
If granular policy-based authorization is implemented for IoT sensors, then access control precision is improved, but device complexity increases
Solution Approach 1:
The patent implements dynamic authorization where access control decisions are made in real-time based on current sensor data, device state, and policy rules stored in the distributed ledger. Rather than static access control lists, the system dynamically evaluates each authentication request against current conditions, enabling granular policy-based authorization that adapts to changing circumstances without requiring complex predetermined access control structures.
Solution Approach 2:
The patent changes the parameters of authorization from static permissions to dynamic credibility scores. Instead of fixed access control lists, the system uses continuously updated credibility scores that reflect device behavior, trust levels, and policy compliance. This parameter transformation enables granular policy-based authorization where access decisions are based on nuanced, real-time assessments rather than rigid predetermined rules.
Data Source
AI summary
Techniques include receiving, at a sensor, a request for authentication of an identity; determining, based on a distributed ledger, a dynamic credibility score for the identity; determining whether the dynamic credibility score for the identity can be validated by consensus by at least a subset of distributed verification services, based on whether the dynamic credibility score for the identity is within a range of variance from one or more credibility scores for the identity determined by the subset of the plurality of distributed verification services; and determining, based on whether the dynamic credibility score for the identity can be validated by consensus, whether to authorize the identity to perform the action in the blockchain network.


