PKI Authentication Chain for Secure Multi-Party Wearable Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication methods, particularly in IoT and metaverse environments, are vulnerable to cyber-attacks and lack robust multi-factor authentication, especially in transactions involving multiple parties, where PKI-based methods require numerous certificates and do not adequately secure system-wide transactions.
Innovation Solution
A chain of authentication method using public key infrastructure (PKI) that sequentially authenticates multiple parties by generating modified public keys containing authentication information from previously authenticated parties, minimizing the number of required certificates and incorporating biometric data for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional PKI-based authentication methods are used in multi-party transactions, then each party can be authenticated individually, but the number of required certificates increases significantly and system-wide security is compromised
Solution Approach 1:
The patent merges multiple individual authentication relationships into a single chain authentication structure. Instead of requiring separate certificate pairs for each party relationship, the system creates a sequential chain where each party's public key is signed by the previous party, forming a unified authentication structure that covers all parties in the transaction.
Solution Approach 2:
The authentication system is segmented into a sequential chain structure where authentication proceeds step-by-step through each party. Each party in the chain authenticates the next party, creating discrete authentication segments that collectively provide system-wide security without requiring all parties to hold all certificates simultaneously.
2Reliability
If traditional authentication methods (ID, password, biometric) are used, then implementation is simple, but security is vulnerable to loss, theft, or interception
Solution Approach 1:
The patent replaces traditional mechanical authentication systems (physical IDs, written passwords, biometric scanners) with a cryptographic digital signature system. Instead of relying on physical tokens or human verification, the system uses mathematical one-way functions and digital signatures to provide security that cannot be easily lost, stolen, or intercepted.
Solution Approach 2:
The authentication mechanism changes from static parameters (fixed passwords, unchangeable biometrics) to dynamic cryptographic parameters (digital signatures, public-private key pairs). This transformation allows for more secure authentication while maintaining operational simplicity through automated cryptographic verification.
3Productivity
If multiple PKI certificates are used for each party in multi-party transactions, then individual authentication is achieved, but system-wide security and transaction efficiency are reduced
Solution Approach 1:
The chain authentication structure serves multiple functions simultaneously: it authenticates each individual party, verifies the entire transaction chain, and provides system-wide security validation. A single chain structure performs what would otherwise require multiple separate authentication processes, improving efficiency without compromising security.
Data Source
AI summary
A method for sequential authentication based on chain of authentication using public key infrastructure (PKI) is provided. The method includes abutting a first wearable device belonging to a first party with a second wearable device belonging to a second party; transmitting, by the first wearable device, authentication information of the first party; verifying the authentication information of the first party; transmitting, by the second wearable device, authentication information of the second party; verifying the authentication information of the second party; authorizing electronic transaction in response to successfully verifying both the authentication information of the first party and the authentication information of the second party. Each of the authentication information of the first party and the authentication information of the second party includes information configured for authentication based on a public key infrastructure (PKI) certificate.


