Decentralized Identity Policy Enforcement via Distributed Ledger

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized identity management systems lack user control and flexibility in enforcing policy rules across different types of data, especially in decentralized environments where data ownership and control are paramount.

Innovation Solution

A computing system and method that utilize a decentralized network with a distributed ledger to backup decentralized identifiers (DIDs), allowing entities to enforce policy rules applicable to specific data types, ensuring operations comply with these rules, thereby providing users with control over their data while adhering to regulatory requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized identity management system is used, then security and centralized control are improved, but user control and flexibility over data are reduced

Engineering Contradiction:
ImprovesecurityVSAvoiduser control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the centralized identity management system into decentralized components where each user has their own identity hub that stores and manages their personal data. This segmentation allows users to maintain control over their own data while still participating in a broader network, thus improving user control without sacrificing security through the distributed nature of the system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer consisting of policy rules and data request mechanisms that mediate between users and their data. This intermediary structure enables automated enforcement of access policies while preserving user autonomy, allowing users to define who can access their data under what conditions, thus enhancing both security and user control simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If decentralized identifiers are used, then user control and flexibility are improved, but enforcement of policy rules across different data types becomes more complex

Engineering Contradiction:
Improveuser controlVSAvoidpolicy rule enforcement
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal policy rule framework that can handle multiple data types and access scenarios through a common mechanism. The data request structure and policy evaluation system are designed to be multi-functional, accommodating various data types (personal data, sensitive data, etc.) and different policy requirements without requiring separate enforcement mechanisms for each case, thus reducing complexity while maintaining flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter-based policy rules that can be dynamically configured and adjusted. By changing parameters within the policy rule structure (such as access conditions, data types, user roles), the system can adapt to different enforcement requirements without modifying the underlying architecture, thereby simplifying policy rule enforcement across diverse data types while preserving user control.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If automated policy rule enforcement is implemented, then compliance with regulatory requirements is improved, but system complexity increases

Engineering Contradiction:
ImprovecomplianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service automated policy enforcement where the system automatically evaluates data requests against policy rules and makes access decisions without requiring manual intervention. The identity hub and data request mechanism work autonomously to enforce compliance with regulatory requirements, reducing system complexity by eliminating the need for complex manual approval workflows while maintaining high compliance standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the system continuously monitors data access requests and automatically adjusts enforcement based on policy rule evaluations. This feedback loop ensures compliance with regulatory requirements by automatically detecting and preventing unauthorized access attempts, thereby improving compliance while keeping system complexity manageable through automated rather than manual processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3938941B1User choice in data location and policy adherence
Publication Date: 2024.05.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3938941B1 patent drawingFigure 1
  • EP3938941B1 patent drawingFigure 2
  • EP3938941B1 patent drawingFigure 3

AI summary

Enforcing different policy rules that are applicable to different types of data. The computing system and methods are implemented in a decentralized network that implements a distributed ledger, the distributed ledger backing one or more decentralized identities (DID) for one or more users of the computing system. Receive a request from an entity for operating on data stored or to be stored in a storage that is associated with an owner of a DID. A type of data that is requested to be operated on is then determined. One or more policy rules that are applicable to the determined type of data are accessed. Based on the one or more policy rules, determine if the operation to be performed on the data will result in the data complying with the one or more policy rules. Based on the determination, allow or deny the request.