IP Library Granted Patent US 11,599,668
Granted Patent B2
US 11,599,668 · App. 17/078,469 · Granted Mar 7, 2023

Securing access to confidential data using a blockchain ledger

Inventors: Joel Vincent Nation (Bruce, AU); James Peter George Ryles (Dunlop, AU)
Assignee: Oracle International Corporation
G06F21/6245G06F16/1805H04L9/0643H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,599,668
App. No.
17/078,469
Granted
Mar 7, 2023
Kind
B2
Abstract

Methods and systems are provided for securing access to confidential data using a blockchain ledger. An update to access permissions can be received from a first entity on behalf of a second entity, the update can change access permissions to a confidential data store. A smart contract that validates the update can be called. Upon consensus from a blockchain community, the update to the access permissions for the second entity can be executed. The blockchain community can be a plurality of different organizations that share access to the confidential data store, and the update can be appended to a blockchain ledger that stores access permissions for the blockchain community.

Claims (39)

1. A method for securing access to confidential data using a blockchain ledger, the method comprising:

receiving an update to access permissions from a first entity on behalf of a second entity, wherein at least a portion of data stored at a confidential data store is keyed with a hierarchical security parameter, the updated access permissions correspond to an update to the hierarchical security parameter, and the updated access permissions provide the second entity row level access to a secure relational data table stored at the confidential data store;

calling a smart contract that validates the update; and

upon consensus from a blockchain community, executing, using a processor, the update to the access permissions for the second entity, wherein the update is appended to a blockchain ledger that stores access permissions for the blockchain community, the blockchain community comprising a plurality of different organizations that share access to the confidential data store.

2. The method of claim 1 , wherein the smart contract validates identities for the first entity and the second entity using an identity management system and validates that the identity of the first entity has permission to update security parameters for the identity of the second entity.

3. The method of claim 2 , further comprising:

receiving a request to access the confidential data store from the second identity;

retrieving the updated access permissions for the second identity from the blockchain; and

permitting, to the second identity, access to confidential information keyed with security parameters that correspond to the updated access permissions.

4. The method of claim 1 , wherein the confidential data store comprises a virtual private database, and the access permissions correspond to security parameter for the virtual private database.

5. The method of claim 4 , wherein the updated access permissions reflect a change in level for the hierarchical security parameter.

6. The method of claim 1 , wherein the consensus is reached based on consensus actions from a threshold of the blockchain community, the consensus actions comprising electronic votes about the update to the access permissions, the electronic votes indicating whether the update to the access permissions should be executed.

7. The method of claim 1 , wherein the blockchain ledger is used to verify access permissions for the first entity and the second entity.

8. The method of claim 7 , wherein the blockchain ledger comprises an encrypted and immutable ledger of access permissions transactions for the blockchain community.

9. A non-transitory computer readable medium having instructions stored thereon that, when executed by a processor, cause the processor to secure access to confidential data, the securing comprising:

receiving an update to access permissions from a first entity on behalf of a second entity, wherein at least a portion of data stored at a confidential data store is keyed with a hierarchical security parameter, the updated access permissions correspond to an update to the hierarchical security parameter, and the updated access permissions provide the second entity row level access to a secure relational data table stored at the confidential data store;

calling a smart contract that validates the update; and

upon consensus from a blockchain community, executing the update to the access permissions for the second entity, wherein the update is appended to a blockchain ledger that stores access permissions for the blockchain community, the blockchain community comprising a plurality of different organizations that share access to the confidential data store.

10. The non-transitory computer readable medium of claim 9 , wherein the smart contract validates identities for the first entity and the second entity using an identity management system and validates that the identity of the first entity has permission to update security parameters for the identity of the second entity.

11. The non-transitory computer readable medium of claim 10 , wherein the securing further comprises:

receiving a request to access the confidential data store from the second identity;

retrieving the updated access permissions for the second identity from the blockchain; and

permitting, to the second identity, access to confidential information keyed with security parameters that correspond to the updated access permissions.

12. The non-transitory computer readable medium of claim 9 , wherein the confidential data store comprises a virtual private database, and the access permissions correspond to security parameter for the virtual private database.

13. The non-transitory computer readable medium of claim 12 , wherein the updated access permissions reflect a change in level for the hierarchical security parameter.

14. The non-transitory computer readable medium of claim 9 , wherein the consensus is reached based on consensus actions from a threshold of the blockchain community, the consensus actions comprising electronic votes about the update to the access permissions, the electronic votes indicating whether the update to the access permissions should be executed.

15. The non-transitory computer readable medium of claim 9 , wherein the blockchain ledger is used to verify access permissions for the first entity and the second entity.

16. The non-transitory computer readable medium of claim 15 , wherein the blockchain ledger comprises an encrypted and immutable ledger of access permissions transactions for the blockchain community.

17. A system for securing access to confidential data using a blockchain ledger, the system comprising:

a processor in communication with a storage device, wherein the processor is configured to execute instructions to:

receive an update to access permissions from a first entity on behalf of a second entity, wherein at least a portion of data stored at a confidential data store is keyed with a hierarchical security parameter, the updated access permissions correspond to an update to the hierarchical security parameter, and the updated access permissions provide the second entity row level access to a secure relational data table stored at the confidential data store;

call a smart contract that validates the update; and

upon consensus from a blockchain community, execute the update to the access permissions for the second entity, wherein the update is appended to a blockchain ledger that stores access permissions for the blockchain community, the blockchain community comprising a plurality of different organizations that share access to the confidential data store.

18. The system of claim 17 , wherein the smart contract validates identities for the first entity and the second entity using an identity management system and validates that the identity of the first entity has permission to update security parameters for the identity of the second entity.

19. The system of claim 18 , wherein the processor is further configured to execute instructions to:

receive a request to access the confidential data store from the second identity;

retrieve the updated access permissions for the second identity from the blockchain; and

permit, to the second identity, access to confidential information keyed with security parameters that correspond to the updated access permissions.

20. The system of claim 18 , wherein the blockchain ledger comprises an encrypted and immutable ledger of access permissions transactions for the blockchain community.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE U.S. APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 054149 FRAME: 0380. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 7, 2020
From: VINCENT, JOEL; RYLES, JAMES PETER GEORGE
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 054623/0128 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBER PREVIOUSLY RECORDED AT REEL: 054149 FRAME: 0380. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 26, 2020
From: NATION, JOEL VINCENT; RYLES, JAMES PETER GEORGE
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 054203/0790 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2020
From: NATION, JOEL VINCENT; RYLES, JAMES PETER GEORGE
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 054149/0380 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2020
From: NATION, JOEL VINCENT
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 054149/0481 →
Continuity (2)
Continuation 15991204 · May 29, 2018
Related Publication 20210056081A1 · Feb 25, 2021
Cited By (1)
US 12,724,916