Decentralized Identifier Authorization for Consortium Blockchain Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack effective mechanisms for users to control and authorize access to their data stored in consortium blockchain networks, making it difficult for users to manage who can access their information and under what conditions.
Innovation Solution
A method and system that utilize decentralized identifiers (DIDs) and hash values to manage access control, where user data is stored in a consortium blockchain and associated records are stored in a decentralized identifier blockchain, allowing users to authorize access based on valid digital activity decentralized identifiers and business identifiers, ensuring secure and controlled data sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user data is stored in consortium blockchain networks, then data security and immutability are improved, but user control over data access authorization deteriorates
Solution Approach 1:
The system segments data storage and access control into separate layers: user data is stored in the consortium blockchain while access authorization is managed through a separate authorization module that uses decentralized identifiers (DIDs) and verifiable credentials. This segmentation allows the data to remain secure and immutable in the blockchain while enabling flexible user-controlled access through digital credentials.
Solution Approach 2:
The patent introduces an intermediary authorization mechanism using decentralized identifiers (DIDs) and verifiable credentials as mediators between users and their data. Instead of direct access control, the system uses cryptographic credentials that users can present to authorize access, allowing indirect but secure user control over data access without compromising blockchain integrity.
2Device complexity
If traditional access control mechanisms are used in blockchain networks, then implementation simplicity is improved, but data privacy and user autonomy deteriorate
Solution Approach 1:
The patent extracts sensitive personal data from the blockchain ledger itself and stores it off-chain or in encrypted form, while only storing cryptographic hashes and authorization metadata on the blockchain. This extraction allows the blockchain to maintain its simplicity and immutability while protecting user privacy by removing personally identifiable information from the public ledger.
Solution Approach 2:
The system changes the parameter of data representation by using cryptographic hashing and verifiable credentials instead of storing raw personal data. Data is transformed into cryptographic forms (hashes, signatures, credentials) that maintain verification capabilities while protecting privacy, allowing access control without exposing underlying sensitive information.
3Ease of operation
If decentralized identifiers are used for data authorization, then user autonomy and data security are improved, but system complexity increases
Solution Approach 1:
The patent implements a universal decentralized identifier (DID) system that serves multiple functions: user authentication, data access authorization, and cross-application identity management. This multi-functional approach consolidates what could be multiple separate systems into a single unified credential framework, reducing overall system complexity while maintaining user autonomy.
Solution Approach 2:
The system performs preliminary actions by pre-issuing verifiable credentials and establishing authorization rules before data access is needed. Users set up their authorization preferences and credentials in advance, which are then automatically verified and enforced when access requests occur, eliminating the need for complex real-time authorization negotiations and reducing operational complexity.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Disclosed herein are methods, systems, and apparatus, including computer programs encoded on computer storage media, for controlling authorization of access to user data. One of the methods includes receiving a first request that includes a first digital activity decentralized identifier (DID) and a first hash value of first digital activity data, wherein the first digital activity decentralized identifier is associated with a first decentralized identifier of a first user and a first business decentralized identifier associated with a first consortium blockchain; storing the first digital activity decentralized identifier and the first hash value in a first record in a decentralized identifier blockchain that is configured to store records associated with a plurality of decentralized identifiers of a plurality of users; and controlling authorization of access to the first digital activity data stored in the first consortium blockchain using information stored in the first record in the decentralized identifier blockchain, including determining whether to authorize another user access to the first digital activity data based on the information stored in the first record in the decentralized identifier blockchain.