Distributed Ledger Privileged Access Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access management systems for critical IT systems face challenges in securely managing privileged user access, particularly in preventing internal attacks and ensuring transparency and trust among stakeholders, as rogue employees can tamper with access controls and audit logs.

Innovation Solution

Implementing a distributed ledger system, such as a blockchain network, to record access requests, approvals, and policy updates, which ensures that all transactions are validated by multiple nodes and immutable, reducing the risk of tampering and enhancing auditability and trust among participants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized access management system is used, then ease of operation is improved, but reliability deteriorates due to single point of failure and tampering risks

Engineering Contradiction:
Improveaccess management operationVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the centralized access management system into multiple distributed nodes forming a blockchain network. Each node maintains a copy of the access control ledger, eliminating the single point of failure. The access management functionality is segmented across peer nodes, validator nodes, and asset owner nodes, each performing specific functions while collectively providing secure access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a distributed ledger (blockchain) as an intermediary between access requests and authorization decisions. This intermediary layer records all access transactions immutably and provides transparent audit trails, mediating between the need for easy access operations and the requirement for reliable security verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If traditional access control logging is implemented, then measurement precision is improved for tracking access, but object-generated harmful factors worsen due to log tampering by rogue employees

Engineering Contradiction:
Improveaccess tracking accuracyVSAvoidinternal attack risk
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent implements preliminary actions by pre-establishing the distributed ledger structure with cryptographic hashing and consensus mechanisms before access logging begins. This preliminary setup ensures that subsequent access logs are written to an immutable structure, preventing retroactive tampering while maintaining precise tracking of all access events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical system of centralized log files (which can be manually edited) with a cryptographic system based on hash chains and digital signatures. Each access log entry is cryptographically linked to previous entries, and any modification would break the cryptographic chain, providing tamper-evident logging that maintains measurement precision while eliminating the vulnerability to internal attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If distributed ledger system is implemented, then reliability is improved through immutability, but device complexity increases due to blockchain infrastructure

Engineering Contradiction:
Improveaccess control integrityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the distributed ledger system multi-functional by using it not only for access logging but also for authorization decisions, audit trails, and policy management. This universal application of the blockchain infrastructure justifies the complexity by providing multiple security functions from a single system, reducing the need for separate complex systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service mechanisms where the distributed ledger automatically validates access requests through consensus protocols and cryptographic verification without requiring manual intervention. The system self-manages the complexity of blockchain operations, node synchronization, and transaction validation, reducing the operational burden despite the underlying system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12143395B2Low trust privileged access management
Publication Date: 2024.11.12 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12143395B2 patent drawing
  • US12143395B2 patent drawing
  • US12143395B2 patent drawing

AI summary

An access management process orchestration method, an access management governance orchestrator, and a computer program product. One embodiment may comprise receiving a request for accessing a managed resource of an information system, querying an authorization for accessing the resource from an access manager, and in response to the querying of the authorization, requesting an access control policy update to grant the access to the managed resource. Receiving the request, querying the authorization, and requesting the access control policy update may comprise generating a transaction record, and adding the transaction record to a distributed ledger, wherein the distributed ledger simultaneously maintains the transaction record at multiple nodes throughout a network.