Distributed Ledger Access Control Using Attestation Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in managing access control for physical and digital spaces, including tracking access to sensitive areas and data, and maintaining records for investigative purposes, while ensuring security and privacy.
Innovation Solution
A computer-implemented method using a distributed ledger system for access control, where entities can verify attribute attestations to determine access permissions based on privilege labels and access rules, allowing secure access while maintaining privacy and transparency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control systems are used to track and manage access to physical and digital spaces, then access records can be maintained for investigative purposes, but security and privacy challenges arise due to centralized data storage and potential unauthorized access
Solution Approach 1:
The patent segments the access control system into multiple independent components: distributed ledger nodes, identity management modules, attribute verification services, and access control policies. Each component operates independently but contributes to the overall security, eliminating the need for a single complex centralized system while maintaining reliable access control.
Solution Approach 2:
The patent introduces a distributed ledger as an intermediary layer between identity holders and access control systems. This intermediary enables trustless verification of attributes and access rights without requiring direct trust between parties, reducing system complexity while enhancing security through cryptographic proofs.
2Loss of information
If centralized access control systems store and process access records, then comprehensive tracking is achieved, but privacy risks increase due to centralized data storage
Solution Approach 1:
The patent extracts sensitive personal information from the access control system by storing only cryptographic hashes and verified attributes on the distributed ledger. The actual personal data remains privately held by individuals, yet access records are still comprehensively tracked through verifiable credentials and audit trails on the ledger.
Solution Approach 2:
The patent uses cryptographic copies (hashes and verified attributes) of access records stored on the distributed ledger instead of storing original sensitive data. These cryptographic copies enable comprehensive tracking and verification of access events while preserving privacy, as the actual personal information never leaves the individual's control.
3Reliability
If distributed ledger technology is implemented for access control, then security and transparency are improved through cryptographic proofs, but system complexity increases
Solution Approach 1:
The patent implements a universal distributed ledger platform that serves multiple functions: identity management, attribute verification, access control policy enforcement, and audit logging. This multi-functional approach consolidates what would otherwise require multiple separate complex systems into a single unified infrastructure, reducing overall system complexity while maintaining high security standards.
Data Source
AI summary
Methods and apparatus for performing access control for a first entity. The method comprises using a pointer associated with a second entity to access, from a distributed ledger system, at least one attestation for at least one attribute of the second entity, wherein the at least one attestation is movable between at least two states in the distributed ledger system, the at least two states comprising a VERIFIED state and allowing the second entity to access the first entity in response to determining that the at least one attestation is in the VERIFIED state, that the third entity is to be trusted for verifying the at least one attestation, that the cryptographic proof is a valid proof of the at least one privilege label, and that the one or more access rules are satisfied.


