Method and apparatus for providing blockchain-based zero-trust confidential file access permission management service

The blockchain-based zero-trust system addresses the issue of transparent and secure access management for confidential files by using smart contracts and dynamic authentication, enhancing security and reducing leaks.

WO2026095289A1PCT designated stage Publication Date: 2026-05-07CHAINTREE INC
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
CHAINTREE INC
Filing Date
2025-08-25
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Existing systems for managing access to confidential files lack transparency and integrity, leading to frequent leaks due to complex authorization structures and the diversification of personnel and organizations, with advancements in software and hardware often bypassing encryption systems.

Method used

A blockchain-based zero-trust confidential file access rights management system that includes an access authority registration module, access verification module, and access management module, utilizing smart contracts and dynamic authentication to manage and verify access rights, ensuring transparency and integrity.

Benefits of technology

Enhances security by providing efficient and transparent management of access rights, reducing the risk of leaks through real-time verification and dynamic authentication, while improving user experience and reducing management costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025012864_07052026_PF_FP_ABST
    Figure KR2025012864_07052026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a blockchain-based zero-trust confidential file access permission management system. The system comprises: an access permission registration module for acquiring setting information about a user type from a manager terminal, determining a type of a user on the basis of the setting information about the user type, and setting a blockchain network type on the basis of the type of the user; an access verification module for generating an access request including an access permission attribute of the user, and determining whether access corresponding to the access request is permitted; and an access management module for checking the integrity of a file.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for providing a blockchain-based zero-trust confidential file access rights management service

[0001] This specification relates to a method and apparatus for providing a blockchain-based zero-trust confidential file access rights management service, and more specifically, to a system for managing confidential file access rights by combining a zero-trust security model and blockchain technology.

[0002] The present invention relates to the fields of blockchain technology, file access permission management, and mobile applications, and concerns a method for enhancing security by utilizing a blockchain wallet app to dynamically respond (such as differential resource access) when a user is denied access to resources while a blockchain-based file access permission management system is in operation.

[0003] The present invention was derived from a project (25AB1600, Development of intelligent technology for key industries for manufacturing innovation and development of human-mobile-space autonomous collaboration intelligence technology in industrial sites) carried out as part of the 2nd joint cooperation project between Ulsan City and ETRI.

[0004] With the acceleration of modernization, all confidential information is being stored as files in the form of electronic documents rather than paper documents, and access to such information is generally possible only after authorization has been granted to the administrator and / or individuals. However, leaks of these confidential documents are occurring frequently due to various reasons, including the diversification, mass production, and complexity of authorized personnel and organizations, the vast variety and volume of security documents, and advancements in software and hardware used to bypass encryption systems. Therefore, strengthening of management systems is required to ensure that access to confidential documents is carried out more systematically and transparently.

[0005] The present invention aims to provide a method and apparatus for providing a blockchain-based zero-trust confidential file access right management service that can enhance security levels, enable efficient security management, and improve user experience.

[0006] A blockchain-based zero-trust confidential file access authority management system according to one embodiment of the present specification for achieving the above objective may include: an access authority registration module that obtains configuration information for a user type from an administrator terminal, determines a user type based on the configuration information for the user type, and sets a blockchain network type based on the user type; an access verification module that generates an access request including the access authority attributes of the user and determines whether access is possible for the access request; and an access management module that verifies the integrity of a file.

[0007] Here, the access right registration module may include: an administrator interface that obtains configuration information regarding the access right attribute for the file from the administrator terminal; an access control document automatic generation unit that generates a document regarding the access right attribute based on the configuration information regarding the access right attribute; a blockchain integration unit that generates and signs a transaction to register the document regarding the access right attribute to the blockchain and transmits the transaction to register the document regarding the access right attribute to the blockchain to a blockchain network where the access right smart contract is deployed; and a smart contract registration unit that registers the document regarding the access right attribute to the access right smart contract.

[0008] Here, the blockchain integration unit may provide notification information to the administrator terminal if there is an access request corresponding to a preset threshold within a preset threshold time after an access request for a specific file has failed.

[0009] Here, the access verification module may include: an access request generation unit that generates an access request including the access authority attribute of the user; a blockchain transaction generation and transmission unit that generates and signs a blockchain transaction including the access request and transmits the blockchain transaction including the access request to the blockchain network; an access request verification unit that verifies whether the user can access the file requested based on a document regarding the access authority attribute registered in the blockchain smart contract and transmits the accessibility status to the access management module; and an access history management unit that stores the access request history and the verification result for the access request.

[0010] Here, the access management module may include: an access token issuance and management unit that issues an access token based on the accessibility status obtained from the access verification module; and an authenticity verification unit that verifies integrity and file authenticity based on a hash stored in a blockchain based on the access token.

[0011] Here, the access request verification unit may, in the event that a document regarding a first access permission attribute based on setting information for a first access permission attribute for the file conflicts with a document regarding a second access permission attribute based on setting information for a second access permission attribute for the file, request signatures from both the first administrator terminal that provided the setting information for the first access permission attribute and the second administrator terminal that provided the setting information for the second access permission attribute, and verify the access request for the file based on the signature of the first administrator terminal and the signature of the second administrator terminal.

