System and method for blockchain-based access control and ai-assisted de-identification of confidential data

WO2026202715A1PCT designated stage Publication Date: 2026-10-01CHINTHAPALLI MRUNAL TEJA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2026/052803
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-24
Filing Date
2026-03-24
Publication Date
2026-10-01

Smart Images

  • Figure IB2026052803_01102026_PF_FP_ABST
    Figure IB2026052803_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a system (102) and method (200) for blockchain-based access control and artificial intelligence-assisted de-identification of data. The system (100) includes a processor (104) that enables receiving data from one or more sources, analyzing the data using an AI module (115) to identify sensitive attributes, and applying masking, encryption, or tokenization for de-identification. The AI module (115) dynamically updates de-identification policies based on compliance requirements. The system records metadata, transformation logs, and cryptographic hash values onto a blockchain network, ensuring transparency and immutability. Access control is managed through blockchain-based smart contracts that define permission rules and access levels. Additionally, an automated smart licensing framework facilitates regulatory approvals and compliance enforcement across industries. The AI module (115) is continuously refined using federated learning and advanced cryptographic techniques to enhance security and regulatory adherence. The system ensures secure data sharing while preserving privacy and compliance in a decentralized environment.
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEM AND METHOD FOR BLOCKCHAIN-BASED ACCESS CONTROL AND ALASSISTED DE-IDENTIFICATION OF CONFIDENTIAL DATATECHNICAL FIELD

[0001] The present disclosure relates to the field of artificial intelligence (Al) and blockchain technologies. More particularly, the present disclosure pertains to a system and method for blockchain-based access control and Al-assisted data de-identification, enabling secure data sharing, privacy preservation, and dynamic regulatory compliance across multiple sectors.BACKGROUND

[0002] Background description includes information that may be useful in understanding the present invention. It is not an admission that any of the information provided herein is prior art or relevant to the presently claimed disclosure, or that any publication specifically or implicitly referenced is prior art.

[0003] With the increasing reliance on digital technologies, organizations across various industries, including healthcare, finance, insurance, pharmaceuticals, and government sectors, generate and process vast amounts of sensitive data. Ensuring data privacy, regulatory compliance, and secure access control has become a significant challenge, especially with the growing complexity of regulatory frameworks and cross-border data sharing.

[0004] Traditional data privacy and access control solutions rely on centralized architectures, which introduce vulnerabilities such as single points of failure, unauthorized access, and compliance risks. Conventional de-identification techniques, including static masking and pseudonymization, often fail to adapt to evolving regulatory requirements, leading to increased exposure to data breaches and non-compliance penalties. Additionally, access control mechanisms primarily rely on role-based or rule-based frameworks that lack flexibility and do not dynamically adjust to changing risk factors.

[0005] Existing approaches face several drawbacks. Rule-based access control systems cannot effectively handle dynamic regulatory changes and industry-specific compliance mandates. Centralized de-identification frameworks introduce inefficiencies and security vulnerabilities, making them prone to unauthorized re-identification attacks. Moreover, current data governance mechanisms lack transparency, auditability, and real-time enforcement,leading to challenges in tracking data usage, verifying access rights, and ensuring accountability.

[0006] Therefore, there is a need for a decentralized and intelligent system that enhances data privacy, ensures regulatory compliance, and provides secure access control across multiple industries.OBJECTS OF THE PRESENT DISCLOSURE

[0007] A general object of the present disclosure is to provide blockchain-based access control with Al-assisted de -identification to enhance data security and privacy.

[0008] An object of the present disclosure is to provide an adaptable Al and blockchain-powered system that delivers sector-specific insights, risk assessments, and compliance automation across diverse industries, including healthcare, finance, pharmaceuticals, supply chain, energy, telecommunications, defense, and governance.

[0009] Another object of the present disclosure is to provide real-time risk evaluation using machine learning algorithms to prevent fraud, security breaches, and compliance violations.

[0010] Another object of the present disclosure is to provide continuous Al model learning to dynamically adapt to evolving threats, data patterns, and industry regulations.

[0011] Another object of the present disclosure is to provide immutable blockchain audit trails for tracking de -identification processes, access attempts, and data transformations.

[0012] Another object of the present disclosure is to provide decentralized Al model training with secure aggregation techniques to preserve data sovereignty and confidentiality.

[0013] Another object of the present disclosure is to provide automated smart licensing frameworks that streamline regulatory approvals and enforce dynamic licensing conditions.

[0014] Another object of the present disclosure is to provide zero-knowledge proofbased identity verification for secure, privacy-preserving access control.

[0015] Another object of the present disclosure is to provide jurisdiction-aware Al policy engines that apply adaptive compliance strategies based on regional and industryspecific mandates.

[0016] Another object of the present disclosure is to provide encrypted data sharding to enable secure and efficient cross-border data transfers.

[0017] Yet another object of the present disclosure is to provide predictive analytics to proactively detect anomalies, assess entity risk scores, and trigger automated compliance actions.SUMMARY

[0018] Aspects of the present disclosure relate to the field of artificial intelligence (Al) and blockchain technologies. More particularly, the present disclosure pertains to a system and method for blockchain-based access control and Al-assisted data de-identification, enabling secure data sharing, privacy preservation, and dynamic regulatory compliance across multiple sectors.

[0019] An aspect of the proposed disclosure pertains to a system for blockchain-based access control and artificial intelligence-assisted de-identification of data. The system includes a processor configured to analyze the received data using an artificial intelligence (Al) module configured to parse structured data and unstructured data, apply natural language processing (NLP) techniques to recognize personal identifiers, utilize pre-trained machine learning models to classify and label sensitive attributes and map the identified sensitive attributes to predefined categories of personally identifiable information (PII). The Al module evaluates the risk level of sensitive attributes using predictive analytics, assessing fraud risk, regulatory violations, operational inefficiencies, security vulnerabilities, and emerging threats across multiple industries. Further, the processor generates de-identified data by performing masking, encryption, or tokenization based on the applied classification, dynamically updating de-identification policies to comply with evolving regulatory requirements across jurisdictions.

[0020] In an aspect, the system records the de-identification process by storing metadata, transformation logs, and cryptographic hash values onto a blockchain network to ensure auditability and integrity.

[0021] In an aspect, the system manages access control by verifying entity identity and access rights through blockchain-based smart contracts that define permission rules and access levels. Authorized entities are granted access to the de-identified data based on validated access rights.

[0022] In an aspect, the system further enables an automated smart licensing framework using the blockchain network and the Al module to streamline regulatory approvals, enforce dynamic licensing conditions, facilitate jurisdictional compliance, and automate governance protocols across multiple industries. The Al module employs pre-trained and continuously evolving machine learning models trained on historical datasets, updating its parameters through incremental learning and validating identified sensitive attributes with confidence scores to minimize false positives.

[0023] In an aspect, to assess the risk level of identified sensitive attributes, the processor analyzes historical and received data, applies machine learning algorithms to detect patterns and anomalies, classifies risk levels based on predefined and evolving parameters, and assigns risk scores using weighted factors. The risk score is updated continuously through adaptive learning, and if it exceeds a predefined threshold, the system triggers alerts, initiates Al-driven compliance reviews, or executes smart contract-based enforcement actions.

