Decentralized Identity Management for Cloud Storage Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties managing and accessing multiple cloud storage accounts due to the need for multiple identities, complex permission management, and lack of integration with decentralized identities, leading to inefficiencies in data access and security across different cloud providers.
Innovation Solution
A decentralized identity management system using a blockchain-based architecture, such as Blockstack, allows users to create and manage their own identities, enabling secure authentication and authorization across multiple storage systems through cryptographically signed token files, eliminating the need for multiple accounts and simplifying permission management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users create separate accounts with each storage system provider, then authentication and authorization can be enforced for each system, but users must manage multiple identities and accounts across different providers
Solution Approach 1:
The patent introduces a decentralized identity management system that acts as an intermediary between users and multiple storage systems. Users create a single identity in the decentralized system, which then mediates authentication and authorization across all connected storage providers, eliminating the need to manage separate accounts for each system.
Solution Approach 2:
The decentralized identity system provides universal authentication and authorization capabilities that work across multiple different storage system providers. A single identity created in the decentralized system can be used to access and manage data across various storage platforms, making the identity management system multi-functional and provider-agnostic.
2Ease of operation
If storage systems use centralized identity management systems like Active Directory, then permission management is simplified, but users do not fully own or control their identities
Solution Approach 1:
Instead of having centralized systems manage user identities and permissions, the patent inverts the model by allowing users to own and control their own identities through decentralized authentication. Users generate and manage their own cryptographic keys and identity data, reversing the traditional centralized control model.
Solution Approach 2:
The decentralized identity system enables users to self-manage their identities without relying on centralized identity providers. Users can independently create, update, and control their identity information and permissions across multiple storage systems, providing full self-service capability.
3Adaptability or versatility
If users need to access data across multiple cloud providers, then data accessibility is improved, but the complexity of managing multiple accounts and permissions increases
Solution Approach 1:
The patent combines multiple account management functions into a single decentralized identity system. Users can access data across multiple cloud providers through one unified identity interface, merging the complexity of managing separate accounts and permissions into a single manageable system.
Solution Approach 2:
The decentralized identity system provides universal access capabilities that work across different cloud storage providers. A single identity can authenticate and manage permissions across multiple providers, making the system versatile and eliminating the need for provider-specific account management.
Data Source
AI summary
At least one identity for a given entity is established in accordance with a decentralized identity management system maintained in accordance with a distributed ledger, wherein the identity of the given entity and a set of attributes relating to the identity are defined by a secure token file. The secure token file is referenced in the distributed ledger enabling two or more computing resource systems (e.g., storage systems) to at least one of authenticate and authorize the given entity in accordance with the secure token file.