[0012] Here, the smart contract register registers, after registering a document regarding a first access right attribute based on configuration information for a first access right attribute for a file, and when registering a document regarding a second access right attribute based on configuration information for a second access right attribute for a file, checks whether there is a conflict between the document regarding the first access right attribute and the document regarding the second access right attribute, and if there is a conflict between the document regarding the first access right attribute and the document regarding the second access right attribute, requests signatures from both the first administrator terminal that provided the configuration information for the first access right attribute and the second administrator terminal that provided the configuration information for the second access right attribute, and can modify the document regarding the first access right attribute and the document regarding the second access right attribute based on the signature of the first administrator terminal and the signature of the second administrator terminal.

[0013] Here, the access verification module can generate a plurality of blockchain transactions including access requests corresponding to the least common multiple of the number of types of the user type and the number of data types of the file targeted by the access request.

[0014] Here, the access management module issues a first access token to a first user, and if there is consent for the retrieval of the first access token from a preset number of multiple users excluding the first user, it retrieves the first access token and can share information regarding the consent for the retrieval of the first access token with all access token owners.

[0015] An apparatus for providing a blockchain-based zero-trust confidential file access permission management service according to another embodiment of the present specification for achieving the above objective comprises a processor and a memory for storing at least one command executed by the processor, wherein the at least one command may be configured to obtain setting information for a user type from an administrator terminal, determine a user type based on the setting information for the user type, and set a blockchain network type based on the user type; generate an access request including access permission attributes of the user, determine whether access is possible for the access request, and verify the integrity of a file.

[0016] Here, the at least one command may be configured to obtain configuration information regarding the access permission attribute for the file from the administrator terminal; generate a document regarding the access permission attribute based on the configuration information regarding the access permission attribute; generate and sign a transaction to register the document regarding the access permission attribute on the blockchain and transmit the transaction to register the document regarding the access permission attribute on the blockchain to a blockchain network where an access permission smart contract is deployed; and to register the document regarding the access permission attribute with the access permission smart contract.

[0017] Here, the above at least one command may be configured to provide notification information to the administrator terminal if there is an access request corresponding to a preset threshold within a preset threshold time after an access request for a specific file has failed.

[0018] Here, the at least one command may be configured to generate the access request including the access authority attribute of the user; generate and sign the blockchain transaction including the access request and transmit the blockchain transaction including the access request to the blockchain network; verify whether the user can access the file requested by the user based on the document regarding the access authority attribute registered in the blockchain smart contract and transmit the accessibility status to the access management module; and store the access request history and the verification result for the access request.

[0019] Here, the at least one command may be configured to issue an access token based on the accessibility status obtained from the access verification module; and to verify integrity and file authenticity based on a hash stored in the blockchain based on the access token.

[0020] Here, the at least one command may be configured to request signatures from both the first administrator terminal that provided the setting information for the first access permission attribute and the second administrator terminal that provided the setting information for the second access permission attribute when there is a conflict between the document regarding the first access permission attribute based on the setting information for the first access permission attribute for the file and the document regarding the second access permission attribute based on the setting information for the second access permission attribute for the file, and to verify the access request for the file based on the signature of the first administrator terminal and the signature of the second administrator terminal.

[0021] Here, the at least one command may be configured to check for a conflict between the document regarding the first access right attribute and the document regarding the second access right attribute when registering the document regarding the second access right attribute based on the setting information for the first access right attribute for the file after registering the document regarding the first access right attribute based on the setting information for the first access right attribute for the file, and if the document regarding the first access right attribute and the document regarding the second access right attribute conflict, to request signatures from both the first administrator terminal that provided the setting information for the first access right attribute and the second administrator terminal that provided the setting information for the second access right attribute, and to modify the document regarding the first access right attribute and the document regarding the second access right attribute based on the signature of the first administrator terminal and the signature of the second administrator terminal.

[0022] Here, the at least one command may be configured to generate a plurality of blockchain transactions including access requests corresponding to the least common multiple of the number of types of the user type and the number of data types of the file targeted by the access request.

[0023] Here, the at least one command may be configured to issue a first access token to a first user, and if consent for the retrieval of the first access token is obtained from a preset number of multiple users excluding the first user, to reclaim the first access token and to share information regarding the consent for the retrieval of the first access token with all access token owners.

[0024] According to one embodiment of the present specification, the level of security can be enhanced through dynamic authentication using a blockchain wallet app when resource access is denied, and rapid and efficient security management can be achieved through an automated response system. Additionally, the functionality of the wallet app can be expanded to improve the user experience and broaden the scope of blockchain technology utilization.

[0025] According to one embodiment of the present specification, type settings regarding data and users can be actively configured by the administrator's settings, and appropriate blockchain network usage and data management can be performed according to said type settings. For the management of specific data, such as confidential documents, there may be advantages of greater transparency, lower latency, accuracy, and lower management costs.

[0026] FIG. 1 is a system diagram including a blockchain-based zero-trust confidential file access rights management service providing server according to one embodiment of the present specification.

[0027] FIG. 2 is a block diagram showing the configuration of a server providing a blockchain-based zero-trust confidential file access rights management service according to one embodiment of the present specification.

