Blockchain-Based Data Access Control System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security methods fail to effectively prevent unauthorized access to confidential data, as data access logs can be tampered with by attackers, and there is a need to differentiate access permissions for users who are authorized to a network but not to specific data.

Innovation Solution

A management system that utilizes a cryptocurrency transaction on a public distributed ledger to authorize and track data access, where users must make a micropayment to access data, with the transaction recorded on a blockchain to enhance security and identity confirmation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a data access log is used to track and prevent unauthorized access, then access monitoring capability is improved, but the log itself becomes a target for attacker tampering and compromise

Engineering Contradiction:
Improveaccess monitoring reliabilityVSAvoidlog tampering vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces blockchain technology as an intermediary layer between the data access log and the actual data. The blockchain serves as a tamper-proof mediator that records access requests and approvals immutably. When a user requests data access, the request is recorded on the blockchain, and only approved requests can access the data. This intermediary blockchain layer prevents direct tampering with access logs while maintaining reliable monitoring capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If network access authorization is granted to users, then network usability is improved, but data-level access control becomes compromised as users can access all data on the network

Engineering Contradiction:
Improvenetwork access convenienceVSAvoiddata access security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments access control into two distinct levels: network-level access and data-level access. Network access authorization allows users to connect to the network conveniently, while data-level access requires separate blockchain-recorded approval for each specific data access request. This segmentation enables users to have network connectivity without automatic access to all data, thereby maintaining both ease of network operation and data security.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If traditional access control methods are used, then system complexity is reduced, but the ability to provide tamper-proof access logs is lost

Engineering Contradiction:
Improveaccess control system complexityVSAvoidaccess log integrity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces blockchain technology as an intermediary layer between the data access log and the actual data. The blockchain serves as a tamper-proof mediator that records access requests and approvals immutably. When a user requests data access, the request is recorded on the blockchain, and only approved requests can access the data. This intermediary blockchain layer prevents direct tampering with access logs while maintaining reliable monitoring capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11687888B2Management system, management method, and computer-readable recording medium
Publication Date: 2023.06.27 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11687888B2 patent drawing
  • US11687888B2 patent drawing
  • US11687888B2 patent drawing

AI summary

A management system includes a user terminal, and a management device that manages data, wherein the management device include a memory; and a processor coupled to the memory and executes a process comprising: requesting remittance of a cryptocurrency that uses a public distributed ledger from the user terminal, upon receiving a request for accessing managed data from the user terminal, and authorizing the user terminal to access the data when a record of clearance of the remittance made by the user terminal is added to the public distributed ledger.