Access Identity Updates Filtered by TEE Access Conditions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access management systems face issues of unnecessary information diffusion during updates to identification information or access conditions, leading to increased management costs and security risks.

Innovation Solution

An access management system utilizing a specific ID management server and a trusted execution environment (TEE) to store and manage identification information and access conditions on a blockchain, ensuring updates are only notified when relevant to access conditions, thereby preventing unnecessary diffusion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If the access management side publishes the access condition to the management side of the identification information to notify only relevant updates, then the notification precision is improved, but the access condition information is unnecessarily diffused

Engineering Contradiction:
Improvenotification precisionVSAvoidaccess condition diffusion
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

A Trusted Execution Environment (TEE) is introduced as an intermediary component that independently compares update contents with access conditions. The TEE acts as a mediator between the identification information management side and the access management side, determining whether updates are related to access conditions without requiring the access management side to publish access conditions to the identification information management side, thus preventing unnecessary diffusion of access condition information while maintaining precise notification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where the TEE continuously monitors and compares update contents against stored access conditions, and only notifies the access management side when relevant changes are detected. This feedback loop ensures that notifications are precisely targeted to relevant updates without requiring broad information publication

Inventive Principle:
Principle #23Feedback

2Measurement precision

If the access management side publishes the access condition to the management side of the identification information, then the notification accuracy is improved, but the management cost increases

Engineering Contradiction:
Improvenotification accuracyVSAvoidmanagement cost
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The TEE serves as a cost-effective intermediary that performs automated comparison of update contents with access conditions. This eliminates the need for expensive manual review processes or broad publication of access conditions, reducing management costs while maintaining high notification accuracy through automated, intelligent filtering

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The TEE autonomously performs the comparison and determination process without requiring human intervention or complex communication protocols between systems. The system self-services by automatically identifying relevant updates and generating notifications only when necessary, reducing overall management overhead and costs

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12556544B2Access management system
Publication Date: 2026.02.17 FUJIFILM CORP
  • US12556544B2 patent drawing
  • US12556544B2 patent drawing
  • US12556544B2 patent drawing

AI summary

In a case where an update of identification information is performed, a content of the update (identification information after update) is stored on a blockchain. In addition, in a case where the update of the identification information is performed, a TEE determines whether or not the update content is related to an access condition. Then, in a case where it is determined that the update content is related to the access condition, a data store terminal is notified that the update is performed.