[0028] FIG. 3 is a diagram illustrating a blockchain-based zero-trust confidential file access rights management system according to one embodiment of the present specification.

[0029] FIG. 4 is a diagram illustrating a method for providing a blockchain-based zero-trust confidential file access rights management service according to one embodiment of the present specification.

[0030] A blockchain-based zero-trust confidential file access authority management system according to one embodiment may include: an access authority registration module that obtains configuration information for a user type from an administrator terminal, determines the type of user based on the configuration information for the user type, and sets a blockchain network type based on the type of user; an access verification module that generates an access request including the access authority attributes of the user and determines whether access is possible for the access request; and an access management module that verifies the integrity of a file.

[0031] An apparatus providing a blockchain-based zero-trust confidential file access permission management service according to one embodiment includes a processor and a memory that stores at least one command executed by the processor, wherein the at least one command may be configured to obtain setting information for a user type from an administrator terminal, determine a user type based on the setting information for the user type, and set a blockchain network type based on the user type; generate an access request including access permission attributes of the user, determine whether access is possible for the access request, and verify the integrity of a file.

[0032] As the present specification is susceptible to various modifications and may have various embodiments, specific embodiments are illustrated in the drawings and described in detail in the detailed description. However, this is not intended to limit the present specification to specific embodiments, and it should be understood that it includes all modifications, equivalents, and substitutions that fall within the spirit and scope of the present specification. Similar reference numerals have been used for similar components in the description of each drawing.

[0033] Terms such as first, second, A, B, etc., may be used to describe various components, but said components should not be limited by said terms. These terms are used solely for the purpose of distinguishing one component from another. For example, without departing from the scope of the rights of this specification, the first component may be named the second component, and similarly, the second component may be named the first component. The term "and / or" includes a combination of a plurality of related described items or any of a plurality of related described items.

[0034] When it is stated that one component is "connected" or "connected" to another component, it should be understood that while it may be directly connected or connected to that other component, there may also be other components in between. On the other hand, when it is stated that one component is "directly connected" or "directly connected" to another component, it should be understood that there are no other components in between.

[0035] The terms used in this application are used merely to describe specific embodiments and are not intended to limit this specification. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this application, terms such as "comprising" or "having" are intended to indicate the presence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.

[0036] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as generally understood by those skilled in the art to which this specification pertains. Terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and should not be interpreted in an ideal or overly formal sense unless explicitly defined in this application.

[0037] Hereinafter, preferred embodiments of the present specification will be described in more detail with reference to the attached drawings. To facilitate overall understanding in describing the present specification, the same reference numerals are used for identical components in the drawings, and redundant descriptions of identical components are omitted.

[0038] FIG. 1 is a system diagram including a battery management service providing server based on battery SoC (state of charge) estimation using an artificial intelligence model according to one embodiment of the present specification.

[0039] Referring to FIG. 1, the method for providing a blockchain-based zero-trust confidential file access rights management service according to an embodiment of the present specification may be performed on a computing device that is equipped with storage space and connected to the internet, such as a PC (Personal Computer), and is not easily portable, or on a portable terminal such as a smartphone. In this case, the blockchain-based zero-trust confidential file access rights management service provision method may be executed after an application implementing the blockchain-based zero-trust confidential file access rights management service provision method is downloaded from an app store, etc., and installed on the portable terminal.

[0040] In addition, the above-mentioned method for providing a blockchain-based zero-trust confidential file access rights management service may be performed through an access operation of a computing device such as a PC while being inserted into a recording medium such as a CD (Compact Disc) or USB (Universal Serial Bus) memory, or it may be performed through an access operation of a computing device after being stored from the recording medium in the storage space of a computing device.

[0041] Meanwhile, if the computing device or portable terminal can access a server connected to the Internet, the method for providing a blockchain-based zero-trust confidential file access rights management service may also be executed on the server upon a request from the computing device or portable terminal.

[0042] In the following, a computing device, portable terminal, or server, etc., on which the above-mentioned method for providing a blockchain-based zero-trust confidential file access rights management service is executed may be collectively referred to as a blockchain-based zero-trust confidential file access rights management service providing device.

[0043] The blockchain-based zero-trust confidential file access rights management service provider described above may have the same configuration as the blockchain-based zero-trust confidential file access rights management service provider exemplified in FIG. 2, and the blockchain-based zero-trust confidential file access rights management service provider may not be limited to the blockchain-based zero-trust confidential file access rights management service provider illustrated in FIG. 1.

[0044] A system according to one embodiment may include a user terminal (110), an administrator terminal (120), an administrator terminal (130), and a blockchain-based zero-trust confidential file access rights management system server (140) (hereinafter, server (140)). The network may include an internet portal site server, an SNS server, a server operating a blog, etc.

[0045] The user terminal (110), administrator terminal (120), and administrator terminal (130) may be, but are not limited to, automobiles, mobility devices, smartphones, tablet PCs, PCs, mobile phones, PDAs (personal digital assistants), laptops, media players, micro servers, GPS (global positioning system) devices, and other mobile or non-mobile computing devices. Additionally, the user terminal (110), administrator terminal (120), and administrator terminal (130) may be wearable devices equipped with communication functions and data processing functions. However, they are not limited to these.

