IP Library › Granted Patent US 11,121,876
Granted Patent B2
US 11,121,876 · App. 15/950,745 · Granted Sep 14, 2021

Distributed access control

Inventor: Abhijeet Haldar (Hyderabad, IN)
Assignee: Microsoft Technology Licensing, LLC
H04L9/3228G06F21/62H04L9/0825H04L9/3213H04L9/3247H04L63/10H04L63/12H04L63/0428H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,121,876
App. No.
15/950,745
Granted
Sep 14, 2021
Kind
B2
Abstract

A distributed access control system is disclosed. A payload is received at a voted principal from the client. The voted principal is selected from the plurality of minors. The payload is passed to the minors, and the user is verified by a consensus of the minors. A response packet, which includes an authentication unit, is prepared via a consensus of minors. The response packet can be provided to the client via the voted principal. The ledger is updated to include the authentication unit.

Claims (33)

1. A method of distributing access control in a distributed ledger, the method comprising:

receiving a payload at a voted principal of a plurality of networked minors, the principal including a selected minor determined by the plurality of minors;

verifying a user from the payload via a consensus of the minors, the minors including a ledger of user data, the payload verified against the distributed ledger of user data, the payload does not include user information included in the distributed ledger;

preparing a response packet having an authentication unit via the minors, wherein the minors generate a response token for the response packet and a first minor of the plurality of minors to generate the response token notifies other minors of the plurality of minors to stop generating the response token, the response packet provided via the principal; and

updating the distributed ledger to include the authentication unit.

2. The method of claim 1 wherein the payload includes an encrypted packet digitally signed using a private key and further includes a hash of the username and timestamp.

3. The method of claim 1 wherein the payload is received from a client.

4. The method of claim 3 wherein the principal interfaces with the client.

5. The method of claim 1 wherein the consensus of the minors includes at least a threshold percentage of the minors.

6. The method of claim 1 wherein the authentication unit includes a security token having an associated time to live.

7. The method of claim 6 wherein the security token provides access to a domain during the time to live.

8. The method of claim 1 wherein the distributed ledger is included on the minors.

9. The method of claim 1 wherein the response packet is verified by a consensus of the minors.

10. A computer readable storage device, which is not a propagating signal, to store computer executable instructions to control a processor to:

receive a payload at a voted principal of a plurality of networked minors, the principal including a selected minor determined by the plurality of minors;

verify a user from the payload via a consensus of the plurality of minors, the minors including a distributed ledger of user data, the payload verified against the ledger of user data, the payload does not include user information included in the distributed ledger;

prepare a response packet having an authentication unit via the networked minors, wherein the minors generate a response token for the response packet and a first minor of the plurality of minors to generate the response token notifies other minors of the plurality of minors to stop generating the response token, the response packet provided via the principal; and

update a distributed ledger to include the authentication unit.

11. The computer readable storage device of claim 10 wherein the payload includes user objects and is received from a client.

12. The computer readable storage device of claim 10 wherein access is denied if the user is not verified via the consensus of minors.

13. The computer readable storage device of claim 10 wherein the response packet is prepared by a consensus of minors.

14. The computer readable storage device of claim 10 wherein the response packet includes an encrypted security token.

15. A system, comprising:

a memory device to store a set of instructions; and

a processor to execute the set of instructions to:

receive a payload at a voted principal of a plurality of networked minors, the principal including a selected minor determined by the plurality of minors;

verify a user from the payload via a consensus of the plurality of minors, the minors including a distributed ledger of user data, the payload verified against the ledger of user data, the payload does not include user information included in the distributed ledger;

prepare a response packet having an authentication unit via the networked minors, wherein the minors generate a response token for the response packet and a first minor of the plurality of minors to generate the response token notifies other minors of the plurality of minors to stop generating the response token, the response packet provided via the principal; and

update the distributed ledger to include the authentication unit.

16. The system of claim 15 wherein the networked minors include the distributed ledger.

17. The system of claim 16 wherein the distributed ledger is a blockchain on the networked minors.

18. The system of claim 17 wherein the blockchain is implemented on a blockchain as a service cloud service.

19. The system of claim 15 wherein the networked minors include the voted principal.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2018
From: HALDAR, ABHIJEET
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 045509/0188 →
Continuity (1)
Related Publication 20190319794A1 · Oct 17, 2019
Cited By (1)
US 12,670,294