Blockchain Authorization Ledger for Distributed Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional resource access control systems are vulnerable to single-point failures, such as 'man in the middle' and 'insider' attacks, and lack the ability to customize access permissions and conditions for specific resources, leading to inadequate authorization and security.

Innovation Solution

A distributed resource access system using blockchain technology, where an authorization event template with constraints is created and stored on an authorization blockchain network, allowing nodes to verify and grant access only when specific conditions are met, ensuring secure and customized access to resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single entity is charged with transaction processing and authorization, then the system is simpler to manage, but the system becomes vulnerable to single-point failures and attacks

Engineering Contradiction:
Improveauthorization system complexityVSAvoidsystem security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the centralized authorization system into multiple distributed nodes that each maintain copies of the authorization ledger. Instead of one entity processing all transactions, multiple nodes independently validate and record authorization events, eliminating the single point of failure while maintaining system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an immutable authorization ledger as an intermediary between users and resources. This ledger acts as a trusted mediator that records all authorization decisions transparently, allowing nodes to verify authorizations without relying on a single controlling entity, thus enhancing security while distributing trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional authorization schemes use general access levels, then authorization is easier to implement, but customization for specific resources and conditions is not possible

Engineering Contradiction:
Improveauthorization implementationVSAvoidaccess permission customization
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent enables different authorization rules to be applied to different resources and contexts. Each resource can have its own specific access conditions and constraints defined in the authorization ledger, allowing granular control where each resource's access policy is tailored to its specific security requirements rather than applying uniform rules everywhere.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic authorization where access permissions can change based on contextual conditions such as time, location, device state, or user behavior. The system can evaluate multiple constraints and adjust authorization decisions in real-time based on current conditions, making the authorization system adaptable rather than static.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If traditional systems authorize access without conditions, then access control is simpler, but comprehensive context-based authorization cannot be established

Engineering Contradiction:
Improveaccess control mechanismVSAvoidsecure access control
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent establishes authorization rules and constraints in advance within the immutable ledger before access requests occur. Context-based conditions such as time windows, location requirements, and device constraints are predefined and stored in the authorization events, allowing the system to automatically evaluate these pre-set conditions rather than requiring complex real-time decision-making logic.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11429958B1System, method and apparatus for resource access control
Publication Date: 2022.08.30 BEYOND AEROSPACE LTD
  • US11429958B1 patent drawing
  • US11429958B1 patent drawing
  • US11429958B1 patent drawing

AI summary

A system, method and apparatus for resource access control. An authorization record is created when a requestor has been authorized to access a resource, the authorization record created from an authorization event template stored on an authorization blockchain network. The authorization resource comprises one or more conditions that must generally be true in order for the user to access the resource. The authorization record may additionally comprise one or more permissions for the user to manage the resource.