[0046] The server (140) may be implemented as a computer device or a plurality of computer devices that communicate with a user terminal (110), an administrator terminal (120), and an administrator terminal (130) through a network to provide commands, code, files, content, services, etc.

[0047] For example, the server (140) can provide a file for installing an application to a user terminal (110), an administrator terminal (120), and an administrator terminal (130) connected via a network. In this case, the user terminal (110), the administrator terminal (120), and the administrator terminal (130) can install the application using the file provided by the server (140).

[0048] Additionally, the user terminal (110), the administrator terminal (120), and the administrator terminal (130) can connect to the server (140) under the control of the operating system (OS) and at least one program (e.g., a browser or an installed application) to receive services or content provided by the server (140).

[0049] As another example, the server (140) may establish a communication session for data transmission and reception and route data transmission and reception between the user terminal (110), the administrator terminal (120), and the administrator terminal (130) through the established communication session.

[0050] A user terminal (110), an administrator terminal (120), an administrator terminal (130), and a blockchain-based zero-trust confidential file access rights management service provider server (140) can communicate using a network. For example, the network includes a Local Area Network (LAN), a Wide Area Network (WAN), a Value Added Network (VAN), a mobile radio communication network, a satellite communication network, and combinations thereof, and is a data communication network in a comprehensive sense that enables each network constituent entity shown in FIG. 1 to communicate smoothly with one another, and may include wired internet, wireless internet, and mobile wireless communication networks. In addition, wireless communication may include, for example, wireless LAN (Wi-Fi), Bluetooth, Bluetooth Low Energy, LoRaWAN, Zigbee, WFD (Wi-Fi Direct), UWB (ultra wideband), infrared communication (IrDA, infrared Data Association), NFC (Near Field Communication), etc., but is not limited thereto.

[0051] FIG. 2 is a block diagram showing the configuration of a server providing a blockchain-based zero-trust confidential file access rights management service according to one embodiment of the present specification.

[0052] Referring to FIG. 2, a server (200) (hereinafter, server (200)) providing a blockchain-based zero-trust confidential file access rights management service may include a communication unit (210), a processor (220), and a DB (230). Only components related to the embodiment are shown in the server (200) of FIG. 2. Therefore, a person skilled in the art will understand that other general-purpose components may be included in addition to the components shown in FIG. 2.

[0053] The communication unit (210) may include one or more components that enable wired / wireless communication with a user terminal and a work provider terminal. For example, the communication unit (210) may include at least one of a short-range communication unit (not shown), a mobile communication unit (not shown), and a broadcast receiving unit (not shown).

[0054] For example, a request generated according to program code stored in a recording device such as a DB (230) can be transmitted to a user terminal and a work provider terminal via a network under the control of the communication unit (210). Conversely, control signals, commands, content, files, etc. provided under the control of the processors of the user terminal and the work provider terminal can be received by the server (200) via the communication unit (210) through the network. For example, control signals, commands, content, files, etc. of the server (200) received through the communication unit (210) can be transmitted to the processor (220) or transmitted to the DB (230) for storage.

[0055] DB (230) is hardware that stores various data processed within the server (200) and can store programs for processing and controlling the processor (220).

[0056] DB (230) may include RAM (random access memory), such as DRAM (dynamic random access memory) and SRAM (static random access memory), ROM (read-only memory), EEPROM (electrically erasable programmable read-only memory), CD-ROM, Blu-ray or other optical disc storage, HDD (hard disk drive), SSD (solid state drive), or flash memory. DB (230) may also be referred to as memory.

[0057] The processor (220) controls the overall operation of the server (200). For example, the processor (220) can control the input unit (not shown), display (not shown), communication unit (210), DB (230), etc., by executing programs stored in the DB (230). The processor (220) can control the operation of the external server (200) by executing programs stored in the DB (230).

[0058] The processor (220) may be implemented using at least one of ASICs (application specific integrated circuits), DSPs (digital signal processors), DSPDs (digital signal processing devices), PLDs (programmable logic devices), FPGAs (field programmable gate arrays), controllers, microcontrollers, microprocessors, and other electrical units for performing functions.

[0059] The DB (230) may store at least one command executed through the processor (220). The at least one command may be configured to obtain configuration information for a user type from an administrator terminal, determine the user type based on the configuration information for the user type, and set a blockchain network type based on the user type; generate an access request including the user's access authority attributes, determine whether access is possible for the access request, and verify the integrity of a file.

[0060] Here, the at least one command may be configured to obtain configuration information regarding the access permission attribute for the file from the administrator terminal; generate a document regarding the access permission attribute based on the configuration information regarding the access permission attribute; generate and sign a transaction to register the document regarding the access permission attribute on the blockchain and transmit the transaction to register the document regarding the access permission attribute on the blockchain to a blockchain network where an access permission smart contract is deployed; and to register the document regarding the access permission attribute with the access permission smart contract.

[0061] Here, the above at least one command may be configured to provide notification information to the administrator terminal if there is an access request corresponding to a preset threshold within a preset threshold time after an access request for a specific file has failed.

