Distributed Ledger Privileged Access Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access management systems for critical IT systems face challenges in securely managing privileged user access, particularly in preventing internal attacks and ensuring transparency and trust among stakeholders, as rogue employees can tamper with access controls and audit logs.
Innovation Solution
Implementing a distributed ledger system, such as a blockchain network, to record access requests, approvals, and policy updates, which ensures that all transactions are validated by multiple nodes and immutable, reducing the risk of tampering and enhancing auditability and trust among participants.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a centralized access management system is used, then ease of operation is improved, but reliability deteriorates due to single point of failure and tampering risks
Solution Approach 1:
The patent divides the centralized access management system into multiple distributed nodes forming a blockchain network. Each node maintains a copy of the access control ledger, eliminating the single point of failure. The access management functionality is segmented across peer nodes, validator nodes, and asset owner nodes, each performing specific functions while collectively providing secure access control.
Solution Approach 2:
The patent introduces a distributed ledger (blockchain) as an intermediary between access requests and authorization decisions. This intermediary layer records all access transactions immutably and provides transparent audit trails, mediating between the need for easy access operations and the requirement for reliable security verification.
2Measurement precision
If traditional access control logging is implemented, then measurement precision is improved for tracking access, but object-generated harmful factors worsen due to log tampering by rogue employees
Solution Approach 1:
The patent implements preliminary actions by pre-establishing the distributed ledger structure with cryptographic hashing and consensus mechanisms before access logging begins. This preliminary setup ensures that subsequent access logs are written to an immutable structure, preventing retroactive tampering while maintaining precise tracking of all access events.
Solution Approach 2:
The patent replaces the mechanical system of centralized log files (which can be manually edited) with a cryptographic system based on hash chains and digital signatures. Each access log entry is cryptographically linked to previous entries, and any modification would break the cryptographic chain, providing tamper-evident logging that maintains measurement precision while eliminating the vulnerability to internal attacks.
3Reliability
If distributed ledger system is implemented, then reliability is improved through immutability, but device complexity increases due to blockchain infrastructure
Solution Approach 1:
The patent makes the distributed ledger system multi-functional by using it not only for access logging but also for authorization decisions, audit trails, and policy management. This universal application of the blockchain infrastructure justifies the complexity by providing multiple security functions from a single system, reducing the need for separate complex systems for each function.
Solution Approach 2:
The patent implements self-service mechanisms where the distributed ledger automatically validates access requests through consensus protocols and cryptographic verification without requiring manual intervention. The system self-manages the complexity of blockchain operations, node synchronization, and transaction validation, reducing the operational burden despite the underlying system complexity.
Data Source
AI summary
An access management process orchestration method, an access management governance orchestrator, and a computer program product. One embodiment may comprise receiving a request for accessing a managed resource of an information system, querying an authorization for accessing the resource from an access manager, and in response to the querying of the authorization, requesting an access control policy update to grant the access to the managed resource. Receiving the request, querying the authorization, and requesting the access control policy update may comprise generating a transaction record, and adding the transaction record to a distributed ledger, wherein the distributed ledger simultaneously maintains the transaction record at multiple nodes throughout a network.


