Blockchain Identity Access Management Decentralized Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized identity and access management systems are prone to arbitrary privilege issuance and revocation by central authorities, leading to potential misuse and higher costs for users, lacking a cost-efficient decentralized solution.

Innovation Solution

Implementing a blockchain-based identity and access management system that uses a one-time password pad generated from a master password and salt, with passwords published on a blockchain for secure access control, allowing decentralized and cost-efficient management of identity and access without a central authority.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized directory service is used for identity and access management, then access control can be implemented, but the central authority can arbitrarily issue and revoke access privileges without oversight and set high pricing

Engineering Contradiction:
Improveaccess controlVSAvoidarbitrary privilege issuance and revocation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a blockchain as an intermediary layer between users and access control systems. The blockchain stores verifiable credentials and access tokens in a decentralized manner, preventing any single authority from arbitrarily issuing or revoking privileges. The smart contracts on the blockchain automatically enforce access rules based on predefined conditions, eliminating human discretion and potential abuse.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables users to self-manage their own credentials and access rights through cryptographic key pairs. Users generate their own digital identities and control their own access tokens without needing a central authority's intervention. The decentralized nature of the blockchain allows users to independently verify and manage their credentials, reducing reliance on centralized control.

Inventive Principle:
Principle #25Self-service

2Reliability

If a centralized directory service is used for identity and access management, then access control can be implemented, but costs for users are higher due to central authority pricing

Engineering Contradiction:
Improveaccess controlVSAvoidcosts for users
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Users generate their own cryptographic key pairs and manage their own credentials without paying centralized service fees. The decentralized blockchain infrastructure eliminates the need for expensive centralized directory services, allowing users to independently establish and verify identities at minimal cost.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The blockchain-based credential system serves multiple functions simultaneously: identity verification, access control, and credential management. This multi-functional approach eliminates the need for separate centralized services for each function, reducing overall system costs and enabling users to benefit from a unified, low-cost infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If a decentralized blockchain-based system is used for identity and access management, then arbitrary privilege issuance is prevented and costs are reduced, but system complexity increases

Engineering Contradiction:
Improvearbitrary privilege issuance and revocationVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system uses cryptographic copies (hashes) of credentials and tokens stored on the blockchain rather than storing the actual sensitive data. This allows verification of credentials without exposing the underlying information, simplifying the security model while maintaining decentralization and preventing arbitrary privilege issuance.

Inventive Principle:
Principle #26Copying

4Ease of operation

If passwords are published on a blockchain for access control, then decentralized identity management is achieved, but security requirements increase

Engineering Contradiction:
Improvedecentralized access managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system stores cryptographic hashes and verified copies of credentials on the blockchain rather than the actual passwords or sensitive data. This allows decentralized verification while maintaining security, as the blockchain stores only immutable proof of validity without exposing the underlying secret information.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces traditional mechanical password storage and verification systems with cryptographic mechanisms based on blockchain technology. Instead of relying on centralized databases and authentication servers, the system uses cryptographic signatures, hash functions, and smart contracts to verify identities and enforce access control, providing both decentralization and enhanced security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10938566B2Blockchain based identity and access management
Publication Date: 2021.03.02 FINLOW BATES KEIR
  • US10938566B2 patent drawing
  • US10938566B2 patent drawing
  • US10938566B2 patent drawing

AI summary

Identity and access management in computer systems without the need for a central authority is provided. A user may create an identity on a blockchain, and generate a one-time pad of access passwords derived from repeated hashing of a master password and cryptographic salt. The user may publish a last access password from the one-time pad on the blockchain. The user may then provide proof of identify in response to an access challenge by revealing a prior access password from which the last access password is derived, and may receive a session token in response. The publishing of access passwords and receiving of session tokens may be associated with a transfer of tokens or digital credits of commercial value on the blockchain.