[0062] Here, the at least one command may be configured to generate the access request including the access authority attribute of the user; generate and sign the blockchain transaction including the access request and transmit the blockchain transaction including the access request to the blockchain network; verify whether the user can access the file requested by the user based on the document regarding the access authority attribute registered in the blockchain smart contract and transmit the accessibility status to the access management module; and store the access request history and the verification result for the access request.

[0063] Here, the at least one command may be configured to issue an access token based on the accessibility status obtained from the access verification module; and to verify integrity and file authenticity based on a hash stored in the blockchain based on the access token.

[0064] Here, the at least one command may be configured to request signatures from both the first administrator terminal that provided the setting information for the first access permission attribute and the second administrator terminal that provided the setting information for the second access permission attribute when there is a conflict between the document regarding the first access permission attribute based on the setting information for the first access permission attribute for the file and the document regarding the second access permission attribute based on the setting information for the second access permission attribute for the file, and to verify the access request for the file based on the signature of the first administrator terminal and the signature of the second administrator terminal.

[0065] Here, the at least one command may be configured to check for a conflict between the document regarding the first access right attribute and the document regarding the second access right attribute when registering the document regarding the second access right attribute based on the setting information for the first access right attribute for the file after registering the document regarding the first access right attribute based on the setting information for the first access right attribute for the file, and if the document regarding the first access right attribute and the document regarding the second access right attribute conflict, to request signatures from both the first administrator terminal that provided the setting information for the first access right attribute and the second administrator terminal that provided the setting information for the second access right attribute, and to modify the document regarding the first access right attribute and the document regarding the second access right attribute based on the signature of the first administrator terminal and the signature of the second administrator terminal.

[0066] Here, the at least one command may be configured to generate a plurality of blockchain transactions including access requests corresponding to the least common multiple of the number of types of the user type and the number of data types of the file targeted by the access request.

[0067] Here, the at least one command may be configured to issue a first access token to a first user, and if consent for the retrieval of the first access token is obtained from a preset number of multiple users excluding the first user, to reclaim the first access token and to share information regarding the consent for the retrieval of the first access token with all access token owners.

[0068] The present invention describes a system and method for managing access rights to confidential files by combining a zero-trust security model and blockchain technology. The system may be composed of a process of defining access policies using a structured language for policy-based access control and access control techniques based on user status / attributes (e.g., time, position, administrator approval, etc.), rather than determining access rights solely based on whether simple access rights to a file have been acquired, and procedures for verifying all access requests in real time based on this. Briefly, to ensure transparency and integrity regarding file access, a smart contract executed on a blockchain basis is utilized, and access tokens are issued only for approved requests and used to provide access to / control of confidential documents.

[0069] FIG. 3 is a diagram illustrating a blockchain-based zero-trust confidential file access rights management system according to one embodiment of the present specification.

[0070] Referring to FIG. 3, the technology of the present invention includes methods for creating, accessing, and managing existing confidential documents based on the advantages of blockchain technology, namely decentralization, immutability, and consensus. FIG. 3 illustrates an example of the configuration of the entire system to be described in the present invention. The system can be broadly divided into three parts, and these parts may be used individually or in combination. The first part may consist of a module (A) responsible for the overall management of data users, such as data creation, modification, and access rights. The second part may consist of a module (B) primarily responsible for processing events (e.g., access history, verification, etc.) when there are data usage events from users registered in the first part. The last part may consist of a module (C) responsible for managing the data when actual data creation and modification occur after permission for data usage has been granted based on the second part. The present invention describes the configuration and definition of these three modules and provides detailed additional descriptions of the characteristic features of each module in comparison to other systems.

[0071] A blockchain-based confidential document management system may be composed of modules that are primarily responsible for the overall management of data users, such as data creation, modification, and access rights (e.g., a user attribute-based access rights registration module); / or modules that primarily handle the processing of data usage events and user verification (e.g., access history, access request verification) when such events occur from authorized users (e.g., a zero-trust-based access verification module); and / or modules responsible for managing data when actual data creation or modification occurs (e.g., confidential file access management). These modules may be used individually or in combination, and each module may consist of the following components. In this case, any part or all of each component may be used.

[0072] A blockchain-based confidential document management system may include an access authority registration module that obtains configuration information for a user type from an administrator terminal, determines the user type based on the configuration information for the user type, and sets the blockchain network type based on the user type.

[0073] A blockchain-based confidential document management system may include an access verification module that generates an access request including the access authority attributes of the user and determines whether access is possible for the access request.

[0074] A blockchain-based confidential document management system may include an access management module that verifies the integrity of files.

[0075] The access right registration module may include an administrator interface that obtains configuration information regarding the access right attribute for the file from the administrator terminal, an access control document automatic generation unit that generates a document regarding the access right attribute based on the configuration information regarding the access right attribute, a blockchain integration unit that generates and signs a transaction to register the document regarding the access right attribute to the blockchain and transmits the transaction to register the document regarding the access right attribute to the blockchain to a blockchain network where an access right smart contract is deployed, and a smart contract registration unit that registers the document regarding the access right attribute to the access right smart contract.

