IP Library › Granted Patent US 12,225,135
Granted Patent B2
US 12,225,135 · App. 17/783,077 · Granted Feb 11, 2025

Access control apparatus, control method, and non-transitory computer readable medium

Inventor: Takashi Yasuda (Tokyo, JP)
Assignee: NEC CORPORATION
H04L9/3231H04L9/321H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,135
App. No.
17/783,077
Granted
Feb 11, 2025
Kind
B2
Abstract

An access control apparatus ( 2000 ) acquires a request ( 20 ) for access to data stored in a first storage apparatus 30 . The access control apparatus ( 2000 ) acquires privilege information ( 70 ) from a blockchain storage ( 40 ). The privilege information ( 70 ) represents access privilege pertaining to access to the first storage apparatus ( 30 ). The access control apparatus ( 2000 ) determines whether requested access is within a range of the access privilege of a target entity ( 10 ) being a subject of the request ( 20 ), by using the privilege information ( 70 ) of the target entity ( 10 ). When it is determined that the access is within the range of the access privilege of the target entity ( 10 ), the access control apparatus ( 2000 ) executes the access.

Claims (39)

1. An access control apparatus, comprising:

at least one memory storing instructions; and

at least one processor configured to execute the instructions to perform operations comprising:

acquiring a request from a first user for access to data of a second user stored in a data storage area of a first storage apparatus allocated for the second user, the request including first authentication information used for authentication of the second user;

acquiring privilege information from a second storage apparatus, the privilege information representing access privilege of the first user with respect to the data stored in the data storage area allocated for the second user;

determining whether the access is within a range of the access privilege of the first user, by using the privilege information of the first user;

executing the access to read second authentication information of the second user stored in the data storage area allocated for the second user, based on the access being determined to be within the range;

performing authentication of the second user by comparing the first authentication information with the second authentication information;

acquiring results of procedures after the authentication based on the authentication being successful; and

storing, in the data storage area allocated for the second user, the results of procedures in association with identification information of the first user, wherein

the second storage apparatus is a blockchain storage.

2. The access control apparatus according to claim 1 , wherein

the first authentication information and the second authentication information comprise biometric information.

3. The access control apparatus according to claim 1 , wherein

the operations further comprise outputting a notification representing a result of the authentication, and

the notification does not include the first authentication information.

4. A control method to be executed by a computer, comprising:

acquiring a request from a first user for access to data of a second user stored in a data storage area of a first storage apparatus allocated for the second user, the request including first authentication information used for authentication of the second user;

acquiring privilege information from a second storage apparatus, the privilege information representing access privilege of the first user with respect to the data stored in the data storage area allocated for the second user;

determining whether the access is within a range of the access privilege of the first user, by using the privilege information of the first user;

executing the access to read second authentication information of the second user stored in the data storage area allocated for the second user, based on the access being determined to be within the range;

performing authentication of the second user by comparing the first authentication information with the second authentication information;

acquiring results of procedures after the authentication based on the authentication being successful; and

storing, in the data storage area allocated for the second user, the results of procedures in association with identification information of the first user, wherein

the second storage apparatus is a blockchain storage.

5. The control method according to claim 4 , wherein

the first authentication information and the second authentication information comprise biometric information.

6. The control method according to claim 4 , further comprising,

outputting a notification representing a result of the authentication, wherein

the notification does not include authentication information acquired from the first storage apparatus.

7. A non-transitory computer readable medium storing a program causing a computer to execute operations, comprising:

acquiring a request from a first user for access to data of a second user stored in a data storage area of a first storage apparatus allocated for the second user, the request including first authentication information used for authentication of the second user;

acquiring, privilege information from a second storage apparatus, the privilege information representing access privilege of the first user with respect to the data stored in the data storage area allocated for the second user;

determining whether the access is within a range of the access privilege of the first user, by using the privilege information of the first user;

executing the access to read second authentication information of the second user stored in the data storage area allocated for the second user, based on the access being determined to be within the range;

performing authentication of the second user by comparing the first authentication information with the second authentication information;

acquiring results of procedures after the authentication based on the authentication being successful; and

storing, in the data storage area allocated for the second user, the results of procedures in association with identification information of the first user, wherein

the second storage apparatus is a blockchain storage.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2022
From: YASUDA, TAKASHI
To: NEC CORPORATION
Reel/Frame 060120/0636 →
Continuity (1)
Related Publication 20230024635A1 · Jan 26, 2023
References Cited (9)
US 20180060496A1 · Bulleit · 2018 [cited by examiner]
US 20190294817A1 · Hennebert · 2019 [cited by examiner]
CN 107480555A · 2017 [cited by applicant]
CN 109286616A · 2019 [cited by applicant]
JP 2013045278A · 2013 [cited by applicant]
JP 2017195627A · 2017 [cited by applicant]
JP 2018081464A · 2018 [cited by applicant]
International Search Report for PCT Application No. PCT/JP2019/050161, mailed on Mar. 10, 2020. [cited by applicant]
JP Office Action for JP Application No. 2021-565303, mailed on Jul. 18, 2023 with English Translation. [cited by applicant]
Cited By (1)
US 12,393,716