[0024] In an aspect, the system records the de -identification process by collecting metadata, including timestamps, entity identifiers, data categories, and jurisdictional compliance parameters, generating transformation logs detailing applied de-identification techniques and rule sets and evaluating hash values for the original and de-identified data. The collected metadata, transformation logs, and cryptographic hash values are stored on a blockchain ledger to create an immutable audit trail.

[0025] In an aspect, the system facilitates secure Al model training by enabling local and decentralized training across connected computing devices. It aggregates model updates using techniques such as Secure Multi-Party Computation (SMPC), Fully Homomorphic Encryption (FHE), Functional Encryption (FE), and Federated Learning with Secure Aggregation (FLSA). The system ensures compliance with global healthcare, financial, insurance, pharmaceutical, government security, and regulated industry frameworks while preserving data sovereignty. Blockchain-based audit trails, Zero-Knowledge Proof-based verifications (ZK-ML), and federated Al governance mechanisms verify Al model training integrity, fairness assessments, and adversarial robustness. The Al model updates, training iterations, risk assessments, and consent records are recorded on the blockchain network.

[0026] In an aspect, to enable the automated smart licensing framework, the processor retrieves regulatory requirements and licensing conditions from external databases, predefined rule repositories, or real-time regulatory updates. It validates received data against regulatory requirements, wherein blockchain-based smart contracts autonomously execute, enforce, and update industry-specific licensing conditions across regulated industries. Smart contracts are generated and executed to automatically grant, revoke, or renew licenses based on real-time regulatory validation, jurisdictional compliance rules, and risk-based Al assessments. Licensing transactions, approval timestamps, regulatory attestations, and compliance decisions are recorded on the blockchain ledger. The system triggers alerts, automated compliance audits, and smart contract-based revocation enforcement when Al-driven risk detection identifies regulatory violations, unauthorized access attempts, or an entity’s risk score exceeding the predefined threshold.

[0027] In an aspect, the system also enhances identity verification by generating cryptographic proofs using Decentralized Identifiers (DIDs) and Zero-Knowledge Proof (ZKP) protocols. Entities, organizations, and digital assets are authenticated through blockchain-based ZKP protocols for decentralized access control. Access to sensitive attributes is granted only upon successful ZKP verification, and all authentication events, access attempts, and proof verifications are recorded on the blockchain network.

[0028] In an aspect, to support compliance with jurisdictional and industry-specific mandates, the system classifies and tags received data based on sensitivity levels and regulatory requirements. Al-driven policy engines dynamically enforce regional and cross-border compliance rules, continuously predicting regulatory risks and automating policy adjustments. The system encrypts and partitions data into smaller segments (shards) for secure cross-border transfers while maintaining an immutable ledger of data flows, regulatory checks, and consent logs.

[0029] Another aspect of the proposed disclosure pertains to a method for blockchainbased access control and artificial intelligence-assisted de-identification of data. The method includes receiving, by a processor, data associated with an entity from one or more data sources and analyzing the received data using an artificial intelligence (Al) module. The Al module is configured to parse structured data and unstructured data, apply natural language processing (NLP) techniques to interpret free-text data and recognize personal identifiers, utilize pretrained machine learning models to classify and label sensitive attributes, map the identified sensitive attributes to predefined categories of personally identifiable information (PII), and evaluate the risk level of the identified sensitive attributes using predictive analytics. The Al module dynamically assesses risk factors, including fraud risk, regulatory violations, operational inefficiencies, security vulnerabilities, and emerging threats across multiple industries.

[0030] The method further includes generating de-identified data by performing masking, encryption, or tokenization to replace the identified sensitive attributes based on classification, wherein the Al module dynamically updates de-identification policies based on evolving compliance requirements across multiple jurisdictions. The de-identification process is recorded by storing metadata, transformation logs, and cryptographic hash values onto a blockchain network. The method also includes managing access control by verifying entity identity and access rights through blockchain-based smart contracts that define permission rules and access levels, facilitating the sharing of de-identified data with authorized entities based on validated access rights. Additionally, the method enables an automated smartlicensing framework using the blockchain network and the Al module to streamline regulatory approvals, enforce dynamic licensing conditions, facilitate jurisdictional compliance, and automate governance protocols across multiple industries.

[0031] In an aspect, the Al module utilizes pre-trained and continuously evolving machine learning models by loading domain-specific models trained on historical datasets, updating parameters through incremental learning, and validating identified sensitive attributes with confidence scores to reduce false positives. The method further includes evaluating the risk level of identified sensitive attributes by analyzing historical and received data, applying machine learning algorithms to detect patterns, recognizing anomalies, classifying risk levels based on predefined and dynamically evolving parameters, assigning risk scores to sensitive attributes or entities using weighted factors, and continuously updating risk scores through adaptive learning. If the risk score exceeds a predefined threshold, the system triggers alerts, initiates Al-driven compliance reviews, or executes smart contract-based enforcement actions.

[0032] In an aspect, the de-identification process is recorded by collecting metadata, including timestamps, entity identifiers, data categories, and jurisdictional compliance parameters for each de-identification operation. Additionally, transformation logs are generated detailing the applied de-identification techniques, attribute changes, and rule sets, and hash values for both the received data and de-identified data are evaluated. This collected metadata, transformation logs, and cryptographic hash values are stored on a blockchain ledger to create an immutable audit trail.

[0033] In an aspect, the method further includes training the model locally on connected computing devices and across decentralized networks, aggregating model updates using Secure Multi-Party Computation (SMPC), Fully Homomorphic Encryption (FHE), Functional Encryption (FE), and Federated Learning with Secure Aggregation (FLSA). The system ensures compliance with global healthcare, financial, insurance, pharmaceutical, government security, and regulated industry frameworks while preserving data sovereignty. Regulators, auditors, and compliance authorities can verify model training integrity, fairness assessments, and adversarial robustness through blockchain-based audit trails, Zero-Knowledge Proof-based verifications (ZK-ML), and federated Al governance mechanisms. The machine learning model updates, training iterations, risk assessments, and consent records are also recorded on the blockchain network.

[0034] In an aspect, to enable the automated smart licensing framework, the method includes retrieving regulatory requirements and licensing conditions from external databases, predefined rule repositories, or real-time regulatory updates. It further involves validatingreceived data for compliance with retrieved regulatory requirements, wherein blockchainbased smart contracts autonomously execute, enforce, and update industry-specific licensing conditions across regulated industries. The smart contracts automatically grant, revoke, or renew licenses based on real-time regulatory validation, jurisdictional compliance rules, and risk-based Al assessments. Additionally, licensing transactions, approval timestamps, regulatory attestations, and compliance decisions are recorded on the blockchain ledger. The system triggers alerts, automated compliance audits, and smart contract-based revocation enforcement when the

[0035] model detects regulatory violations, unauthorized access attempts, or when an entity's risk score exceeds the predefined threshold.

[0036] In an aspect, the method further includes generating cryptographic proofs for identity verification using Decentralized Identifiers (DIDs) and Zero-Knowledge Proof (ZKP) protocols. Entities, organizations, and digital assets are authenticated through blockchain-based ZKP protocols for decentralized access control. Access to sensitive attributes is granted only upon successful ZKP verification, and all authentication events, access attempts, and proof verifications are recorded on the blockchain network.

