Decentralized User Authentication System with Guardian Nodes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication systems are inefficient across system boundaries, prone to predictable failures, vulnerable to Sybil attacks, and burden users with managing multiple authentication protocols and credentials.
Innovation Solution
A User Authentication System (UAS) utilizing a network of guardian nodes and gatekeeper nodes that securely communicate to provide universal authentication across online services, using methods like multifactor authentication, Public Key Infrastructure, and biometric authentication, with tokens and public/private key management to facilitate secure access and identity verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If service providers build and manage their own user authentication functionality, then each service can implement its own security protocols, but users have to use different authentication methods and manage different information across multiple services
Solution Approach 1:
The patent introduces a decentralized authentication network with guardian nodes and gatekeeper nodes as intermediaries between users and service providers. Guardian nodes store user credentials and authenticate users, while gatekeeper nodes verify authentication and manage service access. This intermediary layer eliminates the need for users to manage multiple authentication systems while maintaining service-specific security requirements through cryptographic verification.
2Ease of operation
If password-based authentication is used, then users can access services with simple credentials, but passwords can be stolen from user devices or services creating predictable failures
Solution Approach 1:
The patent replaces traditional password-based mechanical authentication with a cryptographic system using public key infrastructure. Users have guardian nodes that store cryptographic credentials and perform authentication through cryptographic verification rather than password checking. This substitution eliminates password theft vulnerabilities while maintaining user-friendly access through the guardian node infrastructure.
3Reliability
If single use passwords or tokens via text message or authenticator application are used, then security is enhanced, but users with multiple accounts must keep track of different authentication protocols and procedures
Solution Approach 1:
The patent creates a universal authentication system where guardian nodes provide a single interface for all authentication operations across different services. The gatekeeper nodes handle service-specific verification protocols, but users interact with a unified guardian node system that manages all credentials and authentication flows. This multi-functional system eliminates the need for users to learn different authentication protocols for different services while maintaining high security through cryptographic methods.
4Reliability
If users lose their device or change phone number, then security is compromised, but resetting authentication for multiple services becomes a difficult or insurmountable burden
Solution Approach 1:
The patent extracts authentication credentials from user devices and stores them in guardian nodes that are not tied to specific devices or phone numbers. When users lose devices or change contact information, they can recover access by authenticating with their guardian node through alternative methods. The guardian node system separates credential storage from device dependency, making recovery straightforward without requiring resetting of multiple services.
5Reliability
If existing authentication systems are used, then services can verify user identity, but systems are vulnerable to Sybil attacks where bad actors create multiple accounts for anti-social activities
Solution Approach 1:
The patent introduces guardian nodes as intermediaries that issue cryptographic credentials to users after verification. These guardian nodes act as trusted authorities that can prevent Sybil attacks by controlling credential issuance and verifying user identities before granting access. The decentralized network of guardian nodes creates a distributed trust system that is resistant to single-point failures and can detect and prevent malicious multi-account creation through cryptographic verification and reputation mechanisms.
Data Source
AI summary
A user authentication system and method includes a network of guardian nodes and gatekeeper nodes configured to securely communicate with one another. The gatekeeper nodes are connected to service providers and the guardian nodes are associated with UAS customers. The guardian nodes and gatekeeper nodes are configured to generate tokens that are passed between the guardian nodes, gatekeeper nodes, service providers and UAS customers to authenticate UAS customers requesting access to service providers.