[0076] The blockchain integration unit described above can provide notification information to the administrator terminal if there is an access request corresponding to a preset threshold within a preset threshold time after an access request for a specific file has failed.

[0077] The access verification module may include an access request generation unit that generates an access request including the access authority attribute of the user, a blockchain transaction generation and transmission unit that generates and signs a blockchain transaction including the access request and transmits the blockchain transaction including the access request to the blockchain network, an access request verification unit that verifies whether the user can access the file requested based on a document regarding the access authority attribute registered in the blockchain smart contract and transmits the accessibility status to the access management module, and an access history management unit that stores the access request history and the verification result for the access request.

[0078] The access management module may include an access token issuance and management unit that issues an access token based on the accessibility status obtained from the access verification module, and an authenticity verification unit that verifies integrity and file authenticity based on a hash stored in a blockchain based on the access token.

[0079] In the event that a document regarding a first access permission attribute based on setting information for a first access permission attribute for the file conflicts with a document regarding a second access permission attribute based on setting information for a second access permission attribute for the file, the access request verification unit may request signatures from both the first administrator terminal that provided the setting information for the first access permission attribute and the second administrator terminal that provided the setting information for the second access permission attribute, and verify the access request for the file based on the signature of the first administrator terminal and the signature of the second administrator terminal.

[0080] The smart contract register above checks whether there is a conflict between the document regarding the first access right attribute and the document regarding the second access right attribute based on the configuration information for the first access right attribute for the file after registering the document regarding the first access right attribute based on the configuration information for the second access right attribute for the file, and if there is a conflict between the document regarding the first access right attribute and the document regarding the second access right attribute, it requests signatures from both the first administrator terminal that provided the configuration information for the first access right attribute and the second administrator terminal that provided the configuration information for the second access right attribute, and can modify the document regarding the first access right attribute and the document regarding the second access right attribute based on the signature of the first administrator terminal and the signature of the second administrator terminal.

[0081] The system described in this proposal can be supported through a single or multiple types of blockchain networks, which may include public, private, hybrid, or consortium networks. For example, a system might support a private-based blockchain network for administrators, while supporting a hybrid-type blockchain that provides public or private networks depending on the user's tier. In other words, the system can be configured to allow different blockchain network types to be set according to the user type. Furthermore, the user type settings can be configured or modified by the administrator, and this operation can be performed within a user attribute-based access permission registration module. Here, a user can be any user participating in the creation, observation, and / or control of data, and can be a single node or a separate ledger. Additionally, the administrator may be a single or multiple node or ledger of each chain. Alternatively, the network type may be configured differently based on the type of internal data within the data blocks. Here, examples of data types include "General" and "Confidential." For data tagged as "General," a public network type blockchain is supported, while for data tagged as "Confidential," a private network type blockchain can be configured. Furthermore, blockchains supported by different network types may consist of smart contracts configured under different conditions, and the details of such smart contracts may be added or modified by an administrator.

[0082] The above user attribute-based access permission registration module provides an administrator interface, and the administrator can set conditions for smart contracts on blockchains with specific data types or access permissions for specific data. In this case, the data type of pre-generated data may be automatically or manually determined according to the smart contract; some contract conditions may be requirements for exposure to specific users, and if such conditions are satisfied, access rights to the data may be granted only to those specific users.

[0083] The aforementioned user attribute-based access permission registration module can provide administrator(s) with information regarding access attempts and retrievals for specific data blocks, as well as the users who attempted such access. It can also support the management and tracking of the overall access history of users to blocks. Furthermore, in the event of an access failure by a specific user, an alarm can be triggered via an app linked to the administrator's mobile blockchain wallet. The system can be configured to allow administrators to restrict access to all or part of the data for the file where the failure occurred. Additionally, users who have attempted multiple connections or failed to access data can be separately listed and managed, and this list information can also be shared with administrators. Administrators permitted to view this information may modify or remove the details of specific users listed in the list upon obtaining consent from a certain percentage of members. This module can prevent access to specific data through automatic or manual methods. In the manual method, an administrator directly blocks access to specific users or data; in the automatic method, access to specific users or data is blocked without additional action by the administrator if conditions set by the administrator are met. For example, access to specific data becomes impossible after the Nth attempt, and N and the conditions may be registered or modified by the administrator. Alternatively, conditions such as a minimum time for a connection attempt or a maximum time required for the Nth attempt can be entered, and access may be automatically restricted when all conditions are met or when at least a specific condition is satisfied. In this case, the system can notify the terminal attempting access that data access is impossible based on specific conditions, and this information can be conveyed to the user and / or all users and / or administrators.

[0084] The policy-based access control document automatic generation unit supports the system in automatically generating and processing access authority attributes / types according to a structured document format, enabling administrators to manage access rights in a consistent manner within the system. At this time, all policy-based access control documents are registered regardless of conflicts; however, if a conflict arises due to an actual user's access request, the request is processed by obtaining multiple signatures from the administrators who registered the relevant policy. Whenever a new policy-based access control document is registered, it checks for conflicts with existing policy-based access control documents. If a conflict occurs, the conflict can be resolved by modifying and saving both the existing and new policy documents using multiple signatures from the administrator who registered the existing policy and the administrator who registered the new policy.

