Distributed Ledger Access Control Using Attestation Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in managing access control for physical and digital spaces, including tracking access to sensitive areas and data, and maintaining records for investigative purposes, while ensuring security and privacy.

Innovation Solution

A computer-implemented method using a distributed ledger system for access control, where entities can verify attribute attestations to determine access permissions based on privilege labels and access rules, allowing secure access while maintaining privacy and transparency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control systems are used to track and manage access to physical and digital spaces, then access records can be maintained for investigative purposes, but security and privacy challenges arise due to centralized data storage and potential unauthorized access

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the access control system into multiple independent components: distributed ledger nodes, identity management modules, attribute verification services, and access control policies. Each component operates independently but contributes to the overall security, eliminating the need for a single complex centralized system while maintaining reliable access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a distributed ledger as an intermediary layer between identity holders and access control systems. This intermediary enables trustless verification of attributes and access rights without requiring direct trust between parties, reducing system complexity while enhancing security through cryptographic proofs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If centralized access control systems store and process access records, then comprehensive tracking is achieved, but privacy risks increase due to centralized data storage

Engineering Contradiction:
Improveaccess record trackingVSAvoidprivacy risks
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive personal information from the access control system by storing only cryptographic hashes and verified attributes on the distributed ledger. The actual personal data remains privately held by individuals, yet access records are still comprehensively tracked through verifiable credentials and audit trails on the ledger.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses cryptographic copies (hashes and verified attributes) of access records stored on the distributed ledger instead of storing original sensitive data. These cryptographic copies enable comprehensive tracking and verification of access events while preserving privacy, as the actual personal information never leaves the individual's control.

Inventive Principle:
Principle #26Copying

3Reliability

If distributed ledger technology is implemented for access control, then security and transparency are improved through cryptographic proofs, but system complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal distributed ledger platform that serves multiple functions: identity management, attribute verification, access control policy enforcement, and audit logging. This multi-functional approach consolidates what would otherwise require multiple separate complex systems into a single unified infrastructure, reducing overall system complexity while maintaining high security standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10454927B2Systems and methods for managing relationships among digital identities
Publication Date: 2019.10.22 BLOCKCHAINS INC
  • US10454927B2 patent drawing
  • US10454927B2 patent drawing
  • US10454927B2 patent drawing

AI summary

Methods and apparatus for performing access control for a first entity. The method comprises using a pointer associated with a second entity to access, from a distributed ledger system, at least one attestation for at least one attribute of the second entity, wherein the at least one attestation is movable between at least two states in the distributed ledger system, the at least two states comprising a VERIFIED state and allowing the second entity to access the first entity in response to determining that the at least one attestation is in the VERIFIED state, that the third entity is to be trusted for verifying the at least one attestation, that the cryptographic proof is a valid proof of the at least one privilege label, and that the one or more access rules are satisfied.