[0037] In an aspect, the method further includes classifying and tagging received data based on jurisdictional requirements, industry-specific compliance mandates, and data sensitivity levels. The system applies regional and cross-border compliance rules dynamically through Al-driven policy engines, and the model continuously predicts emerging regulatory risks, automates policy adjustments, and enforces adaptive compliance strategies. To ensure secure cross-border data transfers, the method includes encrypting and partitioning data into smaller segments (shards). An immutable ledger of data flows, regulatory checks, and consent logs is maintained for transparency and compliance verification.

[0038] Various objects, features, aspects, and advantages of the inventive subject matter will become more apparent from the following detailed description of preferred embodiments, along with the accompanying drawing figures in which like numerals represent components.BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The accompanying drawings are included to provide a further understanding of the present disclosure and are incorporated in and constitute a part of this specification. The drawings illustrate exemplary embodiments of the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0040] FIG. 1 illustrates an exemplary block diagram of a system for blockchain-based access control and artificial intelligence-assisted de-identification of data, in accordance with an embodiment of the present disclosure.

[0041] FIG. 2 illustrates an exemplary flow chart of a method for blockchain-based access control and artificial intelligence-assisted de-identification of data, in accordance with an embodiment of the present disclosure.

[0042] FIG. 3 illustrates an exemplary computer system in which or with which embodiments of the present disclosure are utilized in accordance with some embodiments of the present disclosure.DETAILED DESCRIPTION

[0043] The following is a detailed description of embodiments of the disclosure depicted in the accompanying drawings. The embodiments are in such detail as to clearly communicate the disclosure. However, the amount of detail offered is not intended to limit the anticipated variations of embodiments; on the contrary, the intention is to cover all modifications, equivalents, and alternatives falling within the spirit and scope of the present disclosures as defined by the appended claims.

[0044] Embodiments explained herein relate to the field of artificial intelligence (Al) and blockchain technologies. More particularly, the present disclosure pertains to a system and method for blockchain-based access control and Al-assisted data de-identification, enabling secure data sharing, privacy preservation, and dynamic regulatory compliance across multiple sectors. Various embodiments with respect to the present disclosure will be explained in detail with reference to FIGs. 1-3.

[0045] Referring to FIG. 1, an exemplary block diagram (100) of a system (102) for blockchain-based access control and artificial intelligence-assisted de-identification of data is disclosed. The proposed system (102) for blockchain-based access control and artificial intelligence-assisted de-identification of data ensures secure data handling, privacy preservation, and regulatory compliance across diverse industries. This system can be applied in multiple sectors, including healthcare, finance, pharmaceuticals, regulatory compliance, supply chain, energy, telecommunications, and defense, enabling secure data access, risk assessment, fraud detection, and optimized decision-making. The system (102) includes one or more processors (104), a memory (106), and an interface(s) (108). The processor (104) may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuitries, and / or any devices that manipulate databased on operational instructions. Among other capabilities, the one or more processor(s) (104) may be configured to fetch and execute computer-readable instructions stored in the memory (106) of the system (102). The memory (106) may store one or more computer-readable instructions or routines, which may be fetched and executed for de-identification process. The memory (106) may include any non-transitory storage device including, for example, volatile memory such as Random-Access Memory (RAM), or non-volatile memory such as Erasable Programmable Read-Only Memory (EPROM), flash memory, and the like.

[0046] The interface(s) (108) may include a variety of interfaces, for example, a variety of interfaces, for example, interfaces for data input and output devices, referred to as I / O devices, storage devices, and the like. The interface(s) (108) may facilitate communication of the system (102) with various devices coupled to it. The interface(s) (108) may also provide a communication pathway for one or more components of the system (102). Examples of such components include but are not limited to, processing engine(s) (110) and a database (112). The database (112) may include data that is either stored or generated as a result of functionalities implemented by any of the components of the processing engine(s) (110).

[0047] In an embodiment, the processing engine(s) (110) may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing engine(s) (110). In examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the processing engine(s) (110) may be processor executable instructions stored on a non-transitory machine -readable storage medium and the hardware for the one or more processor(s) (104) may comprise a processing resource (for example, one or more processors), to execute such instructions. In the present examples, the machine-readable storage medium may store instructions that, when executed by the processing resource, implement the processing engine(s) (110). In such examples, the system (102) may include the machine -readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the system (102) and the processing resource. In other examples, the processing engine(s) (110) may be implemented by an electronic circuitry. The processing engine(s) (110) may include a data acquisition module (114), an artificial intelligence (Al) module (115) and other module(s) (124). The other module(s) (124) may implement functionalities that supplement applications / fimctions performed by the processing engine(s) (110). The Al module (115) includes an analysis and risk evaluation module (116) a de-identification and encryption module (118), an access control and smart contracts module (120), and a training module (122).

[0048] In an embodiment, the data acquisition module (114) receives data associated with an entity from one or more data sources, including enterprise databases, unstructured data repositories, loT devices, regulatory and compliance databases, blockchain networks, and external APIs. These sources provide structured data and unstructured data, real-time sensor inputs, legal records, transaction histories, and third-party insights, enabling comprehensive data analysis and secure processing.

[0049] In an embodiment, the analysis and risk evaluation module (116) analyses and parses the received data to extract structured data (e.g., tabular records, database entries) from unstructured data (e.g., free text, scanned documents, emails). This enables efficient processing and categorization. In addition, the analysis and risk evaluation module (116) applies natural language processing (NLP) techniques to interpret free-text data, extract key information, and recognize personal identifiers such as names, addresses, and contact details. This helps in understanding context and meaning within unstructured data sources.

[0050] In an embodiment, the analysis and risk evaluation module (116) utilizes pretrained machine learning models (interchangeably referred to as Al model, hereinafter) to classify and label sensitive attributes. These Al models are trained on diverse datasets to identify and categorize personally identifiable information (PII). The module also classifies and tags received data based on jurisdictional requirements, industry-specific compliance mandates, and data sensitivity levels to ensure regulatory compliance.

[0051] The analysis and risk evaluation module (116) applies regional and cross-border compliance rules dynamically through Al-driven policy engines. It predicts emerging regulatory risks, automates policy adjustments, and enforces adaptive compliance strategies. To ensure secure cross-border transfers, it encrypts and partitions data into smaller segments, preventing unauthorized access and enhancing privacy. The module maintains an immutable ledger of data flows, regulatory checks, and consent logs for auditability. It also maps identified sensitive attributes to predefined PII categories, ensuring structured de-identification and compliance.

[0052] In addition, the analysis and risk evaluation module (116) evaluates risk levels associated with sensitive attributes using predictive analytics, considering fraud risk, regulatory violations, operational inefficiencies, security vulnerabilities, and emerging threats across industries like healthcare, finance, insurance, telecommunications, supply chain, energy, aerospace, defense, and government sectors. For risk evaluation, the analysis and riskevaluation module (116) analyzes historical and real-time data, covering risks such as fraud likelihood, patient health risks, disease progression, insurance claim risks, financial compliance violations, investment risks, cybersecurity threats, supply chain disruptions, and operational inefficiencies. Machine learning algorithms detect patterns, recognize anomalies, and classify risks based on evolving parameters. The Al model continuously refines assessments by incorporating new fraud patterns, medical advancements, financial regulations, and cybersecurity intelligence.

