Permissioned Blockchain Access Control for Classified Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing classified information lack efficient and secure methods for access control and validation, particularly in ensuring that only authorized personnel can access sensitive documents based on their security clearance levels and location.
Innovation Solution
A permissioned blockchain is deployed across multiple nodes, with access level blocks configured to store encrypted nanoblocks, each containing user security credentials, allowing for real-time permission determination and secure replication to maintain data integrity and accessibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a central database is used to store access control attributes, then data access and validation can be performed, but the system becomes vulnerable to single points of failure and centralized security risks
Solution Approach 1:
The patent segments the centralized database into distributed blockchain nodes, where access control attributes are replicated across multiple independent nodes. This eliminates the single point of failure inherent in centralized databases while maintaining the ability to perform access validation through consensus mechanisms among distributed nodes.
Solution Approach 2:
The patent creates multiple copies of the access control database distributed across different blockchain nodes. Each node maintains a replica of the access control attributes, enabling any node to independently validate access requests without relying on a central authority, thereby improving reliability while distributing system complexity.
2Reliability
If agents are installed on application servers to intercept and validate data access, then access control can be enforced, but the system becomes more complex and harder to maintain
Solution Approach 1:
The patent extracts the access control validation logic from the application server agents and relocates it to the blockchain network. Instead of installing and maintaining agents on every application server, the validation functionality is moved to the distributed blockchain, where it operates independently and returns validation results to the application servers, thereby reducing system complexity while maintaining enforcement reliability.
Solution Approach 2:
The patent introduces the blockchain network as an intermediary between application servers and the access control database. The blockchain acts as a mediator that handles all validation operations, receiving access requests from application servers, querying the distributed access control attributes, and returning validation results, thereby eliminating the need for complex agent installations on application servers.
3Ease of manufacture
If text-based marking and validation are used for classified information, then the system is simple to implement, but it lacks the security and efficiency required for real-time permission determination
Solution Approach 1:
The patent replaces the mechanical text-based marking and validation system with a cryptographic blockchain-based system. Instead of using text labels that require manual comparison and validation, the system uses cryptographic hashes and digital signatures stored on the blockchain, enabling automated, real-time permission determination through cryptographic verification, thereby dramatically improving productivity while maintaining implementation feasibility through standardized cryptographic operations.
Data Source
AI summary
A permissioned blockchain is caused to be deployed to nodes. Access level blocks are established. Each access level block is configured to store a nanoblock. Each nanoblock is an encrypted database. The access level blocks include access levels blocks for users, and the corresponding access level block for each user includes security credentials for the user. For each access level block: nodes are selected for deployment of the access level block; and the access level block is replicated to each of the selected nodes, such that, after replicating the access level blocks, there are at least two copies of each access level block on the permissioned blockchain, and the permissioned blockchain is capable of performing cryptographic operations, including determining permissions of the users based on the security credentials for the users, and is further capable of storing details of the cryptographic operations on the nanoblocks.


