Blockchain Access Control With Dual Authority Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing blockchain systems lack effective mechanisms for flexible control of content access authority, particularly in off-chain storage scenarios, leading to a risk of sensitive data leakage due to one-time authority authentication.
Innovation Solution
A method and system for blockchain access authority control that involves dual authority confirmation, where a first authority is determined based on role confirmation information, followed by locating the access content in a distributed storage system and then verifying a second authority using authority authentication information before accessing the content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If one-time authority authentication is used for accessing content in blockchain system, then access efficiency is improved, but security is worsened due to risk of sensitive data leakage
Solution Approach 1:
The patent segments the authentication process into two distinct authorities: first authority verification based on role confirmation information, and second authority verification based on authority authentication information. This segmentation allows the system to maintain both access efficiency (through automated dual verification) and security (through layered authentication checks at different stages of the data access process)
Solution Approach 2:
The patent performs preliminary authority verification by determining the first authority based on role confirmation information before the actual data access occurs. This preliminary action ensures that only users with appropriate roles can initiate access requests, preventing unauthorized access attempts and enhancing security while maintaining efficient access for authorized users
2Reliability
If dual authority confirmation is implemented with role confirmation and authority authentication, then security is improved, but system complexity is worsened
Solution Approach 1:
The patent implements a universal authority verification mechanism that handles both role-based access control and authority-based access control through a unified dual verification framework. This multi-functional approach consolidates multiple authentication requirements into a single systematic process, managing complexity through standardization while maintaining comprehensive security coverage
Solution Approach 2:
The patent introduces an intermediary verification layer that mediates between the user's access request and the actual data access. This intermediary performs both first authority (role-based) and second authority (permission-based) verifications, acting as a security gatekeeper that manages the complexity of dual authentication while protecting the underlying data storage system
3Quantity of substance
If distributed storage system is used for off-chain storage, then storage capacity is improved, but access control difficulty is worsened
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously verifies authority information during the data access process. The dual authority verification provides feedback loops that check both role confirmation and authority authentication, ensuring that access control decisions are made based on current, validated information. This feedback system manages the complexity of distributed storage access control by providing structured verification at each access point
Data Source
AI summary
The embodiments of the disclosure disclose a method and a system for blockchain access authority control, an apparatus, a program and a medium. The system comprises a plurality of blockchain nodes. For each blockchain node, a corresponding distributed node is further deployed in a node apparatus where the blockchain node is located, and the distributed nodes form a distributed storage system. A first blockchain node receives an access request sent by a first client, determines a possession of a first authority to access the blockchain system by the first client according to role confirmation information, and then determines a distributed node where access content is located from the distributed storage system. After determining a possession of a second authority to access the distributed node where the access content is located by the first client according to authority authentication information, the access content is obtained and returned to the first client.