[0053] Further, the analysis and risk evaluation module (116) assigns dynamic risk scores to sensitive attributes, entities, or transactions based on weighted factors, including Decentralized Identifier (DID)-based digital identity verification, data sensitivity, behavioral patterns, access frequency, historical security incidents, and operational anomalies. Al updates risk scores in real time, integrating security updates, system usage patterns, cross-industry risk indicators, and regulatory changes. Adaptive learning techniques continuously improve risk assessments across financial systems, healthcare, supply chains, energy grids, manufacturing ecosystems, and emerging technologies.

[0054] If a risk score exceeds a predefined threshold, the module triggers automated alerts, initiates Al-driven compliance reviews, or executes smart contract-based enforcement actions. The Al system dynamically adjusts security protocols, restricts access, suspends high-risk transactions, or initiates regulatory reporting. These actions ensure proactive risk mitigation, regulatory adaptation, and compliance enforcement across financial, healthcare, supply chain, manufacturing, digital governance, and emerging technology sectors.

[0055] In an embodiment, the de-identification and encryption module (118) generates de-identified data by applying masking, encryption, or tokenization techniques to replace sensitive attributes. It ensures compliance with evolving privacy laws, financial governance standards, industry regulations, and cross-border data protection frameworks. The module updates de-identification policies to align with regulatory frameworks such as HIPAA, GDPR, DPDP, SEC, FATF, ISO 27001, PIPL, and LGPD. To ensure compliance and data integrity, the module records the de-identification process by securely storing metadata, transformation logs, and cryptographic hash values on a blockchain network. This provides immutable data tracking, regulatory transparency, and compliance validation across healthcare, finance, insurance, pharmaceutical research, supply chains, telecommunications, critical infrastructure, and government audits.

[0056] In an embodiment, the de-identification and encryption module ( 118)collects metadata, including timestamps, entity identifiers, data categories, and jurisdictionalcompliance parameters. Al analyzes metadata to ensure regulatory adherence, detect anomalies, and validate compliance. The system continuously adapts to changing legal requirements and compliance frameworks.

[0057] The de -identification and encryption module (118)generates transformation logs detailing de -identification techniques, attribute modifications, and rule sets. Zero-Knowledge Proof (ZKP) authentication and privacy-preserving cryptographic verification enable auditors and regulatory bodies to verify compliance without exposing raw data. This supports cross-industry compliance auditing in healthcare, finance, insurance, supply chain, government, and other regulated industries.

[0058] In addition, to maintain security, the de-identification and encryption module (118)evaluates hash values for received and de-identified data. Al dynamically validates compliance updates, identifies security risks, and ensures regulatory enforcement across global compliance frameworks. The system provides real-time audit readiness, fraud detection, policy verification, risk-adaptive security monitoring, and operational integrity assessments across industries.

[0059] Further, metadata, transformation logs, and cryptographic hash values are stored on a blockchain ledger, creating an immutable audit trail. The use of Decentralized Identifiers (DIDs) facilitates self-sovereign identity verification, access control, credential validation, and regulatory tracking. The system ensures privacy-preserving identity authentication, secure transaction validation, and automated compliance enforcement across multiple industries. Al dynamically updates identity verification policies and compliance parameters to align with jurisdictional and cross-border regulations.

[0060] In an embodiment, the access control and smart contracts module (120) manages access control by verifying entity identities and access rights through blockchainbased smart contracts. These contracts define permission rules and access levels, ensuring secure data access across industries. Blockchain-based smart contracts enforce role-based access control, allowing individuals to manage permissions through a user-controlled application. The access control and smart contracts module (120) utilizes DIDs for secure access, enabling users to share medical records for second opinions, participate in research, engage in clinical trials, and receive automated follow-ups. Blockchain-enforced policies and DID-based authentication prevent unauthorized access. The system adapts to evolving jurisdictional regulations, ensuring compliance across healthcare, finance, insurance, pharmaceutical research, supply chain, and government sectors.

[0061] The access control and smart contracts module (120) integrates with existing industry infrastructures, including Electronic Health Records (EHR) systems, financial risk management platforms, supply chain monitoring networks, pharmaceutical research databases, and digital identity frameworks. Al-driven compliance validation ensures secure, cross-domain data exchange and compliance automation. Standardized data exchange protocols maintain interoperability across industries, such as HL7 FHIR and DICOM for healthcare, ISO 20022 for finance, GS 1 for supply chains, and digital identity frameworks for government and defense applications.

[0062] In addition, to enhance security, the module generates cryptographic proofs for identity verification using DIDs and ZKP-based authentication. This ensures tamper-proof validation without exposing personally identifiable information. The system enforces riskbased authentication, detecting anomalous verification attempts and triggering adaptive security measures. Al-driven monitoring ensures compliance with financial KYC / AML regulations, healthcare data access policies, and digital identity protection frameworks.

[0063] Further, the access control and smart contracts module (120) authenticates entities through blockchain-based ZKP protocols for decentralized access control. ZKP verification enables secure authentication for individuals, organizations, smart contracts, and loT devices. Al-driven monitoring detects high-risk authentication attempts and enforces adaptive security measures like multi-factor authentication. This strengthens access control mechanisms across industries, ensuring security and compliance.

[0064] The system ensures adherence to global and jurisdictional regulatory frameworks, including HIPAA, GDPR, DPDP, SEC, FATF, RBI, CDSCO, ISO 27001, and other applicable privacy and financial compliance laws. Sensitive attributes are accessible only after successful ZKP verification, ensuring data privacy and regulatory compliance.

[0065] In an embodiment, authentication events, access attempts, and proof verifications are recorded on a blockchain network, ensuring tamper-proof auditability. AI-driven compliance tracking analyzes authentication patterns, detects anomalies, prevents unauthorized access, and triggers adaptive security policies based on real-time risk assessments. The system generates automated regulatory audit reports, fraud risk insights, and compliance verifications across financial, insurance, healthcare, supply chain, government, pharmaceutical, and digital identity platforms.

[0066] In an embodiment, the access control and smart contracts module (120) facilitates sharing of de-identified data with authorized entities based on validated access rights. It enables an automated smart licensing framework using blockchain and Al to streamlineregulatory approvals, enforce dynamic licensing conditions, and automate governance across industries. Al-driven compliance validation, smart contracts, and ZKP-based verification ensure real-time risk assessment and jurisdiction-specific licensing enforcement.

[0067] In an embodiment, the access control and smart contracts module (120) retrieves, monitors, and analyzes regulatory requirements and licensing conditions from external databases, predefined rules, and real-time updates. It dynamically adapts licensing policies, predicts regulatory risks, and autonomously applies compliance modifications across industries, ensuring adherence to global standards such as HIPAA, GDPR, DPDP, SEC, FATF, FDA, ISO 27001, Al Act, and NIST Al Risk Framework.

[0068] Further, the access control and smart contracts module (120) validates received data for regulatory compliance. Blockchain-based smart contracts autonomously execute, enforce, and update industry-specific licensing conditions. Al-driven monitoring detects non-compliance, prevents fraudulent approvals, and issues automated alerts. Blockchain-based smart contracts automatically grant, revoke, or renew licenses based on regulatory validation and Al assessments. Licensing transactions, approvals, and compliance decisions are recorded on an immutable ledger. Al-driven monitoring detects anomalies, prevents unauthorized licensing, and enforces compliance. Furthermore, the access control and smart contracts module (120) triggers real-time alerts, automated audits, and enforcement actions when Al detects regulatory violations or compliance risks. Al-driven monitoring predicts risks, detects suspicious activity, and enforces dynamic security restrictions, ensuring cross-border regulatory alignment and jurisdictional enforcement.

