Metadata-Driven Blockchain Access Control via Granular Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current blockchain and distributed ledger technologies face challenges in implementing user access controls, data retrieval efficiency, and data deletion due to their fixed, immutable, and context-less nature, which limits their applicability in applications requiring dynamic access management and data permanence.

Innovation Solution

Implementing user access controls in a metadata-driven blockchain using granular access objects and ALFA/XACML visibility rules within a cloud-based computing environment, allowing for dynamic metadata management, efficient data retrieval, and controlled access privileges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored in a fixed, immutable manner in blockchain, then data security and integrity are improved, but data retrieval efficiency and adaptability deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiddata retrieval efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments data storage into two parts: immutable hash values stored on the blockchain for security and verification, and actual data stored externally in databases or cloud storage for efficient retrieval. This segmentation allows the system to maintain blockchain immutability while achieving fast data access through external storage systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer (external database or cloud storage) that mediates between the blockchain and data retrieval operations. This intermediary handles the actual data storage and retrieval, while the blockchain maintains only cryptographic references, thus resolving the conflict between immutability and retrieval efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control is implemented in traditional blockchain, then user privacy is improved, but system complexity and operational ease deteriorate

Engineering Contradiction:
Improveuser privacyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts access control logic from the core blockchain protocol and implements it as separate smart contracts or external authentication mechanisms. This extraction allows access control to be added without fundamentally altering the blockchain structure, reducing system complexity while maintaining privacy through controlled data access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements universal access control mechanisms that can be applied across different blockchain applications and data types. By creating a standardized access control framework that works with various data structures and permission models, the system reduces complexity through reusability while providing comprehensive privacy protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If complete records are stored on blockchain, then data integrity is improved, but storage volume and resource consumption worsen

Engineering Contradiction:
Improvedata integrityVSAvoidstorage volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent creates cryptographic copies (hash values) of data and stores only these compact representations on the blockchain, while the full data resides in external storage systems. This copying approach ensures data integrity through blockchain-verified hashes while dramatically reducing the storage volume required on the distributed ledger.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent applies different storage qualities to different data elements: cryptographic hashes with full integrity verification are stored on the blockchain, while the actual data content is stored in external systems with appropriate local storage optimizations. This local quality differentiation optimizes both integrity assurance and storage efficiency.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11824970B2Systems, methods, and apparatuses for implementing user access controls in a metadata driven blockchain operating via distributed ledger technology (DLT) using granular access objects and ALFA/XACML visibility rules
Publication Date: 2023.11.21 SALESFORCE INC
  • US11824970B2 patent drawing
  • US11824970B2 patent drawing
  • US11824970B2 patent drawing

AI summary

Systems, methods, and apparatuses for implementing user access controls in a metadata driven blockchain operating via Distributed Ledger Technology (DLT) using granular access objects and ALFA/XACML visibility rules in conjunction with a cloud based computing environment. For example, according to one embodiment there is a system having at least a processor and a memory therein executing within a host organization, in which such a system includes means for operating a blockchain interface to a blockchain on behalf of a plurality of tenants of the host organization; displaying a Graphical User Interface (GUI Interface) to a user device communicably interfaced with the system over a network, wherein the GUI interface is to prompt for a metadata rule definition at the user device when displayed by the user device; auto-generating an access control object specifying the access control permissions based on the input received from the GUI interface displayed to the client device; transacting the access control object onto the blockchain; receiving a transaction at the blockchain requesting access to the blockchain entity object or one blockchain entity within the group of blockchain entity objects; executing a smart contract responsive to receiving the transaction at the blockchain, wherein the smart contract retrieves the access control object previously transacted onto the blockchain specifying the access control permissions; and approving or denying access to the blockchain entity object or one blockchain entity within the group of blockchain entity objects based on the execution of the smart contract. Other related embodiments are disclosed.