Decentralized Attribute-Based Access Control Federation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control methods fail to effectively manage and enforce attribute-based access control in decentralized environments, particularly in multi-cloud settings, leading to challenges in ensuring security, privacy, and compliance with regulations such as GDPR and HIPAA.

Innovation Solution

Implementing a decentralized federation with a federation authority that manages membership, policies, and rules across multiple cloud computing systems, using verifiable credentials and decentralized identifiers to determine and enforce attribute-based access control, allowing each member to provide and consume services based on attributes associated with other members.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If decentralized access control is implemented, then security and privacy are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a federation authority as an intermediary component that manages access control policies, verifiable credentials, and attribute verification across decentralized cloud members. This mediator handles the complexity of policy enforcement and credential verification, allowing individual cloud members to maintain simplicity while the federation authority centralizes the complex security management functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If attribute-based access control is enforced across multiple cloud systems, then compliance with regulations is improved, but operational complexity increases

Engineering Contradiction:
ImprovecomplianceVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The federation authority serves multiple functions simultaneously: it issues and verifies verifiable credentials, manages access control policies, enforces compliance with regulations like GDPR and HIPAA, and coordinates attribute-based access control across diverse cloud members. This multi-functional design consolidates compliance management operations into a single system that handles various regulatory requirements through unified processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If granular access control based on attributes is implemented, then data protection is improved, but processing overhead increases

Engineering Contradiction:
Improvedata protectionVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by issuing verifiable credentials and establishing access control policies before actual data access operations occur. Attributes and access permissions are pre-verified and encoded in cryptographic credentials during the credential issuance phase, allowing rapid verification during data access without repeated complex processing. This shifts processing overhead to the credential issuance stage rather than every data access operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12166748B2Decentralized attribute-based access control
Publication Date: 2024.12.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12166748B2 patent drawing
  • US12166748B2 patent drawing
  • US12166748B2 patent drawing

AI summary

Embodiments of the present disclosure include systems and methods for providing a decentralized federation for attribute-based access control. A request for a list of unique identifiers (IDs) associated with members belonging to the federation is sent to a federation authority. For a unique ID in the list of unique IDs associated with a second member belonging to the federation, a set of communication information for communicating with the second member is determined. Based on the set of communication information associated with the second member, the second member is sent a request for a list of available services. The second member is provided a set of verifiable credentials associated with the first member. The second member determines the list of available services based on the set of verifiable credentials and a set of policies and rules. The list of available services is received from the second member.