[0069] In an embodiment, the training module (122) trains Al models locally on connected computing devices and across decentralized networks using federated learning, secure multi-party computation (MPC), and differential privacy techniques. This allows Al to adapt across enterprises, government agencies, financial institutions, and regulated industries without centralizing sensitive data. Model updates are aggregated using techniques such as Secure Multi-Party Computation (SMPC), Fully Homomorphic Encryption (FHE), Functional Encryption (FE), and Federated Learning with Secure Aggregation (FLSA). Compliance is maintained with global healthcare, financial, insurance, pharmaceutical, government security, and regulated industry frameworks by preserving data sovereignty. Regulators, auditors, and compliance authorities can verify Al model training integrity, fairness assessments, and adversarial robustness through blockchain-based audit trails, Zero-Knowledge Proof-based verifications (ZK-ML), and federated Al governance mechanisms. The system ensures realtime regulatory enforcement, jurisdictional compliance verification, and cross-industry Alaccountability in alignment with global and national Al regulations, including HIPAA (US healthcare), GDPR (EU data protection), DPDP (India), PIPL (China), SEC (US finance), FATF (AML compliance), ISO 27001 (cybersecurity), NIST Al Risk Framework (US), and the EU Al Act. Model updates, training iterations, risk assessments, and consent records are recorded on the blockchain network, enabling automated smart licensing frameworks.

[0070] In an embodiment, the training module (122) utilizes pre-trained and continuously evolving models. It loads domain-specific models trained on historical datasets while enabling federated learning to train Al models across decentralized entities without centralizing sensitive data, ensuring compliance with privacy regulations and industry governance policies. The training module (122)updates model parameters continuously through incremental learning, integrating real-time compliance updates, regulatory changes, anomaly detection signals, emerging security threats, and jurisdictional governance rules to improve predictive accuracy across multiple industries. Identified sensitive attributes are validated with confidence scores to reduce false positives. The Al module applies predictive analytics to dynamically assess risk factors and optimize decision-making across diverse sectors, including healthcare, finance, insurance, pharmaceutical and biotech research, regulatory compliance, supply chain, energy, telecommunications, defense, and critical infrastructure. This ensures Al-driven efficiency in clinical decision-making, fraud detection, risk assessment, regulatory tracking, operational forecasting, cybersecurity, and national security.

[0071] In an exemplary implementation, the proposed system (102) may be used to ensure secure, compliant, and interoperable healthcare data exchange. By integrating Al-driven Protected Health Information (PHI) de-identification, blockchain-based access control, and regulatory compliance automation, the system protects sensitive patient information while enabling seamless data sharing among hospitals, pharmaceutical companies, governments, and research institutions. The core functionality includes Al-powered PHI de-identification, which utilises Natural Language Processing (NLP) and machine learning to detect and remove PHI from unstructured data such as medical notes, reports, and imaging metadata. This ensures that critical medical information remains intact while personal identifiers are anonymized. A hospital uploading medical records to the system would have the Al module automatically scan and remove PHI, making the data suitable for research without exposing patient identities. The processed records are then securely stored, accessible only through blockchain-based authorization.

[0072] The system utilises blockchain-based access control to ensure role-based, permissioned access to healthcare data. Smart contracts manage access requests, while Zero-Knowledge Proofs (ZKP) enable privacy-preserving identity verification without exposing user credentials. Each access attempt and modification is logged in a tamper-proof audit trail. For instance, when a research institution requests access to de-identified datasets, the smart contract evaluates compliance, granting temporary encrypted access if authorized. Patients or data owners retain the ability to revoke access at any time through a secure interface. Interoperability and secure Electronic Health Record (EHR) data exchange are facilitated through the integration of FHIR (Fast Healthcare Interoperability Resources) and HL7 standards, ensuring seamless communication between hospitals, pharmaceutical firms, insurers, governments, and researchers. A hospital using an EHR system such as Epic can securely share de-identified patient datasets with a pharmaceutical company conducting drug trials. The proposed system ensures FHIR-compliant data formatting, enabling Al-driven analytics on anonymized datasets without violating HIPAA or GDPR.

[0073] The system (102) offers significant benefits to governments and public health agencies by providing real-time analytics on disease prevalence, streamlining reporting to WHO and national health organizations, and facilitating secure, anonymized global data sharing for medical research and pandemic response. Governments can use Al-generated insights to optimize healthcare policies, allocate resources, and prepare for potential epidemics based on real-time de-identified patient data. If Al predicts an increase in diabetes cases in a particular region, policymakers can implement proactive interventions before the situation escalates.

[0074] Al-driven predictive healthcare analytics further enhance the capabilities of the system by analyzing de-identified health records to predict future disease trends. This assists hospitals in early disease detection and supports governments in resource allocation. In parallel, Al-powered drug discovery and clinical trial optimization enable pharmaceutical companies to utilize anonymized patient data for Al-driven drug development. The system facilitates the identification of suitable clinical trial participants while maintaining compliance with privacy regulations, and expediting the testing of new treatments on diverse datasets. A pharmaceutical company, for example, could use the platform’s Al to identify cancer patients eligible for a new drug trial.

[0075] For instance, Al-based personalized healthcare and insurance plans are made possible by analyzing de-identified health data to offer customized insurance policies. Insurers can more accurately price policies based on real health risks without accessing personal details,while patients receive customized preventive healthcare recommendations. An insurance provider might use Al-driven analysis to offer lower premiums to individuals who maintain healthy lifestyle patterns, detected through their anonymized health data.

[0076] Blockchain-powered medical device security and loT integration ensure secure connectivity for medical devices and wearables, preventing unauthorized access or data manipulation. This is particularly crucial for implanted medical devices such as pacemakers and insulin pumps. A smart insulin pump, for instance, may use the proposed system to allow only authorized healthcare professionals and the patient to adjust its settings securely, enhancing patient safety and device integrity.

[0077] By combining Al, blockchain, and regulatory automation, the proposed system establishes a secure, transparent, and privacy-compliant ecosystem for healthcare data exchange. It enhances patient privacy while enabling innovation in medical research, predictive analytics, personalized treatment, and global health security.

[0078] The proposed system (102) can be accessed by computing devices (130) connected through a wireless network (132), ensuring secure, real-time access to authorized entities. The system (102) enables seamless data exchange, Al-driven processing, and blockchain-based security enforcement across multiple industries. Computing devices, including servers, cloud platforms, mobile devices, and loT-enabled healthcare systems, communicate with the proposed system (102) using encrypted protocols to maintain data integrity and confidentiality. Wireless connectivity enhances scalability of the system, enabling hospitals, financial institutions, research organizations, and government agencies to collaborate securely without physical infrastructure limitations. Edge computing capabilities allow realtime processing of sensitive information at the source, reducing latency and enhancing decision-making efficiency. The proposed system (102) ensures end-to-end encryption, immutable audit trails, and automated smart licensing, creating a robust, interoperable framework for secure data exchange across global networks.

[0079] Referring to FIG. 3, an exemplary flow chart of a method (1300) for method for blockchain-based access control and artificial intelligence-assisted de-identification of data is disclosed.

