Decentralized Identity Management for Cloud Storage Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties managing and accessing multiple cloud storage accounts due to the need for multiple identities, complex permission management, and lack of integration with decentralized identities, leading to inefficiencies in data access and security across different cloud providers.

Innovation Solution

A decentralized identity management system using a blockchain-based architecture, such as Blockstack, allows users to create and manage their own identities, enabling secure authentication and authorization across multiple storage systems through cryptographically signed token files, eliminating the need for multiple accounts and simplifying permission management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users create separate accounts with each storage system provider, then authentication and authorization can be enforced for each system, but users must manage multiple identities and accounts across different providers

Engineering Contradiction:
Improveauthentication and authorization enforcementVSAvoididentity management complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a decentralized identity management system that acts as an intermediary between users and multiple storage systems. Users create a single identity in the decentralized system, which then mediates authentication and authorization across all connected storage providers, eliminating the need to manage separate accounts for each system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The decentralized identity system provides universal authentication and authorization capabilities that work across multiple different storage system providers. A single identity created in the decentralized system can be used to access and manage data across various storage platforms, making the identity management system multi-functional and provider-agnostic.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If storage systems use centralized identity management systems like Active Directory, then permission management is simplified, but users do not fully own or control their identities

Engineering Contradiction:
Improvepermission managementVSAvoididentity ownership and control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

Instead of having centralized systems manage user identities and permissions, the patent inverts the model by allowing users to own and control their own identities through decentralized authentication. Users generate and manage their own cryptographic keys and identity data, reversing the traditional centralized control model.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The decentralized identity system enables users to self-manage their identities without relying on centralized identity providers. Users can independently create, update, and control their identity information and permissions across multiple storage systems, providing full self-service capability.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If users need to access data across multiple cloud providers, then data accessibility is improved, but the complexity of managing multiple accounts and permissions increases

Engineering Contradiction:
Improvedata accessibility across providersVSAvoidaccount and permission management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple account management functions into a single decentralized identity system. Users can access data across multiple cloud providers through one unified identity interface, merging the complexity of managing separate accounts and permissions into a single manageable system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The decentralized identity system provides universal access capabilities that work across different cloud storage providers. A single identity can authenticate and manage permissions across multiple providers, making the system versatile and eliminating the need for provider-specific account management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12028343B2Decentralized identities for access to multiple computing resource systems
Publication Date: 2024.07.02 EMC IP HLDG CO LLC
  • US12028343B2 patent drawing
  • US12028343B2 patent drawing
  • US12028343B2 patent drawing

AI summary

At least one identity for a given entity is established in accordance with a decentralized identity management system maintained in accordance with a distributed ledger, wherein the identity of the given entity and a set of attributes relating to the identity are defined by a secure token file. The secure token file is referenced in the distributed ledger enabling two or more computing resource systems (e.g., storage systems) to at least one of authenticate and authorize the given entity in accordance with the secure token file.