[0085] The zero-trust based access verification module (B) in FIG. 3 can support different blockchain types of networks depending on the user's authentication information or type, and can notify the confidential file access management module (C) that valid access is triggered by comparing the access request for data with the access policy of the target data. The configuration of the transaction generated by the module may differ depending on the blockchain network type.

[0086] Multiple transaction logs may be generated regardless of the user type or the type of target data the user attempts to access. These multiple transactions can be generated in a number equal to the least common multiple of the number of user types or target data types the user attempts to access. This is intended to avoid violating the fairness of the blockchain, to ensure that every load can fairly know which transactions a specific user has performed, and to indicate how the system processed the transaction based on the actual user type used or the type of target data the user attempted to access. While this may result in a massive amount of data information, it supports fairness and dynamic control within the system. This is because each user can implicitly calculate the terminal type or user type supported by the system. For example, if the user types supported by the system can be set to "General" or "Potential Perpetrator" and data types are divided into "General" and "Confidential," the system generates up to four logs in a parallel structure upon a specific user's request and shares information regarding all logs with the user. Furthermore, based on conditions set by the administrator or the system, a portion of the logs associated with the user and the target data type the user attempts to access are selected and updated. Logs that do not meet the conditions may be stored with previous transaction data retained or with some hash values ​​altered. In this case, other users may be able to infer or calculate the structure and decision-making methods of the blockchain supported by the system through these logs. Additionally, the hash value for each log may be a single value or multiple hash values ​​for each log.In other words, since hash values ​​include multiple values ​​rather than a single value per transaction as in existing blockchains, system overhead may increase; however, this offers enhanced reliability and protection against data corruption. Furthermore, it enables dynamic control between systems, and users can improve their understanding of the system through the relevant logs.

[0087] The Confidential File Access Management Module supports access to actual data based on the results of the Zero Trust-based Access Verification Module, and this module can issue tokens separately to users permitted to access the data. Here, token issuance may be limited to all permitted users for data requiring verification, or issued to all permitted users regardless of the data requiring verification. Furthermore, tokens issued to a specific user may be revoked if a certain percentage of consent is obtained from users excluding the token holder. In this case, the revocation procedure is disclosed to all token holders, and voting rights regarding the revocation can also be conveyed via the same information. Additionally, this procedure can be manually triggered by an administrator or performed automatically when specific conditions are met. For example, if a specific user is continuously denied permission to access target data, a vote on whether to revoke the tokens issued to that user can be automatically sent to all token holders, and the revocation measure can be carried out based on the voting results.

[0088] A separate reward token may be issued for users who have transparently viewed target data without any modification or change history. The issued token may be identical to the token described in Proposal #4 above, or it may be a separately issued token. The reward may vary depending on the number of tokens held, and such reward may be the right to access and manage the data. Alternatively, it may be used as a measure of user trustworthiness, or voting rights in Proposal 4 may be obtained in proportion to the number of tokens held. Furthermore, if the holding of the token satisfies specific conditions, the user may be replaced as an administrator rather than a general user. Therefore, the token may be used for user management purposes. For example, if there is no change in the number of tokens held for a certain period of time or interval, the access rights for that user may be automatically revoked, and access permission may be restored to a user whose access rights have been revoked through a re-registration / approval process.

[0089] The access verification module can generate a plurality of blockchain transactions including access requests corresponding to the least common multiple of the number of types of the user type and the number of data types of the file targeted by the access request.

[0090] The access management module may issue a first access token to a first user, and if consent for the retrieval of the first access token is obtained from a preset number of multiple users excluding the first user, it may reclaim the first access token and share information regarding the consent for the retrieval of the first access token with all access token owners.

[0091] FIG. 4 is a diagram illustrating a method for providing a blockchain-based zero-trust confidential file access rights management service according to one embodiment of the present specification.

[0092] FIG. 4 shows an example in which some of the proposals of the present invention are applied. The proposals described in the present invention can be used individually or in combination of multiple parts, and can be applied with extension regardless of the module. Furthermore, they can also be applied with extension to systems targeting various services, such as material management and financial services.

[0093] The operation according to the embodiments of this specification may be implemented as a computer-readable program or code on a computer-readable recording medium. A computer-readable recording medium includes all types of recording devices in which data that can be read by a computer system is stored. Additionally, a computer-readable recording medium may be distributed across networked computer systems, allowing computer-readable programs or code to be stored and executed in a distributed manner.

[0094] When the embodiment is implemented in software, the above-described technique may be implemented as a module (process, function, etc.) that performs the above-described function. The module may be stored in memory and executed by a processor. The memory may be located inside or outside the processor and may be connected to the processor by various well-known means.

[0095] In addition, computer-readable recording media may include hardware devices specifically configured to store and execute program instructions, such as ROM, RAM, and flash memory. Program instructions may include machine code, such as that generated by a compiler, as well as high-level language code that can be executed by a computer using an interpreter, etc.

