Distributed file system for managing permissioned access to records
The distributed file system includes a blockchain node with one or more records recorded in a blockchain of the blockchain node by a series of immutable transactions. More specifically, the blockchain node receives a request to permit access to a record by a service provider. The blockchain node is further configured to determine a geofenced area associated with the service provider, the geofenced area being an area encompassing a geographic location associated with the service provider, and to determine a location of the mobile device associated with the record based on the request. When the blockchain node determines that the mobile device is within the geofenced area associated with the service provider, the blockchain node sends a biometric confirmation request to the mobile device to permit the service provider access to the record.
1 . A method performed by at least one processor, the method comprising:
receiving, at a blockchain node of a distributed file system comprising one or more records associated with a user, a request to permit access to a record of the one or more records by a service provider, wherein the request comprises a record identifier associated with the record, an indication of a location of the service provider, and an indication of a mobile device associated with an owner of the record, and wherein the one or more records are stored in a blockchain of the blockchain node by a series of immutable transactions;
identifying the record stored in the blockchain based on the record identifier;
determining a geofenced area associated with the service provider based on the indication of the location of the service provider, wherein the geofenced area corresponds with an area encompassing a geographic location associated with the service provider;
querying a location of the mobile device;
determining that the mobile device is within the geofenced area associated with the service provider;
in response to entry of the mobile device in the geofenced area, identifying the mobile device as being associated with the user, wherein the identifying is based on a handshake between the mobile device and the service provider with an application running and active on the mobile device to facilitate user interaction with a communication network of the service provider;
sending a biometric confirmation request to the mobile device for a biometric confirmation to permit the service provider access to the record based upon determining that the mobile device is within the geofenced area and identifying that the mobile device is associated with the user;
receiving the biometric confirmation from the mobile device;
upon receiving the biometric confirmation, determining validation of the request to permit access to the record, wherein the validation comprises receiving the biometric confirmation within a specified time period; and
upon determining the validation, transmitting the record or a reference to the record from the blockchain to a service provider device associated with the service provider according to permission information associated with the record.
2 . The method of claim 1 , wherein the permission information comprises ephemeral permissions that expire after a pre-determined amount of time such that the service provider cannot access the record or the reference to the record after the pre-determined amount of time has passed.
3 . The method of claim 1 , wherein the permission information comprises permissions that expire after a pre-determined number of uses such that the service provider cannot access the record or the reference to the record after the pre-determined number of uses has been exceeded.
4 . The method of claim 1 , comprising transmitting a key to the service provider device and transmitting the record or the reference to the record in response to receipt of the key.
5 . The method of claim 4 , comprising, prior to transmitting the record or the reference to the record, decrypting the record or the reference to the record based in part on the key.
6 . The method of claim 1 , wherein transmitting the record or the reference to the record from the blockchain to the service provider device associated with the service provider comprises:
transmitting a key to the service provider device;
receiving an additional request from the service provider device to access the one or more records associated with the user, wherein the additional request comprises the key;
determining, based in part on the key and the permissions information, whether the additional request is permitted; and
when the additional request is permitted:
transmitting the record or the reference to the record from the blockchain to the service provider device associated with the service provider; and
when the additional request is not permitted:
outputting a notification to the service provider device associated with the service provider that access to the one or more records or the reference to the one or more records has been denied.
7 . The method of claim 1 , comprising, after transmitting the record or the reference to the record from the blockchain to the service provider device associated with the service provider:
receiving, at the blockchain node, additional location information of the mobile device;
determining that the mobile device is outside the geographic location associated with the service provider based on the additional location information of the mobile device; and
revoking access by the service provider to the record or the reference to the record.
8 . The method of claim 1 , wherein the one or more records are an electronic medical record of the user.
9 . The method of claim 1 , wherein the one or more records are selected from a plurality of user-associated records based on the permission information.
10 . The method of claim 1 , wherein the one or more records are stored as hashed record data in an interplanetary file system, and wherein the record identifier comprises a hash address associated with a respective portion of the hashed record data.
11 . The method of claim 1 , wherein the one or more records are owned by the user and stored in the distributed file system.
