Secure Data Exchange Network Using Distributed Ledger Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network communication technologies face vulnerabilities in security, trust, privacy, and authentication, particularly with the rise of IoT devices and malicious servers, leading to data breaches and loss of user trust, as existing solutions are complex, expensive, or ineffective in ensuring secure device authentication and data privacy.

Innovation Solution

A distributed ledger-based system that enables secure device authentication and data exchange by using network address encryption, session encryption, and message encryption, eliminating the need for central databases and allowing direct device communication without third-party monitoring, with devices uniquely paired for secure key management and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (passwords, 2FA) are used, then user identification is achieved, but user frustration increases and access delays occur

Engineering Contradiction:
Improveauthentication securityVSAvoidaccess speed
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary device authentication during the device pairing process, establishing secure communication channels before actual data exchange begins. This preliminary authentication eliminates the need for repeated login attempts during normal operation, providing both security and speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Authenticated devices automatically present their credentials and authentication tokens to the network, eliminating the need for manual user intervention. The system serves itself by automatically handling authentication and authorization, providing frictionless access for users.

Inventive Principle:
Principle #25Self-service

2Extent of automation

If central databases are used for authentication and data storage, then centralized control is achieved, but security vulnerabilities and data breach risks increase

Engineering Contradiction:
Improvecentralized managementVSAvoiddata breach risk
Core Design Contradiction:
Extent of automationVSObject-affected harmful factors

Solution Approach 1:

The system segments authentication and data storage functions across multiple distributed components including device pairings, authentication servers, and encrypted storage. No single central database holds all user data, reducing the impact of potential breaches and eliminating single points of failure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces encrypted communication channels and authentication tokens as intermediaries between devices and the network. These intermediaries protect data in transit and at rest, allowing centralized management functions to operate without exposing raw data to malicious actors.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If encryption and VPN are used to protect data, then privacy and security are improved, but system complexity and cost increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system merges authentication, encryption, and data protection functions into a unified device pairing mechanism. By combining these functions, the system achieves comprehensive security without requiring separate complex systems for each function, reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The device pairing mechanism serves multiple functions simultaneously: it authenticates devices, establishes encryption keys, creates communication channels, and manages data protection. This multi-functionality eliminates the need for separate specialized systems, reducing complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If multiple encryption keys and authentication methods are implemented, then security is improved, but authentication requirements and user friction increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs comprehensive authentication and key exchange during the initial device pairing process, establishing all necessary security measures before actual use begins. This preliminary action consolidates multiple authentication steps into a single user interaction, maintaining security while improving convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once devices are paired and authenticated, the system automatically manages all subsequent authentication and encryption operations without requiring user intervention. Devices present their credentials automatically, and the system handles key management, eliminating the need for users to repeatedly provide authentication information.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11159312B2Secure data exchange network
Publication Date: 2021.10.26 THUNDERPORT INC
  • US11159312B2 patent drawing
  • US11159312B2 patent drawing
  • US11159312B2 patent drawing

AI summary

A secure data exchange system permits device to exchange secure message keys and securely transmit messages between devices. The devices may initially exchange temporary message keys that are used to encrypt permanent message keys. In addition, devices may have pairing managed that authenticates devices. Devices may be associated with an address ledger that maintains address information and is accessible with a public ledger key, which may provide different access to address information to different paired devices. Data within the system may also be encrypted with user device keys that prevents unauthorized access to data while permitting recreation of the user device key for data backup and migration.