FIDO Universal Authentication via Blockchain Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods based on IDs and passwords are vulnerable to security threats, requiring users to manage multiple complex passwords across various services, leading to inconvenience and increased security risks due to repeated registration processes, especially when sharing authentication information between different domains.
Innovation Solution
Implementing a method that uses FIDO universal authentication with a blockchain to securely share and manage user authentication information across multiple domains without the need for a trusted third party, allowing users to perform FIDO registration and authentication seamlessly across various services using a blockchain identifier and public key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If FIDO authentication device is registered in each application service server, then authentication security is improved, but device complexity and registration process burden increase
Solution Approach 1:
The patent introduces a trusted third party server that mediates between multiple application service servers and the user's FIDO authentication device. This intermediary manages the public keys and authentication information centrally, allowing the user to register once with the trusted third party rather than with each individual service. The trusted third party then facilitates authentication across multiple domains, reducing the registration burden while maintaining security through centralized key management.
Solution Approach 2:
The trusted third party server provides universal authentication functionality across multiple application services and domains. Instead of requiring separate FIDO device registrations for each service, the system enables a single FIDO device to authenticate across multiple services through the trusted third party's coordination. This multi-functional approach allows one authentication mechanism to serve multiple purposes and services.
2Adaptability or versatility
If multiple private keys are stored in FIDO authentication device for different services, then authentication capability across services is improved, but storage requirements and management complexity increase
Solution Approach 1:
The trusted third party server acts as an intermediary that stores and manages the public keys corresponding to the user's private keys. Instead of requiring the user's FIDO device to store multiple private keys for different services, the system stores the necessary public key information centrally at the trusted third party. This reduces the storage burden on the user's device while maintaining the ability to authenticate across multiple services.
Solution Approach 2:
The system uses public keys as copies or representations of the authentication credentials, which can be stored and shared across multiple services without exposing the actual private keys. The trusted third party stores public key information that can be used by multiple application services to verify authentication, eliminating the need to store multiple private key copies in the user's device.
3Reliability
If FIDO registration process is performed for each application service, then service-specific authentication security is improved, but user convenience and time efficiency deteriorate
Solution Approach 1:
The system performs preliminary authentication setup through a single registration process with the trusted third party server. During this initial action, the user's FIDO device is registered and public keys are established once. This preliminary setup enables subsequent authentication across multiple services without requiring repeated registration processes, saving time while maintaining security through the pre-established cryptographic credentials.
Solution Approach 2:
The single FIDO registration process with the trusted third party provides universal authentication capability across multiple application services. Instead of performing separate registration actions for each service, the initial registration creates a universal authentication mechanism that works across domains, reducing the time investment required while maintaining service-specific security through the trusted third party's coordination.
Data Source
AI summary
Disclosed herein are a terminal apparatus, a server apparatus, and a method for FIDO universal authentication using a blockchain. The method includes sending, by the terminal apparatus, a FIDO service request for any one of FIDO registration, FIDO authentication, and FIDO deregistration for an application service provided by the server apparatus to the server apparatus; verifying, by the blockchain, a FIDO service response message, which is created as a result of local authentication of a user in the terminal apparatus in response to the FIDO service request; and processing, by the server apparatus, the FIDO service request based on whether the FIDO service response message is successfully verified by the blockchain.


