Blockchain Authorization Group Key Access Duration Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional application architectures compromise user privacy by centralizing personal information and lacking control over access, leading to inconsistent data storage and unauthorized sharing of sensitive information.
Innovation Solution
A blockchain-based system that encrypts user information and controls access through a group key mechanism, allowing users to manage access duration by periodically changing the group key, ensuring secure and decentralized storage and authorization across multiple applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user information is stored on a centralized application server for each application, then each application can access user information conveniently, but user privacy is compromised and users lose control over their information
Solution Approach 1:
The patent segments user information control by separating storage (centralized blockchain) from access control (decentralized authorization). Each application receives only the specific data it needs through authorized access, rather than storing all user information centrally across multiple servers. This segmentation allows convenient access while protecting privacy through selective disclosure.
Solution Approach 2:
The patent introduces a blockchain-based intermediary system that mediates between user information and applications. The blockchain ledger acts as a trusted intermediary that verifies authorization tokens and manages access rights without applications directly accessing raw user data. This intermediary mechanism enables convenient access while preventing unauthorized information sharing.
2Adaptability or versatility
If user information is stored on multiple application servers, then each application has its own data, but data inconsistency occurs and users must repeatedly enter the same information
Solution Approach 1:
The patent merges the storage function of multiple application servers into a single blockchain ledger. User information is stored once in the blockchain, and all applications access this unified source through authorized tokens. This combining eliminates data inconsistency while maintaining application-specific access control through the authorization mechanism.
Solution Approach 2:
The blockchain ledger serves as a universal storage infrastructure that supports multiple applications simultaneously. A single blockchain system provides data storage, authorization management, and access control services to numerous applications, eliminating the need for each application to maintain separate data stores while ensuring data consistency across all applications.
3Duration of action of moving object
If applications can access user information indefinitely, then applications have continuous access to data, but users cannot prevent unauthorized access in perpetuity
Solution Approach 1:
The patent implements periodic renewal of authorization tokens with defined expiration times. Instead of indefinite access, authorization tokens are issued for specific durations and must be renewed or revoked by the user. This periodic action allows applications to access user information when needed while automatically limiting long-term unauthorized access risks through time-bound authorization.
Solution Approach 2:
The patent changes the authorization parameter from permanent to time-limited by incorporating expiration timestamps in authorization tokens. This parameter change transforms the access model from indefinite to controlled-duration access, enabling users to automatically prevent perpetual unauthorized access while maintaining convenient access during authorized periods.
Data Source
AI summary
A record of authorization including user information is received and appended to a blockchain. The record of authorization authorizes access by a third-party application to the user information for an access duration. The user information is encrypted by a group key and access duration is based on a change to the group key. The group key comprises a public/private key pair, and the access duration is implemented by an authorization group of nodes having the group key. The group key corresponds to either a valid group key at or near the start of the access duration, that enables decryption of a message in the record of authorization that includes the user information, or an incompatible group key at or after the end of the access duration, that does not enable decryption of the message in the record of authorization that includes the user information.


