Public Ledger Authentication System for Payment Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional online and mobile payment systems face security challenges due to users often using easily guessed authentication credentials, lacking biometric devices, which compromises the security of their payment accounts.
Innovation Solution
A public ledger authentication system that generates static user keys through a common hash operation on user identification information, allowing users to register and authenticate securely without storing sensitive information, using a distributed network to verify transactions and maintain a secure authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional authentication credentials (username/password) are used, then ease of operation is improved, but security is worsened due to easily guessed credentials
Solution Approach 1:
The patent extracts the authentication credentials from the conventional username/password system and stores them instead on a public ledger (blockchain). This removes the vulnerability of storing credentials in centralized databases while maintaining user accessibility through the distributed ledger technology.
Solution Approach 2:
The public ledger acts as an intermediary between the user and the system provider for authentication. Instead of directly storing credentials in a centralized database, the system uses the decentralized public ledger as a mediator to verify authentication information, enhancing security while maintaining ease of operation.
2Ease of operation
If centralized authentication systems are used, then ease of operation is improved, but security is worsened due to centralized storage vulnerabilities
Solution Approach 1:
The patent segments the authentication system by distributing credential storage across multiple nodes in a public ledger rather than concentrating it in a single centralized database. This segmentation eliminates the single point of failure while maintaining authentication functionality.
Solution Approach 2:
The public ledger serves as an intermediary that replaces the vulnerable centralized authentication database. It provides a decentralized, secure mechanism for storing and verifying authentication credentials, eliminating the security risks associated with centralized storage while maintaining operational simplicity.
3Adaptability or versatility
If user identification information is stored centrally, then authentication functionality is improved, but security is worsened due to data breach risks
Solution Approach 1:
The patent extracts user identification information from centralized storage and relocates it to a public ledger. This extraction removes the target for data breaches while preserving authentication functionality through the distributed ledger's verification mechanisms.
Solution Approach 2:
The public ledger acts as an intermediary that enables authentication functionality without requiring centralized storage of user identification information. It provides a secure, decentralized verification mechanism that eliminates data breach risks while maintaining system adaptability.
Data Source
AI summary
Systems and methods for public ledger authentication includes receiving a first previous authentication public ledger address and a first current authentication public ledger address from a user. A verified static user key is identified in a public ledger using the first previous authentication public ledger address. A second current authentication public ledger address is then provided to the user for use in the current authentication attempt. Authentication attempt information is determined that includes a number of authentication attempts by the user, and used in a hash operation with the verified static user key to generate a first user authentication key. A second user authentication key is retrieved from the public ledger that was sent from the first current authentication public ledger address to the second current authentication public ledger address in a transaction, and the user is authenticated if the second user authentication key matches the first user authentication key.


