Permissioned Blockchain Access Control for Classified Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing classified information lack efficient and secure methods for access control and validation, particularly in ensuring that only authorized personnel can access sensitive documents based on their security clearance levels and location.

Innovation Solution

A permissioned blockchain is deployed across multiple nodes, with access level blocks configured to store encrypted nanoblocks, each containing user security credentials, allowing for real-time permission determination and secure replication to maintain data integrity and accessibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central database is used to store access control attributes, then data access and validation can be performed, but the system becomes vulnerable to single points of failure and centralized security risks

Engineering Contradiction:
Improveaccess control validationVSAvoidcentralized database architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized database into distributed blockchain nodes, where access control attributes are replicated across multiple independent nodes. This eliminates the single point of failure inherent in centralized databases while maintaining the ability to perform access validation through consensus mechanisms among distributed nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates multiple copies of the access control database distributed across different blockchain nodes. Each node maintains a replica of the access control attributes, enabling any node to independently validate access requests without relying on a central authority, thereby improving reliability while distributing system complexity.

Inventive Principle:
Principle #26Copying

2Reliability

If agents are installed on application servers to intercept and validate data access, then access control can be enforced, but the system becomes more complex and harder to maintain

Engineering Contradiction:
Improveaccess control enforcementVSAvoidagent installation and configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the access control validation logic from the application server agents and relocates it to the blockchain network. Instead of installing and maintaining agents on every application server, the validation functionality is moved to the distributed blockchain, where it operates independently and returns validation results to the application servers, thereby reducing system complexity while maintaining enforcement reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces the blockchain network as an intermediary between application servers and the access control database. The blockchain acts as a mediator that handles all validation operations, receiving access requests from application servers, querying the distributed access control attributes, and returning validation results, thereby eliminating the need for complex agent installations on application servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If text-based marking and validation are used for classified information, then the system is simple to implement, but it lacks the security and efficiency required for real-time permission determination

Engineering Contradiction:
Improveimplementation simplicityVSAvoidreal-time permission validation
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent replaces the mechanical text-based marking and validation system with a cryptographic blockchain-based system. Instead of using text labels that require manual comparison and validation, the system uses cryptographic hashes and digital signatures stored on the blockchain, enabling automated, real-time permission determination through cryptographic verification, thereby dramatically improving productivity while maintaining implementation feasibility through standardized cryptographic operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10922425B2Establishment of a confidential blockchain network
Publication Date: 2021.02.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10922425B2 patent drawing
  • US10922425B2 patent drawing
  • US10922425B2 patent drawing

AI summary

A permissioned blockchain is caused to be deployed to nodes. Access level blocks are established. Each access level block is configured to store a nanoblock. Each nanoblock is an encrypted database. The access level blocks include access levels blocks for users, and the corresponding access level block for each user includes security credentials for the user. For each access level block: nodes are selected for deployment of the access level block; and the access level block is replicated to each of the selected nodes, such that, after replicating the access level blocks, there are at least two copies of each access level block on the permissioned blockchain, and the permissioned blockchain is capable of performing cryptographic operations, including determining permissions of the users based on the security credentials for the users, and is further capable of storing details of the cryptographic operations on the nanoblocks.