Metadata-Driven Blockchain Access Control via Granular Objects
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current blockchain and distributed ledger technologies face challenges in implementing user access controls, data retrieval efficiency, and data deletion due to their fixed, immutable, and context-less nature, which limits their applicability in applications requiring dynamic access management and data permanence.
Innovation Solution
Implementing user access controls in a metadata-driven blockchain using granular access objects and ALFA/XACML visibility rules within a cloud-based computing environment, allowing for dynamic metadata management, efficient data retrieval, and controlled access privileges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored in a fixed, immutable manner in blockchain, then data security and integrity are improved, but data retrieval efficiency and adaptability deteriorate
Solution Approach 1:
The patent segments data storage into two parts: immutable hash values stored on the blockchain for security and verification, and actual data stored externally in databases or cloud storage for efficient retrieval. This segmentation allows the system to maintain blockchain immutability while achieving fast data access through external storage systems.
Solution Approach 2:
The patent introduces an intermediary layer (external database or cloud storage) that mediates between the blockchain and data retrieval operations. This intermediary handles the actual data storage and retrieval, while the blockchain maintains only cryptographic references, thus resolving the conflict between immutability and retrieval efficiency.
2Reliability
If access control is implemented in traditional blockchain, then user privacy is improved, but system complexity and operational ease deteriorate
Solution Approach 1:
The patent extracts access control logic from the core blockchain protocol and implements it as separate smart contracts or external authentication mechanisms. This extraction allows access control to be added without fundamentally altering the blockchain structure, reducing system complexity while maintaining privacy through controlled data access.
Solution Approach 2:
The patent implements universal access control mechanisms that can be applied across different blockchain applications and data types. By creating a standardized access control framework that works with various data structures and permission models, the system reduces complexity through reusability while providing comprehensive privacy protection.
3Reliability
If complete records are stored on blockchain, then data integrity is improved, but storage volume and resource consumption worsen
Solution Approach 1:
The patent creates cryptographic copies (hash values) of data and stores only these compact representations on the blockchain, while the full data resides in external storage systems. This copying approach ensures data integrity through blockchain-verified hashes while dramatically reducing the storage volume required on the distributed ledger.
Solution Approach 2:
The patent applies different storage qualities to different data elements: cryptographic hashes with full integrity verification are stored on the blockchain, while the actual data content is stored in external systems with appropriate local storage optimizations. This local quality differentiation optimizes both integrity assurance and storage efficiency.
Data Source
AI summary
Systems, methods, and apparatuses for implementing user access controls in a metadata driven blockchain operating via Distributed Ledger Technology (DLT) using granular access objects and ALFA/XACML visibility rules in conjunction with a cloud based computing environment. For example, according to one embodiment there is a system having at least a processor and a memory therein executing within a host organization, in which such a system includes means for operating a blockchain interface to a blockchain on behalf of a plurality of tenants of the host organization; displaying a Graphical User Interface (GUI Interface) to a user device communicably interfaced with the system over a network, wherein the GUI interface is to prompt for a metadata rule definition at the user device when displayed by the user device; auto-generating an access control object specifying the access control permissions based on the input received from the GUI interface displayed to the client device; transacting the access control object onto the blockchain; receiving a transaction at the blockchain requesting access to the blockchain entity object or one blockchain entity within the group of blockchain entity objects; executing a smart contract responsive to receiving the transaction at the blockchain, wherein the smart contract retrieves the access control object previously transacted onto the blockchain specifying the access control permissions; and approving or denying access to the blockchain entity object or one blockchain entity within the group of blockchain entity objects based on the execution of the smart contract. Other related embodiments are disclosed.