[0096] Some aspects of this specification have been described in the context of a device, but may also be described according to a corresponding method, wherein a block or device corresponds to a method step or a feature of a method step. Similarly, aspects described in the context of a method may also be described according to a corresponding block or item or a feature of a corresponding device. Some or all of the method steps may be performed by (or using) a hardware device, such as, for example, a microprocessor, a programmable computer, or an electronic circuit. In some embodiments, one or more of the most important method steps may be performed by such a device.

[0097] In the embodiments, a programmable logic device (e.g., a field-programmable gate array) may be used to perform some or all of the functions of the methods described herein. In the embodiments, the field-programmable gate array may operate with a microprocessor to perform one of the methods described herein. Generally, it is preferable that the methods be performed by some hardware device.

[0098] Although the foregoing has been described with reference to preferred embodiments of this specification, those skilled in the art will understand that various modifications and changes can be made to this specification without departing from the spirit and scope of the specification as set forth in the following claims.

Claims

1. In a blockchain-based zero-trust confidential file access control system, An access authority registration module that obtains configuration information for a user type from an administrator terminal, determines the user type based on the configuration information for the user type, and sets a blockchain network type based on the user type; An access verification module that generates an access request including the access authority attributes of the above-mentioned user and determines whether access to the above-mentioned access request is possible; and Includes an access management module that verifies the integrity of the file, Blockchain-based zero-trust confidential file access control system.

2. In Paragraph 1, The above access permission registration module is, An administrator interface that obtains setting information regarding the access permission attribute for the file from the administrator terminal; An access control document automatic generation unit that generates a document for the access permission attribute based on setting information for the access permission attribute; A blockchain integration unit that generates and signs a transaction to register a document regarding the above access authority attribute on the blockchain, and transmits the transaction to register a document regarding the above access authority attribute on the blockchain to a blockchain network where an access authority smart contract is deployed; and A smart contract register comprising a document for the above access authority attribute to be registered as the above access authority smart contract, Blockchain-based zero-trust confidential file access control system.

3. In Paragraph 2, The blockchain integration unit above provides notification information to the administrator terminal when there is an access request corresponding to a preset threshold within a preset threshold time after an access request for a specific file has failed. Blockchain-based zero-trust confidential file access control system.

4. In Paragraph 2, The above access verification module is, An access request generation unit that generates the access request including the access authority attributes of the above user; A blockchain transaction generation and transmission unit that generates and signs a blockchain transaction including the access request and transmits the blockchain transaction including the access request to the blockchain network; An access request verification unit that verifies whether the user can access the file requested by the user based on a document regarding the access authority attribute registered in the blockchain smart contract and transmits the access status to the access management module; and Includes an access history management unit that stores the details of the access request and the verification results for the access request. Blockchain-based zero-trust confidential file access control system.

5. In Paragraph 4, The above access management module is, An access token issuance and management unit that issues an access token based on the accessibility status obtained from the access verification module; and A verification unit for authenticity that verifies integrity and file authenticity based on a hash stored in a blockchain based on the access token mentioned above. Blockchain-based zero-trust confidential file access control system.

6. In Paragraph 5, The above access request verification unit is, In the event that a document regarding the first access permission attribute based on the setting information for the first access permission attribute for the above file conflicts with a document regarding the second access permission attribute based on the setting information for the second access permission attribute for the above file, Requesting signatures from both the first administrator terminal that provided setting information for the first access authority attribute and the second administrator terminal that provided setting information for the second access authority attribute, and Verifying the access request for the file based on the signature of the first administrator terminal and the signature of the second administrator terminal, Blockchain-based zero-trust confidential file access control system.

7. In Paragraph 5, The above smart contract register is, When registering a document regarding a first access permission attribute based on setting information for a first access permission attribute for the above file, and then registering a document regarding a second access permission attribute based on setting information for a second access permission attribute for the above file, Check whether there is a conflict between the document regarding the first access right attribute and the document regarding the second access right attribute, and In the event that the document regarding the first access authority attribute and the document regarding the second access authority attribute conflict, a signature is requested from both the first administrator terminal that provided the configuration information for the first access authority attribute and the second administrator terminal that provided the configuration information for the second access authority attribute, and Modifying the document regarding the first access authority attribute and the document regarding the second access authority attribute based on the signature of the first administrator terminal and the signature of the second administrator terminal, Blockchain-based zero-trust confidential file access control system.

8. In Paragraph 5, The above access verification module is, Generating a plurality of blockchain transactions including the access requests corresponding to the least common multiple of the number of types of the above-mentioned user types and the number of data types of the file targeted by the access requests, Blockchain-based zero-trust confidential file access control system.

9. In Paragraph 5, The above access management module is, Issue a first access token to the first user, and If consent for the retrieval of the first access token is obtained from a preset number of multiple users excluding the first user, the first access token is retrieved, and Sharing information regarding consent to reclaim the above-mentioned first access token with all access token owners, Blockchain-based zero-trust confidential file access control system.

Citation Information

Patent Citations

  • User management method based on smart contract and related device

    CN116595502A

  • User data privacy protection method for financial management system

    CN118296655A

  • Authority delegation system, control method thereof, authorization server, and program

    JP2017091221A

  • Revoking access to the network

    JP2023518004A

  • An electronic device for generating a map and method for controlling the same

    KR1020250001483A