Decentralized Access Control via Credential Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control and policy enforcement mechanisms for networked services are inadequate for managing cross-organizational access and fine-grained policy enforcement, particularly in large and diverse user bases, and fail to scale effectively across organizational boundaries, lacking a decentralized and privacy-preserving solution for heterogeneous information objects and services.
Innovation Solution
A system comprising an authorisation module, a servicing module, and a clearance module, which issue enrollments, define credentials, and map enrollments to credentials, respectively, allowing end users to access distributed object services across a network, with policy data structures binding credentials to specific actions, enabling dynamic interaction and fine-grained policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If centralized access control mechanisms are used to manage user credentials, then access control can be implemented, but the system cannot scale effectively across organizational boundaries and loses privacy
Solution Approach 1:
The patent segments the centralized access control system into distributed components: local credential verification modules at each organization and a decentralized credential issuance system. This allows each organization to independently manage access control for their resources without relying on a central authority, enabling scalability across organizational boundaries while maintaining privacy through localized processing of sensitive credential data
Solution Approach 2:
The patent introduces credential tokens as intermediary objects that mediate between user authentication and resource access. These tokens contain verified credential information without exposing raw personal data, allowing organizations to verify user eligibility while preserving privacy. The tokens act as intermediaries that enable cross-organizational trust without requiring centralized credential storage or processing
2Ease of operation
If simple access control lists are used for resource access, then implementation is straightforward, but the system cannot enforce fine-grained policies for large and diverse user bases
Solution Approach 1:
The patent implements dynamic access control policies that can be configured and modified without system reconfiguration. Policy rules are stored in a configurable format that allows organizations to define complex access conditions based on user attributes, resource types, and contextual factors. The system dynamically evaluates these policies during credential verification, enabling fine-grained control adaptable to diverse user bases and resource types while maintaining ease of policy management through standardized configuration interfaces
3Reliability
If credentials are centrally managed and verified, then access control decisions can be made, but privacy is compromised and the system does not scale across organizations
Solution Approach 1:
The patent extracts sensitive personal information from the credential verification process. Instead of centrally storing or processing detailed user data, the system extracts only the essential verification information needed for access control decisions. Credential tokens contain verified attributes without exposing underlying personal data, and local verification modules process only the minimal information necessary, thereby maintaining verification reliability while preserving user privacy through selective information extraction
Solution Approach 2:
The patent implements local credential verification where each organization's resources are verified by local modules using locally-stored policy rules. This distributed verification approach allows each organization to maintain control over their own access control decisions with high reliability, while user data never leaves the local environment unnecessarily. The local quality of verification ensures both reliability through decentralized control and privacy through localized data processing
Data Source
AI summary
Apparatus for controlling cross-organizational access by end users associated with a plurality of organizations to one or more distributed object services available via a resource server across an information technology communications network. The apparatus comprises at least one Requesting Organization (RO) having access to services via the resource server, the Requesting Organization being adapted to issue enrollments to one or more end users upon request and electronically transmitting the enrollments to the respective end users. The apparatus further comprises at least one Servicing Organization (SO) communicating with the Requesting Organization and defining the credentials required for access to a service via the resource server by end users associated with each of the organizations. A Clearance Service (CS) is provided in which is stored one or more mappings of enrollments to credentials, the end user being adapted to transmit to the resource server a request for access to a resource together with data relating to their respective enrollment, in response to receipt of which request, the Requesting Organization is adapted to transmit the data relating to the enrollment to the Clearance Service which is adapted to map the enrollment to one or more respective credentials and return data representative of the credentials to the resource server which in turn is adapted to compare the data representative of the credentials to the original resource request and to comply (or otherwise) with the request. The Requesting Organization the resource server and the Clearance Service are all implemented as web or e-services.


