Distributed Ledger Access Control for Secure Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data management systems face challenges in securely and efficiently managing access to sensitive information across disparate repositories while protecting privacy and ensuring authorized access.
Innovation Solution
A distributed ledger network with smart contracts is used to manage access control and sharing of sensitive information, enabling secure, efficient, and flexible management of personal data through encryption and smart contracts, allowing data owners to control access rights and revoke permissions without exposing primary authentication credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is made accessible to authorised individuals or information systems, then the value of the data is improved, but the risk of unauthorized access and privacy breaches worsens
Solution Approach 1:
The patent introduces a distributed ledger network as an intermediary between data owners and data consumers. The ledger stores encrypted access control configurations and data access keys, acting as a trusted mediator that enables authorized access while preventing unauthorized access. The smart contracts on the ledger automatically enforce access policies without requiring direct trust between data owners and consumers.
Solution Approach 2:
The patent segments access control into multiple components: data access policies, data access keys, and access control configurations. The data access key is encrypted and stored on the distributed ledger, separate from the actual data. This segmentation allows fine-grained control over who can access what data under what conditions, improving security while maintaining accessibility.
2Ease of operation
If traditional centralized access control systems are used, then ease of operation is improved, but reliability and security against hacking worsens
Solution Approach 1:
The patent implements self-service access control where data owners can independently define and update their own data access policies without requiring intervention from system administrators. The smart contracts on the distributed ledger automatically enforce these policies, and data consumers can request access based on predefined conditions. This eliminates single points of failure while maintaining ease of operation.
Solution Approach 2:
The distributed ledger network serves multiple functions simultaneously: it stores encrypted access control configurations, manages data access keys, executes smart contracts for access validation, and provides a decentralized authentication mechanism. This multi-functionality replaces multiple separate systems with a single reliable infrastructure.
3Adaptability or versatility
If data access policies are made flexible and dynamic, then adaptability is improved, but device complexity and system architecture complexity worsens
Solution Approach 1:
The patent replaces complex mechanical access control systems with cryptographic mechanisms. Access policies are encoded as smart contracts on the distributed ledger, and data access keys are protected using encryption. The cryptographic operations automatically enforce access control logic without requiring complex hardware or software implementations at each node.
4Reliability
If encryption is applied to protect data access keys, then security is improved, but processing time and computational overhead worsens
Solution Approach 1:
The patent performs preliminary encryption of data access keys and stores the encrypted versions on the distributed ledger before any access requests occur. When data access is needed, the smart contracts automatically retrieve and decrypt the appropriate keys based on validated access conditions. This preliminary preparation reduces processing time during actual data access operations.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Some embodiments relate to systems and method for secure information sharing using an information sharing engine. The information sharing engine configured to manage data access keys and data access control configuration, store the data access keys and data access control configuration on a distributed ledger network and selectively retrieve the data access keys from the distributed ledger network based on the data access control configuration.