12 . A distributed file system, comprising:
a blockchain node comprising one or more records associated with a user, wherein the one or more records are stored in a blockchain of the blockchain node by a series of immutable transactions; and
a processor configured to:
receive a request to permit access to a record of the one or more records by a service provider, wherein the request comprises a record identifier associated with the record, an indication of a location of the service provider, and an indication of a mobile device associated with an owner of the record;
identify the record stored in the blockchain based on the record identifier;
determine a geofenced area associated with the service provider based on the indication of the location of the service provider, wherein the geofenced area corresponds with an area encompassing a geographic location associated with the service provider;
query a location of the mobile device;
determine that the mobile device is within the geofenced area associated with the service provider;
in response to entry of the mobile device in the geofenced area, identify the mobile device as being associated with the user, wherein the identifying is based on a handshake between the mobile device and the service provider with an application running and active on the mobile device to facilitate user interaction with a communication network of the service provider;
send a biometric confirmation request to the mobile device for a biometric confirmation to permit the service provider access to the record based upon the determination that the mobile device is within the geofenced area and the identification that the mobile device is associated with the user;
receive the biometric confirmation from the mobile device;
upon receiving the biometric confirmation, transmit the record or a reference to the record from the blockchain to a service provider device associated with the service provider according to permission information associated with the record;
receive an updated request to permit access to the record of the one or more records by the service provider;
receive updated location information of the mobile device;
determine that the mobile device is outside the geographic location associated with the service provider based on the updated location information of the mobile device;
denying access by the service provider to the record or the reference to the record; and
transmitting a notification to the service provider that the request has been denied.
13 . The distributed file system of claim 12 , wherein the mobile device comprises a global positioning system (GPS) sensor, wherein the location of the mobile device is based in part on GPS location information determined by the GPS sensor.
14 . The distributed file system of claim 12 , wherein the mobile device comprises a fingerprint scanner, wherein the biometric confirmation comprises a fingerprint associated with the user.
15 . The distributed file system of claim 12 , wherein the mobile device comprises a camera, wherein the biometric confirmation comprises a facial scan, an eye scan, or a combination thereof, associated with the user.
16 . The distributed file system of claim 12 , wherein the request comprises a hypertext transfer protocol (HTTP) request.
17 . A tangible, non-transitory, machine-readable medium, comprising machine-readable instructions which, when executed, cause at least one processor to perform operations comprising:
receiving, at a blockchain node of a distributed file system comprising one or more records associated with a user, a request to permit access to a record of the one or more records by a service provider, wherein the request comprises a record identifier associated with the record, an indication of a location of the service provider, and an indication of a mobile device associated with an owner of the record, and wherein the one or more records are stored in a blockchain of the blockchain node by a series of immutable transactions;
identifying the record stored in the blockchain based on the record identifier;
determining a geofenced area associated with the service provider based on the indication of the location of the service provider, wherein the geofenced area corresponds with an area encompassing a geographic location associated with the service provider;
querying a location of the mobile device;
determining that the mobile device is within the geofenced area associated with the service provider;
in response to entry of the mobile device in the geofenced area, identifying the mobile device as being associated with the user, wherein the identifying is based on a handshake between the mobile device and the service provider with an application running and active on the mobile device to facilitate user interaction with a communication network of the service provider;
transmitting a biometric confirmation request to the mobile device for a biometric confirmation to permit the service provider access to the record based upon determining that the mobile device is within the geofenced area and identifying that the mobile device is associated with the user;
receiving the biometric confirmation from the mobile device;
upon receiving the biometric confirmation, transmitting the record or a reference to the record from the blockchain to a service provider device associated with the service provider according to permission information associated with the record;
determining a pre-determined amount of time has passed; and
revoking access by the service provider to the record or the reference to the record.
18 . The tangible, non-transitory, machine-readable medium of claim 17 , wherein the operations comprise:
determining the geofenced area based in part on an internet protocol (IP) address of the service provider device, a basic service set identifier (BSSID) of the service provider device, a service set identifier (SSID) of the service provider device, a communication network accessed by the service provider device, or a combination thereof.
19 . The tangible, non-transitory, machine-readable medium of claim 17 , wherein the operations comprise:
receiving an additional request from the service provider device to access the record;
querying the location of the mobile device associated with the user to obtain location information of the mobile device;
determining that the mobile device is not within the geofenced area associated with the service provider based on the location information of the mobile device;
denying access by the service provider to the record based in part on the location information of the mobile device; and
outputting a notification to the service provider device.
20 . The tangible, non-transitory, machine-readable medium of claim 17 , wherein the operations comprise:
receiving an additional request from the service provider device to access additional records associated with the user;
determining, based on information related to the additional records, that the service provider lacks permission to access the additional records;
denying access by the service provider to the additional records based in part on the information related to the additional records; and
outputting a notification to the service provider device.