Decentralized Data Rights Management via Hybrid Blockchain

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Self-Sovereign Data Storage systems require centralized trusted parties for data distribution and management, lacking mechanisms for peer-to-peer distribution, transfer, and delegation of data rights, as well as flexible models for access control and policy enforcement.

Innovation Solution

A decentralized data rights management system using data authorization tokens and a hybrid blockchain/cloud storage architecture, enabling secure, multi-lateral data transfer and access control through multiple layers of encryption and decentralized policy enforcement, allowing data owners to manage dissemination without relying on centralized systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional Self-Sovereign Data Storage is used, then data control by issuer is maintained, but peer-to-peer distribution and transfer of data rights is not enabled

Engineering Contradiction:
Improvepeer-to-peer distribution capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a decentralized identity framework with digital wallets and verifiable credentials as intermediaries between data owners and data consumers. These intermediaries enable peer-to-peer data exchange without requiring a centralized trusted party, resolving the contradiction by providing the necessary distribution mechanism while maintaining architectural complexity at acceptable levels through standardized protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal decentralized identity system that can handle multiple data types and scenarios through a single framework. The verifiable credential system and digital wallet infrastructure serve multiple functions including data storage, authentication, authorization, and audit trails, thereby enabling versatile peer-to-peer distribution without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If centralized trusted parties are used for data management, then data distribution control is maintained, but trust between unrelated counterparties cannot be established

Engineering Contradiction:
Improvedata access securityVSAvoidtrustless peer access capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent enables data owners to self-manage their data and authorization through decentralized digital wallets and cryptographic keys. The system allows owners to independently create, manage, and revoke access permissions without centralized intermediaries, establishing reliability through cryptographic security while enabling trustless access between unrelated parties through verifiable credentials.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical centralized authorization system with a cryptographic decentralized system. Instead of relying on centralized trusted parties to manage access, the system uses public-key cryptography, digital signatures, and verifiable credentials to establish and enforce access control, thereby achieving both security and trustless peer access.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If simple data storage is used, then ease of operation is maintained, but flexible access control and policy enforcement is not provided

Engineering Contradiction:
Improveaccess policy flexibilityVSAvoiddata access simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the access control system into discrete verifiable credentials and policy components. Each access right can be independently defined, granted, and enforced through separate cryptographic proofs, allowing flexible policies (such as time-based or condition-based access) while maintaining operational simplicity through automated verification by the decentralized system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11757639B2Method, apparatus, and computer-readable medium for secured data transfer over a decentrlaized computer network
Publication Date: 2023.09.12 SECURRENCY INC
  • US11757639B2 patent drawing
  • US11757639B2 patent drawing
  • US11757639B2 patent drawing

AI summary

A method and apparatus for secured, peer-to-peer transfer of data rights over a computer network, the method being accomplished by a distributed computing system including a distributed ledger platform and an off-chain data host platform. On-chain authorization tokens are used to track data access rights, enforce access policies, and control distribution of encryption keys.