Decentralized Attribute-Based Access Control Federation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control methods fail to effectively manage and enforce attribute-based access control in decentralized environments, particularly in multi-cloud settings, leading to challenges in ensuring security, privacy, and compliance with regulations such as GDPR and HIPAA.
Innovation Solution
Implementing a decentralized federation with a federation authority that manages membership, policies, and rules across multiple cloud computing systems, using verifiable credentials and decentralized identifiers to determine and enforce attribute-based access control, allowing each member to provide and consume services based on attributes associated with other members.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If decentralized access control is implemented, then security and privacy are improved, but system complexity increases
Solution Approach 1:
The patent introduces a federation authority as an intermediary component that manages access control policies, verifiable credentials, and attribute verification across decentralized cloud members. This mediator handles the complexity of policy enforcement and credential verification, allowing individual cloud members to maintain simplicity while the federation authority centralizes the complex security management functions.
2Reliability
If attribute-based access control is enforced across multiple cloud systems, then compliance with regulations is improved, but operational complexity increases
Solution Approach 1:
The federation authority serves multiple functions simultaneously: it issues and verifies verifiable credentials, manages access control policies, enforces compliance with regulations like GDPR and HIPAA, and coordinates attribute-based access control across diverse cloud members. This multi-functional design consolidates compliance management operations into a single system that handles various regulatory requirements through unified processes.
3Reliability
If granular access control based on attributes is implemented, then data protection is improved, but processing overhead increases
Solution Approach 1:
The system performs preliminary actions by issuing verifiable credentials and establishing access control policies before actual data access operations occur. Attributes and access permissions are pre-verified and encoded in cryptographic credentials during the credential issuance phase, allowing rapid verification during data access without repeated complex processing. This shifts processing overhead to the credential issuance stage rather than every data access operation.
Data Source
AI summary
Embodiments of the present disclosure include systems and methods for providing a decentralized federation for attribute-based access control. A request for a list of unique identifiers (IDs) associated with members belonging to the federation is sent to a federation authority. For a unique ID in the list of unique IDs associated with a second member belonging to the federation, a set of communication information for communicating with the second member is determined. Based on the set of communication information associated with the second member, the second member is sent a request for a list of available services. The second member is provided a set of verifiable credentials associated with the first member. The second member determines the list of available services based on the set of verifiable credentials and a set of policies and rules. The list of available services is received from the second member.


