Distributed Identity Authorization via Dynamic Credibility Scores

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems are vulnerable to credential harvesting and require users to manage multiple passwords, lacking efficient passwordless and distributed authentication solutions, especially in large networks like IoT sensors, which need granular, policy-based authorization.

Innovation Solution

A distributed ledger system, such as blockchain, is used to store credibility scores based on user interactions across multiple sensors, allowing authorization without traditional credentials by calculating a dynamic credibility score through consensus among verification services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized credential repository is used for authentication, then usability is improved through single sign-on, but security deteriorates due to vulnerability to credential harvesting attacks

Engineering Contradiction:
ImproveusabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the centralized credential repository into distributed verification services across multiple independent nodes. Each node maintains its own copy of verification data, eliminating the single point of failure. When authentication is needed, requests are distributed to multiple verification services that independently evaluate credentials, preventing credential harvesting attacks while maintaining single sign-on usability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a distributed ledger as an intermediary between users and verification services. The ledger stores verification data in a decentralized manner, with each verification service maintaining a copy. This intermediary layer enables authentication without requiring direct access to a centralized database, thus improving security while preserving usability through distributed verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple distributed verification services are used for authentication, then security is improved by eliminating single-point vulnerabilities, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple distributed verification services into a unified authentication system that operates through a common distributed ledger. All verification services share the same ledger structure and authentication protocols, allowing them to function independently yet cooperatively. This merging approach improves security through distribution while managing complexity by establishing standardized interfaces and shared data structures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal authentication framework where the distributed ledger serves multiple verification services simultaneously. The same ledger infrastructure supports various verification services with different credential types and verification logic, allowing a single system to handle multiple authentication scenarios without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If traditional password-based authentication is used, then ease of operation is maintained with familiar login methods, but security deteriorates due to credential storage vulnerabilities

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts authentication credentials from traditional password-based systems and stores them in the distributed ledger as verification data. Instead of storing passwords in centralized databases or on user devices, the system extracts and stores only the necessary verification information in the decentralized ledger, eliminating vulnerabilities associated with credential storage while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements self-service authentication where users authenticate themselves through the distributed verification services without requiring manual password entry or credential management. The system automatically retrieves verification data from the distributed ledger and performs authentication decisions, eliminating the need for users to manage passwords while maintaining convenient authentication access.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If granular policy-based authorization is implemented for IoT sensors, then access control precision is improved, but device complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidauthorization system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements dynamic authorization where access control decisions are made in real-time based on current sensor data, device state, and policy rules stored in the distributed ledger. Rather than static access control lists, the system dynamically evaluates each authentication request against current conditions, enabling granular policy-based authorization that adapts to changing circumstances without requiring complex predetermined access control structures.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of authorization from static permissions to dynamic credibility scores. Instead of fixed access control lists, the system uses continuously updated credibility scores that reflect device behavior, trust levels, and policy compliance. This parameter transformation enables granular policy-based authorization where access decisions are based on nuanced, real-time assessments rather than rigid predetermined rules.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10440028B1Distributed authorization of identities in a dynamic connected environment
Publication Date: 2019.10.08 CYBER ARK SOFTWARE LTD
  • US10440028B1 patent drawing
  • US10440028B1 patent drawing
  • US10440028B1 patent drawing

AI summary

Techniques include receiving, at a sensor, a request for authentication of an identity; determining, based on a distributed ledger, a dynamic credibility score for the identity; determining whether the dynamic credibility score for the identity can be validated by consensus by at least a subset of distributed verification services, based on whether the dynamic credibility score for the identity is within a range of variance from one or more credibility scores for the identity determined by the subset of the plurality of distributed verification services; and determining, based on whether the dynamic credibility score for the identity can be validated by consensus, whether to authorize the identity to perform the action in the blockchain network.