Decentralized Authorization Management for Connected Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing centralized systems for managing access authorizations and identities of connected objects are inefficient due to data security issues, complexity in replication, and lack of scalability, especially in multi-player scenarios where decentralization is necessary.

Innovation Solution

A decentralized and distributed system using a blockchain with a controlled number of governing entities to manage access authorizations, where storage nodes record new blocks and smart contracts are executed to verify conditional authorizations, ensuring data integrity and traceability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized management platform is used to manage access authorizations, then the system is easier to control and manage, but data security is compromised and the system lacks resilience against data loss and unauthorized modification

Engineering Contradiction:
Improveease of controlVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The centralized management platform is segmented into multiple independent nodes distributed across different locations. Each node maintains a copy of the authorization data, eliminating the single point of failure while preserving centralized control capabilities through coordinated operation of the distributed nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A blockchain intermediary layer is introduced between the management platform and the underlying storage infrastructure. This intermediary provides cryptographic verification and consensus mechanisms that ensure data integrity and security while maintaining the ease of operation of the management platform.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If distributed databases with replication are used to ensure data availability, then data accessibility is improved, but the system becomes too complex to implement and performance is reduced

Engineering Contradiction:
Improvedata availabilityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The blockchain infrastructure serves multiple functions simultaneously: it provides data replication, consensus verification, security validation, and audit trail maintenance. This multi-functionality reduces overall system complexity compared to separate systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the replication parameter from traditional N copies to N+1 copies where each node holds a unique portion of the data plus one additional copy. This parameter change simplifies the replication logic while ensuring data availability and reducing implementation complexity.

Inventive Principle:
Principle #35Parameter changes

3Stability of the object's composition

If a master-slave replication architecture is used, then data consistency is maintained, but the system lacks decentralization and is difficult to implement in multi-player scenarios

Engineering Contradiction:
Improvedata consistencyVSAvoiddecentralization capability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The traditional master-slave hierarchy is inverted to a peer-to-peer equality model where all nodes have equal status. Data consistency is maintained not through a central master but through cryptographic consensus mechanisms that validate data integrity across all equal nodes.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

While nodes are equal in status, asymmetry is introduced in their functional roles through cryptographic key pairs. Each node has unique private keys for signing and public keys for verification, allowing decentralized consistency without centralized control.

Inventive Principle:
Principle #4Asymmetry

4Reliability

If existing specialized systems are used for each category of connected objects, then system expertise is maximized, but interoperability and migration between systems become complex

Engineering Contradiction:
Improvesystem expertiseVSAvoidinteroperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The blockchain-based authorization system serves as a universal layer that can manage authorizations across multiple categories of connected objects and different specialized systems. This universal layer maintains interoperability while allowing specialized systems to retain their domain expertise.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The blockchain system acts as an intermediary layer between different specialized systems, enabling migration and interoperability without requiring changes to the specialized systems themselves. Authorization data can be transferred and verified across system boundaries through this intermediary.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10552627B2System and method for the creation and management of decentralized authorizations for connected objects
Publication Date: 2020.02.04 BULL SA
  • US10552627B2 patent drawing
  • US10552627B2 patent drawing
  • US10552627B2 patent drawing

AI summary

Computing systems and methods for the creation and management of authorizations of blockchain objects. Systems and methods managed by a controlled number of governing entities allow the management of access authorizations for an object connected to a varying group of services. Systems and methods therefore have numerous advantages including strong inter-operability, strong resilience, confidentiality, autonomy, ensured data integrity and traceability.