Off-Chain Identifier Authentication for Secure Blockchain Transfers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing blockchain systems lack security for off-chain identifiers, preventing the practical transfer of digital resources to users without a blockchain address, hindering mass adoption.
Innovation Solution
A method for client-side authentication using a target off-chain identifier, generating a URL to sign a code with a mobile signing application, and authenticating with a target public key to transfer resources between blockchain addresses, while associating off-chain identifiers with blockchain addresses in an off-chain database.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If blockchain systems require recipients to have a blockchain address for authentication, then security is maintained, but accessibility and ease of use deteriorate for users without on-chain presence
Solution Approach 1:
The patent introduces an off-chain identifier (such as email address) as an intermediary that bridges the gap between traditional users and blockchain systems. This intermediary allows users without blockchain addresses to participate in transactions while maintaining security through cryptographic verification of the identifier against the target blockchain address.
Solution Approach 2:
The system performs preliminary binding between off-chain identifiers and target blockchain addresses before the actual resource transfer occurs. This preliminary action establishes the authentication relationship in advance, allowing seamless transfers to users who may not yet have or know their blockchain addresses.
2Reliability
If blockchain records are made immutable and traceable, then security and transparency are improved, but the ability to protect recipient identity and enable private transfers deteriorates
Solution Approach 1:
The patent segments the identification system into two distinct layers: off-chain identifiers (email addresses, phone numbers) that users can freely share, and on-chain blockchain addresses that remain private. This segmentation allows the system to maintain traceability for security purposes while protecting the actual recipient identity through the use of pseudonymous blockchain addresses.
Solution Approach 2:
The off-chain identifier serves as a mediator that enables the transfer process without exposing the recipient's blockchain address. The system verifies the binding between the off-chain identifier and the target blockchain address through cryptographic proof, allowing identity protection while maintaining record integrity.
3Measurement precision
If the system stores mappings between off-chain identifiers and blockchain addresses, then transfer accuracy is improved, but the complexity of the system architecture increases
Solution Approach 1:
The system employs self-service mechanisms where users independently bind their own off-chain identifiers to their blockchain addresses through cryptographic operations. This eliminates the need for centralized databases or complex registration systems, as the binding relationship is established and verified through self-contained cryptographic proofs that users generate and submit to the blockchain.
4Adaptability or versatility
If blockchain transfers require existing on-chain presence, then security is maintained, but mass adoption and usability are hindered
Solution Approach 1:
The patent makes the blockchain authentication system universal by allowing it to work with traditional off-chain identifiers that all users already possess (email addresses, phone numbers). This multi-functionality enables the system to serve both traditional users without blockchain experience and crypto-native users simultaneously, greatly expanding accessibility while maintaining cryptographic security through the binding verification mechanism.
Data Source
AI summary
A method and related system operations include receiving, from a first user device of a first user, a request indicating an off-chain identifier associated with a second user and a resource for the second user. The method also includes generating and sending a link to the second user based on the request. The method also includes obtaining, based on the link being activated at a second user device of the second user, a signed code signed with a first key via a signing application. The method also includes sending, based on authentication of the signed code, to a blockchain system, a signed message indicating a transfer of the resource from a source blockchain address to a target blockchain address. The method also includes storing, based on the authentication of the signed code, the off-chain identifier and the target blockchain address in association with one another.


