FIDO Universal Authentication via Blockchain Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods based on IDs and passwords are vulnerable to security threats, requiring users to manage multiple complex passwords across various services, leading to inconvenience and increased security risks due to repeated registration processes, especially when sharing authentication information between different domains.

Innovation Solution

Implementing a method that uses FIDO universal authentication with a blockchain to securely share and manage user authentication information across multiple domains without the need for a trusted third party, allowing users to perform FIDO registration and authentication seamlessly across various services using a blockchain identifier and public key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If FIDO authentication device is registered in each application service server, then authentication security is improved, but device complexity and registration process burden increase

Engineering Contradiction:
Improveauthentication securityVSAvoidregistration process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted third party server that mediates between multiple application service servers and the user's FIDO authentication device. This intermediary manages the public keys and authentication information centrally, allowing the user to register once with the trusted third party rather than with each individual service. The trusted third party then facilitates authentication across multiple domains, reducing the registration burden while maintaining security through centralized key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trusted third party server provides universal authentication functionality across multiple application services and domains. Instead of requiring separate FIDO device registrations for each service, the system enables a single FIDO device to authenticate across multiple services through the trusted third party's coordination. This multi-functional approach allows one authentication mechanism to serve multiple purposes and services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple private keys are stored in FIDO authentication device for different services, then authentication capability across services is improved, but storage requirements and management complexity increase

Engineering Contradiction:
Improveauthentication capability across servicesVSAvoidnumber of private keys to store
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The trusted third party server acts as an intermediary that stores and manages the public keys corresponding to the user's private keys. Instead of requiring the user's FIDO device to store multiple private keys for different services, the system stores the necessary public key information centrally at the trusted third party. This reduces the storage burden on the user's device while maintaining the ability to authenticate across multiple services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses public keys as copies or representations of the authentication credentials, which can be stored and shared across multiple services without exposing the actual private keys. The trusted third party stores public key information that can be used by multiple application services to verify authentication, eliminating the need to store multiple private key copies in the user's device.

Inventive Principle:
Principle #26Copying

3Reliability

If FIDO registration process is performed for each application service, then service-specific authentication security is improved, but user convenience and time efficiency deteriorate

Engineering Contradiction:
Improveservice-specific authentication securityVSAvoidtime for repeated registration processes
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication setup through a single registration process with the trusted third party server. During this initial action, the user's FIDO device is registered and public keys are established once. This preliminary setup enables subsequent authentication across multiple services without requiring repeated registration processes, saving time while maintaining security through the pre-established cryptographic credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The single FIDO registration process with the trusted third party provides universal authentication capability across multiple application services. Instead of performing separate registration actions for each service, the initial registration creates a universal authentication mechanism that works across domains, reducing the time investment required while maintaining service-specific security through the trusted third party's coordination.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10771459B2Terminal apparatus, server apparatus, blockchain and method for FIDO universal authentication using the same
Publication Date: 2020.09.08 ELECTRONICS & TELECOMM RES INST
  • US10771459B2 patent drawing
  • US10771459B2 patent drawing
  • US10771459B2 patent drawing

AI summary

Disclosed herein are a terminal apparatus, a server apparatus, and a method for FIDO universal authentication using a blockchain. The method includes sending, by the terminal apparatus, a FIDO service request for any one of FIDO registration, FIDO authentication, and FIDO deregistration for an application service provided by the server apparatus to the server apparatus; verifying, by the blockchain, a FIDO service response message, which is created as a result of local authentication of a user in the terminal apparatus in response to the FIDO service request; and processing, by the server apparatus, the FIDO service request based on whether the FIDO service response message is successfully verified by the blockchain.