[0080] At step (202), the method (200) includes receiving by a processor (104), data associated with an entity from one or more data sources.

[0081] Continuing further, the method (200) further includes classifying and tagging the received data by the processor ( 104), based on jurisdictional requirements, industry-specific compliance mandates, and sensitivity levels. The Al-driven policy engines dynamically applyregional and cross-border compliance rules, continuously predicting emerging regulatory risks, automating policy adjustments, and enforcing adaptive compliance strategies. Data is encrypted and partitioned into smaller segments (shards) for secure cross-border transfers while maintaining an immutable ledger of data flows, regulatory checks, and consent logs.

[0082] At step (204), the method (200) includes analysing by the processor (104), the received data using an artificial intelligence (Al) module (115), which parses the data to extract structured and unstructured information. Natural language processing (NLP) techniques interpret free-text data to recognize personal identifiers, while pre-trained machine learning models classify and label sensitive attributes. The identified attributes are mapped to predefined categories of personally identifiable information (PII), and risk levels are evaluated dynamically using predictive analytics to assess fraud risks, regulatory violations, operational inefficiencies, security vulnerabilities, and emerging threats across multiple industries. In addition, risk assessment is performed by analyzing historical and real-time data, applying machine learning algorithms to detect patterns, recognize anomalies, and classify risk levels based on predefined and dynamically refined parameters. A risk score is assigned to sensitive attributes or entities using weighted factors, continuously updated through adaptive learning. If the assigned risk score exceeds a predefined threshold, the method triggers alerts, initiates Al-driven compliance reviews, or executes smart contract-based enforcement actions.

[0083] In addition, the Al module (115) utilizes pre-trained and continuously improving machine learning models, the method further including loading domain-specific models trained on historical datasets, updating parameters of the model continuously through incremental learning, validating the identified sensitive attributes with confidence scores to reduce false positives.

[0084] At step (206), the method (200) includes generating de-identified data by the processor (104), by performing masking, encryption, or tokenization to replace the identified sensitive attributes based on the applied classification. The Al module (115) dynamically updates de-identification policies based on growing compliance requirements across multiple jurisdictions.

[0085] At step (208), the method (200) includes recording the de-identification process by the processor (104), by storing metadata, transformation logs, and cryptographic hash values onto a blockchain network. In addition, recording the de-identification process by: collecting metadata, comprising timestamps, entity identifiers, data categories, and jurisdictional compliance parameters during each de-identification operation. Generating transformation logs detailing the applied de-identification techniques, attribute changes, and rule sets, evaluatinghash values for the received data and de-identified data, and storing the collected metadata, the transformation logs, and the cryptographic hash values onto a blockchain ledger to create an immutable audit trail.

[0086] At step (210), the method (200) includes managing by the processor (104), access control by verifying the identity of the entity and access rights through blockchain-based smart contracts, which define permission rules and access levels.

[0087] At step (212), the method (200) includes facilitating by the processor (104), sharing of the de-identified data to the authorized entities, based on the validated access rights.

[0088] At step (214), the method (200) includes enabling by the processor (104), an automated smart licensing framework using the blockchain network and the Al module to streamline regulatory approvals, enforce dynamic licensing conditions, facilitate jurisdictional compliance, and automate governance protocols across multiple industries. Continuing further, enabling the automated smart licensing framework by retrieving regulatory requirements and licensing conditions from at least one of: external databases, predefined rule repositories, or real-time regulatory updates, validating the received data to assess compliance with the retrieved regulatory requirements, the blockchain-based smart contracts autonomously execute, enforce, and update industry-specific licensing conditions across regulated industries, generating and executing the blockchain-based smart contracts to automatically grant, revoke, or renew licenses based on real-time regulatory validation, jurisdictional compliance rules, and risk-based Al assessments, recording licensing transactions, approval timestamps, regulatory attestations, and compliance decisions on the blockchain ledger, and triggering alerts, automated compliance audits, and smart contract-based revocation enforcement when the Al model detects regulatory violations, unauthorized access attempts, or the risk score of the entity exceeds the predefined threshold.

[0089] Continuing further, the method (200) includes training the Al model locally on connected computing devices and across decentralized networks, aggregating model updates using at least one of: Secure Multi-Party Computation (SMPC), Fully Homomorphic Encryption (FHE), Functional Encryption (FE), and Federated Learning with Secure Aggregation (FLSA), facilitating compliance with at least one of: global healthcare, financial, insurance, pharmaceutical, government security, or regulated industry frameworks by preserving data sovereignty while allowing regulators, auditors, and compliance authorities to verify the Al model training integrity, fairness assessments, and adversarial robustness through blockchain-based audit trails, Zero-Knowledge Proof-based verifications (ZK-ML), andfederated Al governance mechanisms, and recording the Al model updates, training iterations, risk assessments, and consent records on the blockchain network.

[0090] Continuing further, the method (200) further includes generating cryptographic proofs for identity verification of the entities, using Decentralized Identifiers (DIDs) and Zero-Knowledge Proof (ZKP) protocols, authenticating the entities, the organizations, and the digital assets through the blockchain-based Zero-Knowledge Proof (ZKP) protocols for decentralized access control, enabling access to the sensitive attributes only upon successful ZKP verification, and recording authentication events, access attempts, and proof verifications on the blockchain network.

[0091] The proposed system (102) and method (200) can be used across various industries to enhance security, compliance, and efficiency. In healthcare and research, AI-driven risk scoring, predictive diagnostics, and blockchain-based compliance ensure data security and regulatory adherence. Al-powered remote monitoring prevents hospital readmissions, while real-time emergency response indicators from wearables improve hospital efficiency. Blockchain secures patient consent and research data transparency, while federated Al learning supports privacy-compliant medical advancements.

[0092] In finance and banking, Al-driven fraud detection, investment risk scoring, and KYC automation enhance financial security. Blockchain-based digital identity verification and smart contract licensing streamline transactions, ensuring real-time AML compliance. The system optimizes supply chain and logistics through Al-powered predictive analytics for demand forecasting, fraud prevention, and real-time inventory tracking, with blockchain securing product authentication and supplier agreements.

[0093] Government and public sector applications include Al risk scoring for tax fraud detection, welfare fraud prevention, and smart compliance tracking. Blockchain-backed digital identity verification and automated contract execution ensure regulatory transparency. In aerospace and defense, Al-driven aircraft maintenance predictions and cybersecurity risk analysis enhance operational safety, while blockchain secures defense contracts, military data, and national security intelligence.

[0094] The telecommunications industry benefits from Al fraud detection in billing systems and network congestion prediction, ensuring service reliability. Blockchain supports secure identity verification and automated telecom contract licensing. In e-commerce and retail, Al-driven transaction risk scoring and personalized consumer analytics improve fraud detection, while blockchain-backed product authenticity verification and automated supply chain compliance prevent counterfeit goods.

[0095] Energy and utilities utilise Al-driven predictive maintenance for power grids and fraud detection in energy consumption, while blockchain ensures carbon credit tracking and automated licensing for energy distribution. Education and EdTech benefit from AI-powered personalized learning analytics and plagiarism detection, with blockchain securing digital credential verification and automated licensing for digital courses.

[0096] FIG. 3 illustrates a block diagram of an example computer system (300) in which or with which embodiments of the present disclosure may be implemented.

