Trust Broker System for Decentralized Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure resource access solutions rely on centralized authorities for user and device authentication, making it difficult to share trust information with third-party systems and unable to reassess trust based on access patterns or behavior during sessions, leading to inflexible and reactive security measures.

Innovation Solution

A Trust Broker System using a permissioned blockchain-based distributed trust ledger to encode and manage trust levels for clients, allowing decentralized trust management and dynamic adjustments through a trust account balance (TAB) that reflects user and device behavior, enabling secure access to resources without relying on explicit trust relationships or central authorities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If centralized authorities are used for user and device authentication, then security control is simplified and centralized, but trust information cannot be shared with third-party systems and cannot be dynamically reassessed

Engineering Contradiction:
Improvetrust sharing capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a distributed ledger as an intermediary layer between identity providers and relying parties. This mediator enables trust information to be shared across multiple third-party systems without requiring direct trust relationships or explicit APIs between them. The ledger stores trust decisions and session context that can be queried by any participant in the network, solving the trust sharing problem while maintaining a relatively simple interface for each participant.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The distributed ledger serves multiple functions: it stores authentication decisions, maintains session context, enables trust sharing across different relying parties, and provides a mechanism for dynamic trust reassessment. This single infrastructure replaces multiple specialized systems that would otherwise be needed for each function, reducing overall system complexity while enabling versatile trust management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If centralized authentication systems are used, then initial trust assessment is efficient, but dynamic trust reassessment based on access patterns and behavior is not possible

Engineering Contradiction:
Improvedynamic trust reassessmentVSAvoidtrust assessment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary trust assessment during initial authentication at the identity provider, storing the decision and session context in the distributed ledger before the user accesses any resources. This upfront action captures trust-relevant information including device attributes, user profile data, and initial risk assessment, eliminating the need for repeated authentication queries during the session.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where relying parties can query the distributed ledger for updated trust information based on observed access patterns and user behavior during the session. The ledger is updated with new trust decisions and session context, allowing dynamic reassessment without requiring continuous communication with the original identity provider. This creates a feedback loop that adapts trust levels based on actual usage.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If explicit trust relationships and APIs are required between systems, then trust can be controlled, but trust sharing with third parties becomes difficult and requires explicit relationships

Engineering Contradiction:
Improvetrust sharing with third partiesVSAvoidtrust relationship management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The distributed ledger acts as a universal intermediary that all systems can query without requiring bilateral trust relationships or custom APIs. Any relying party can query the ledger for trust decisions made by any identity provider, and any identity provider can publish trust decisions to the ledger. This eliminates the need for explicit trust relationships between each pair of systems, replacing them with a common queryable infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates copies of trust decisions and session context in the distributed ledger that can be queried by multiple relying parties simultaneously. Instead of requiring each system to maintain its own trust database and establish direct relationships with identity providers, the ledger stores replicated copies of trust information that can be accessed by any participant, reducing the need for redundant trust management infrastructure.

Inventive Principle:
Principle #26Copying

4Reliability

If reactive security measures are used, then security responses are simple, but security cannot proactively adapt to user behavior patterns

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements feedback loops where relying parties observe user behavior and access patterns, then query the distributed ledger for updated trust decisions based on this observed behavior. The ledger is updated with new trust assessments that reflect actual usage patterns, enabling the system to proactively adapt security measures based on feedback from real-world usage rather than relying solely on pre-configured reactive rules.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The trust management system transitions from static, pre-configured security policies to dynamic trust assessments that are continuously updated based on user behavior, access patterns, and observed security events. The distributed ledger stores evolving trust decisions that adapt to changing conditions, allowing the system to dynamically adjust security measures rather than relying on fixed reactive rules.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11700252B2Trust broker system for managing and sharing trust levels
Publication Date: 2023.07.11 PULSE SECURE LLC
  • US11700252B2 patent drawing
  • US11700252B2 patent drawing
  • US11700252B2 patent drawing

AI summary

This disclosure is related to devices, systems, and techniques for controlling access to network services based on a trust ledger. In some examples, a trust broker system enables a relying party to control network service access of client device, where the trust broker system comprises one or more computing devices configured to maintain a trust ledger including a trust account balance (TAB) associated with each user of a set of users, where the TAB associated with each user of the set of users represents a value used to determine whether the respective user is permitted to access a resource.