Blockchain-Based Data Access Control Preventing Collusion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern web services lack transparency and user control over how sensitive user data is managed and shared, with existing protocols requiring users to be online and trusting third parties, leading to potential data misuse and security breaches.

Innovation Solution

Implementing a system that allows users to create and enforce information usage policies using a blockchain to control data access and usage, with a host server processing requests within a private enclave and encrypting data for secure distribution to authorized parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users trust third parties to execute protocols online, then data access control is enabled, but user control and transparency are lost

Engineering Contradiction:
Improvedata access controlVSAvoiduser control
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces a blockchain-based intermediary system that mediates between users and data consumers. The blockchain stores verifiable proofs of data usage compliance, allowing users to control data access without needing to trust third-party executors. The smart contract on blockchain automatically enforces usage policies and provides transparent verification, resolving the contradiction between ease of operation and user control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If automatic enforcement of policies is implemented, then online presence requirement is removed, but security against adversarial hosts deteriorates

Engineering Contradiction:
Improveoffline operation capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by having users pre-define usage policies and store them on the blockchain before data is shared. These policies include verifiable proofs of compliance that are recorded on the blockchain in advance. When data is accessed offline, the pre-stored policies and proofs ensure security without requiring real-time verification, thus enabling offline operation while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If data is shared with multiple recipients, then data utility is improved, but fairness and prevention of collusion deteriorate

Engineering Contradiction:
Improvedata distribution capabilityVSAvoidfairness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where each data consumer must provide verifiable proof of compliance with usage policies to the blockchain network. The smart contract monitors and verifies each recipient's adherence to the defined policies, providing continuous feedback on data usage. This ensures fair distribution to multiple recipients by preventing collusion, as any policy violation is detected and recorded on the immutable blockchain ledger.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11921884B2Techniques for preventing collusion using simultaneous key release
Publication Date: 2024.03.05 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11921884B2 patent drawing
  • US11921884B2 patent drawing
  • US11921884B2 patent drawing

AI summary

Described herein are a system and techniques for enabling user control over usage of their information by data consumers, even when untrusted parties are involved, while also preventing collusion between the untrusted party and a data consumer. A user's information may be collected by a client device and provided to a host server. An encrypted version of the user's information may be stored at the host server so that it is processed on a private enclave of the host server. When the data is to be provided to multiple data consumers, the data may be encrypted for each of the data consumers and may be released to each of those data consumers simultaneously once confirmation has been received that the data has been made available to each of the data consumers.