[0097] As shown in FIG. 3, the computer system (300) may include an external storage device (310), a bus (320), a main memory (330), a read-only memory (340), a mass storage device (350), communication port(s) (360), and a processor (370). A person skilled in the art will appreciate that the computer system 300) may include more than one processor and communication ports. The processor (370) may include various modules associated with embodiments of the present disclosure. The communication port(s) (360) may be any of an RS-232 port for use with a modem -based dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fibre, a serial port, a parallel port, or other existing or future ports. The communication port(s) (360) may be chosen depending on a network, such as a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system (300) connects. The main memory (330) may be random access memory (RAM), or any other dynamic storage device commonly known in the art. The read-only memory (340) may be any static storage device(s) including, but not limited to, a Programmable Read Only Memory (PROM) chips for storing static information e.g., start-up or basic input / output system (BIOS) instructions for the processor (370). The mass storage device (350) may be any current or future mass storage solution, which may be used to store information and / or instructions.

[0098] The bus (320) communicatively couples the processor (370) with the other memory, storage, and communication blocks. The bus (320) can be, e.g., a Peripheral Component Interconnect (PCI) / PCI Extended (PCI-X) bus, Small Computer System Interface (SCSI), universal serial bus (USB), or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor (370) to the computer system (300).

[0099] Optionally, operator and administrative interfaces, e.g. a display, keyboard, and a cursor control device, may also be coupled to the bus (320) to support direct operator interaction with the computer system (300). Other operator and administrative interfaces may be provided through network connections connected through the communication port(s) (360).In no way should the aforementioned exemplary computer system (300) limit the scope of the present disclosure.

[0100] Thus, the present disclosure discloses the system (102) and method (200) for blockchain-based access control and artificial intelligence-assisted de-identification of data, ensuring secure data handling, regulatory compliance, and privacy preservation.

[0101] While the foregoing describes various embodiments of the disclosure, other and further embodiments of the invention may be devised without departing from the basic scope thereof. The scope of the disclosure is determined by the claims that follow. The disclosure is not limited to the described embodiments, versions, or examples, which are included to enable a person having ordinary skill in the art to make and use the disclosure when combined with information and knowledge available to the person having ordinary skill in the art.ADVANTAGES OF THE PRESENT DISCLOSURE

[0102] The present disclosure provides blockchain-based access control with AI-assisted de-identification to enhance data security and privacy.

[0103] The present disclosure provides an adaptable Al and blockchain-powered system that delivers sector-specific insights, risk assessments, and compliance automation across diverse industries, including healthcare, finance, pharmaceuticals, supply chain, energy, telecommunications, defense, and governance.

[0104] The present disclosure provides real-time risk evaluation using machine learning algorithms to prevent fraud, security breaches, and compliance violations.

[0105] The present disclosure provides continuous Al model learning to dynamically adapt to growing threats, data patterns, and industry regulations.

[0106] The present disclosure provides immutable blockchain audit trails for tracking de-identification processes, access attempts, and data transformations.

[0107] The present disclosure provides decentralized Al model training with secure aggregation techniques to preserve data sovereignty and confidentiality.

[0108] The present disclosure provides automated smart licensing frameworks that streamline regulatory approvals and enforce dynamic licensing conditions.

[0109] The present disclosure provides zero-knowledge proof-based identity verification for secure, privacy-preserving access control.

[0110] The present disclosure provides jurisdiction-aware Al policy engines that apply adaptive compliance strategies based on regional and industry-specific mandates.[oni] The present disclosure provides encrypted data sharding to enable secure and efficient cross-border data transfers.

[0112] The present disclosure provides predictive analytics to proactively detect anomalies, assess entity risk scores, and trigger automated compliance actions.

Claims

I Claim:

1. A system (102) for blockchain-based access control and artificial intelligence-assisted deidentification of data, the system (102) comprising:a processor (104);a memory (106) coupled to the processor (104), storing instructions that, when executed by the processor, cause the system to:receive data associated with an entity from one or more data sources; analyze the received data using an artificial intelligence (Al) module (115), wherein the Al module (115) is configured to:parse the received data to extract structured data and unstructured data; apply natural language processing (NLP) techniques to interpret free- text data and recognize personal identifiers;utilize pre-trained machine learning models to classify and label sensitive attributes;map the identified sensitive attributes to pre-defined categories of personally identifiable information (PII); andevaluates risk level of the identified sensitive attributes, wherein the Al module applies predictive analytics to dynamically assess risk factors comprising fraud risk, regulatory violations, operational inefficiencies, security vulnerabilities, and emerging threats across multiple industries; generate de-identified data by performing masking, encryption, or tokenization to replace the identified sensitive attributes based on the applied classification, wherein the Al module dynamically updates de -identification policies based on progressing compliance requirements across multiple jurisdictions;record the de -identification process by storing metadata, transformation logs, and cryptographic hash values onto a blockchain network;manage access control by verifying identity of the entity and access rights through blockchain-based smart contracts, which define permission rules and access levels; andfacilitate sharing of the de-identified data to the authorized entities, based on the validated access rights; andenable an automated smart licensing framework using the blockchain network and the Al module to streamline regulatory approvals, enforce dynamic licensing conditions, facilitate jurisdictional compliance, and automate governance protocols across the multiple industries.

2. The system (102) as claimed in claim 1, wherein the Al module utilizes pre-trained and continuously refining the models, the Al module is configured to:loads domain-specific models trained on historical datasets;updates parameters of the models continuously through incremental learning; and validates the identified sensitive attributes with confidence scores to reduce false positives.

3. The system (102) as claimed in claim 1, wherein the processor is further configured to, in response to evaluating the risk level of the identified sensitive attributes:analyzes historical data and the received data to assess the risk factors;applies machine learning algorithms to detect patterns, recognize anomalies, and classify risk levels based on predefined and dynamically updating risk parameters;assigns the risk score to at least one of the sensitive attributes or entities using weighted factors;updates the risk score continuously through adaptive learning;trigger an alert, initiate an Al-driven compliance review, or execute a smart contractbased enforcement action if the assigned risk score exceeds a predefined threshold.

4. The system (102) as claimed in claim 1, wherein the processor is further configured to, in response to record the de-identification process:collect metadata, comprising timestamps, entity identifiers, data categories, and jurisdictional compliance parameters during each de-identification operation;generate transformation logs detailing the applied de-identification techniques, attribute changes, and rule sets;evaluate hash values for the received data and de-identified data; andstore the collected metadata, the transformation logs, and the cryptographic hash values onto a blockchain ledger to create an immutable audit trail.

5. The system (102) as claimed in claim 1, wherein the processor is further configured to:train the model locally on connected computing devices and across decentralized networks;aggregate the model updates using at least one of: Secure Multi-Party Computation (SMPC), Fully Homomorphic Encryption (FHE), Functional Encryption (FE), and Federated Learning with Secure Aggregation (FLSA),facilitate compliance with at least one of: global healthcare, financial, insurance, pharmaceutical, government security, or regulated industry frameworks by preserving data sovereignty while allowing regulators, auditors, and compliance authorities to verify the model training integrity, fairness assessments, and adversarial robustness through blockchain-based audit trails, Zero-Knowledge Proof-based verifications (ZK-ML), and federated Al governance mechanisms; andrecord the model updates, training iterations, risk assessments, and consent records on the blockchain network.

6. The system (102) as claimed in claim 4, wherein the processor is further configured to, in response to enable the automated smart licensing framework:retrieves regulatory requirements and licensing conditions from at least one of: external databases, predefined rule repositories, or real-time regulatory updates;validates the received data to assess compliance with the retrieved regulatory requirements, wherein the blockchain-based smart contracts autonomously execute, enforce, and update industry-specific licensing conditions across regulated industries; generates and executes the blockchain-based smart contracts to automatically grant, revoke, or renew licenses based on real-time regulatory validation, jurisdictional compliance rules, and risk-based Al assessments.;record licensing transactions, approval timestamps, regulatory attestations, and compliance decisions on the blockchain ledger; andtrigger the alerts, automated compliance audits, and smart contract-based revocation enforcement, when the model detects regulatory violations, unauthorized access attempts, or the risk score of the entity, exceeds the predefined threshold.

7. The system (102) as claimed in claim 1, wherein the processor is further configured to: generate cryptographic proofs for identity verification of the entities, using Decentralized Identifiers (DIDs) and Zero-Knowledge Proof (ZKP) protocols, authenticate the entities, the organizations, and the digital assets through the blockchain-based Zero-Knowledge Proof (ZKP) protocols for decentralized access control;enable access to the sensitive attributes only upon successful ZKP verification; and record authentication events, access attempts, and proof verifications on the blockchain network.

8. The system (102) as claimed in claim 1, wherein the processor is further configured to: classify and tag the received data based on jurisdictional requirements, industryspecific compliance mandates, and sensitivity levels of the data;apply regional and cross-border compliance rules dynamically through Al-driven policy engines, wherein the model continuously predicts emerging regulatory risks, automates policy adjustments, and enforces adaptive compliance strategies;encrypt and partition data into smaller segments (shards) for secure cross-border transfers; andmaintain an immutable ledger of data flows, regulatory checks, and consent logs.

9. A method (200) for blockchain-based access control and artificial intelligence-assisted deidentification of data, the method (200) comprising:receiving (202), by a processor, data associated with an entity from one or more data sources;analyzing (204), by the processor, the received data using an artificial intelligence (Al) module, wherein the Al module is configured to:parse the received data to extract structured data and unstructured data; apply natural language processing (NLP) techniques to interpret free-text data and recognize personal identifiers;utilize pre-trained machine learning models to classify and label sensitive attributes; map the identified sensitive attributes to pre-defined categories of personally identifiable information (PII); andevaluate risk level of the identified sensitive attributes, wherein the Al module applies predictive analytics to dynamically assess risk factors comprising fraud risk, regulatory violations, operational inefficiencies, security vulnerabilities, and emerging threats across multiple industries;generating (206), by the processor, de-identified data by performing masking, encryption, or tokenization to replace the identified sensitive attributes based on the applied classification, wherein the Al module dynamically updates de-identification policies based on progressing compliance requirements across multiple jurisdictions;recording (208), by the processor, the de-identification process by storing metadata, transformation logs, and cryptographic hash values onto a blockchain network;managing (210), by the processor, access control by verifying the identity of the entity and access rights through blockchain-based smart contracts, which define permission rules and access levels; andfacilitating (212), by the processor, sharing of the de-identified data to the authorized entities, based on the validated access rights; andenabling (214), by the processor, an automated smart licensing framework using the blockchain network and the Al module to streamline regulatory approvals, enforce dynamic licensing conditions, facilitate jurisdictional compliance, and automate governance protocols across the multiple industries.

10. The method (200) as claimed in claim 9, wherein the Al module utilizes pre-trained and continuously refining machine learning models, the method further comprises:loading domain-specific models trained on historical datasets;updating parameters of the Al model continuously through incremental learning; and validating the identified sensitive attributes with confidence scores to reduce false positives.

11. The method (200) as claimed in claim 9, further comprises evaluating the risk level of the identified sensitive attributes by:analyzing historical data and the received data to assess the risk factors; applying machine learning algorithms to detect patterns, recognize anomalies, and classify risk levels based on predefined and dynamically updating risk parameters; assigning the risk score to at least one of the sensitive attributes or entities using weighted factors;updating the risk score continuously through adaptive learning; and triggering an alert, initiating an Al-driven compliance review, or executing a smart contract-based enforcement action if the assigned risk score exceeds a predefined threshold.

12. The method (200) as claimed in claim 9, further comprises:recording the de-identification process by: collecting metadata, comprising timestamps, entity identifiers, data categories, and jurisdictional compliance parameters during each deidentification operation;generating transformation logs detailing the applied de-identification techniques, attribute changes, and rule sets;evaluating hash values for the received data and de-identified data; andstoring the collected metadata, the transformation logs, and the cryptographic hash values onto a blockchain ledger to create an immutable audit trail.

13. The method (200) as claimed in claim 9, further comprises:training the Al model locally on connected computing devices and across decentralized networks;aggregating model updates using at least one of: Secure Multi-Party Computation (SMPC), Fully Homomorphic Encryption (FHE), Functional Encryption (FE), and Federated Learning with Secure Aggregation (FLSA);facilitating compliance with at least one of: global healthcare, financial, insurance, pharmaceutical, government security, or regulated industry frameworks by preserving data sovereignty while allowing regulators, auditors, and compliance authorities to verify the Al model training integrity, fairness assessments, and adversarial robustness through blockchain-based audit trails, Zero-Knowledge Proof-based verifications (ZK-ML), and federated Al governance mechanisms; andrecording the Al model updates, training iterations, risk assessments, and consent records on the blockchain network.

14. The method (200) as claimed in claim 9, further comprises enabling the automated smart licensing framework by:retrieving regulatory requirements and licensing conditions from at least one of: external databases, predefined rule repositories, or real-time regulatory updates;validating the received data to assess compliance with the retrieved regulatory requirements, wherein the blockchain-based smart contracts autonomously execute, enforce, and update industry-specific licensing conditions across regulated industries; generating and executing the blockchain-based smart contracts to automatically grant, revoke, or renew licenses based on real-time regulatory validation, jurisdictional compliance rules, and risk-based Al assessments;recording licensing transactions, approval timestamps, regulatory attestations, and compliance decisions on the blockchain ledger; andtriggering alerts, automated compliance audits, and smart contract-based revocation enforcement, when the Al model detects regulatory violations, unauthorized access attempts, or the risk score of the entity, exceeds the predefined threshold.

15. The method (200) as claimed in claim 9, further comprises:generating cryptographic proofs for identity verification of the entities, using Decentralized Identifiers (DIDs) and Zero-Knowledge Proof (ZKP) protocols;authenticating the entities, the organizations, and the digital assets through the blockchain-based Zero-Knowledge Proof (ZKP) protocols for decentralized access control; enabling access to the sensitive attributes only upon successful ZKP verification; andrecording authentication events, access attempts, and proof verifications on the blockchain network.

16. The method (200) as claimed in claim 9, further comprising:classifying and tagging the received data based on jurisdictional requirements, industry- specific compliance mandates, and sensitivity levels of the data;applying regional and cross-border compliance rules dynamically through Al-driven policy engines, wherein the Al model continuously predicts emerging regulatory risks, automates policy adjustments, and enforces adaptive compliance strategies;encrypting and partitioning data into smaller segments (shards) for secure cross-border transfers; andmaintaining an immutable ledger of data flows, regulatory checks, and consent logs.