IP Library Granted Patent US 12,368,591
Granted Patent B2
US 12,368,591 · App. 17/654,107 · Granted Jul 22, 2025

Blockchain enhanced identity access management system

Inventors: Marek Zidek (Dhahran, SA); Mazen A. Baragaba (Dammam, SA); Muhammad S. Aljuaid (Dammam, SA)
Assignee: Saudi Arabian Oil Company
H04L9/3226H04L9/3239H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,591
App. No.
17/654,107
Granted
Jul 22, 2025
Kind
B2
Abstract

Systems and methods include a computer-implemented method for verifying blockchain transaction. A request is received in a blockchain for a user to use an application. A three-blockchain cluster verification process is performed in response to receiving the request. Verification that the application is authorized is performed using a nodes blockchain cluster in the blockchain based on user-application data pre-verified by at least two administrators and stored in the nodes blockchain cluster. Verification that the user exists and is authorized is performed using a users/objects blockchain cluster in the blockchain different from the nodes blockchain cluster, where the verifying is based on the user-application data pre-verified by the at least two administrators and stored in the users/objects blockchain cluster. Verification that credentials for the user exist is performed using a passwords blockchain cluster in the blockchain different from the nodes blockchain cluster and the users/objects blockchain cluster, where the verifying is based on the user-application data pre-verified by the at least two administrators and stored in the passwords blockchain cluster. Access to the application is granted to the user in response to successfully completing the three-blockchain cluster verification process, including verification using the nodes blockchain cluster, the users/objects blockchain cluster, and the passwords blockchain cluster.

Claims (58)

1. A computer-implemented method, comprising:

receiving, in a blockchain, a request for a user to use an application, the blockchain comprising a host validator module providing application firewall functionality, blocking unauthorized user devices from accessing the application;

performing, in response to receiving the request, a three-blockchain cluster verification process, comprising:

verifying, using a nodes blockchain cluster in the blockchain, that the application is authorized, wherein the verifying is based on user-application data verified by at least two administrators and stored in the nodes blockchain cluster;

verifying, using an object blockchain cluster in the blockchain and different from the nodes blockchain cluster, that the user exists and is authorized, wherein the verifying is based on the user-application data verified by the at least two administrators and stored in the object blockchain cluster; and

validating, using a passwords blockchain cluster in the blockchain and different from the nodes blockchain cluster and the object blockchain cluster, over three different blockchain clusters, that credentials for the user exist, wherein the verifying is based on the user-application data verified by the at least two administrators and stored in the passwords blockchain cluster, each node of the nodes blockchain cluster comprising data defining which system is allowed to communicate with another system; and

granting, to the user, access to the application in response to successfully completing the three-blockchain cluster verification process, comprising verification using the nodes blockchain cluster, the object blockchain cluster, and the passwords blockchain cluster.

2. The computer-implemented method of claim 1 , further comprising:

receiving user-application data for verification of the user and for verification of the application used by the user;

validating, using validation received from the at least two administrators, the user-application data; and

in response to validating the user-application data using validation received from the at least two administrators, generating, using the user-application data:

at least one host record in the nodes blockchain cluster,

at least one identity record in the object blockchain cluster, and

at least one password record in the passwords blockchain cluster.

3. The computer-implemented method of claim 2 , further comprising storing, on an identity server different from a web server, the at least one host record, the at least one identity record, and the at least one password record.

4. The computer-implemented method of claim 1 , wherein a majority of cluster nodes of the nodes blockchain cluster, the object blockchain cluster, and the passwords blockchain cluster reside in a corporate network.

5. The computer-implemented method of claim 1 , wherein performing the three-blockchain cluster verification process comprises accessing a plurality of records in the nodes blockchain cluster, the object blockchain cluster, and the passwords blockchain cluster.

6. The computer-implemented method of claim 5 , wherein the plurality of records comprise n records, n+1 records, and n+2 records.

7. The computer-implemented method of claim 5 , wherein the plurality of records are linked with block hashes.

8. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

receiving, in a blockchain, a request for a user to use an application, the blockchain comprising a host validator module providing application firewall functionality, blocking unauthorized user devices from accessing the application;

performing, in response to receiving the request, a three-blockchain cluster verification process, comprising:

verifying, using a nodes blockchain cluster in the blockchain, that the application is authorized, wherein the verifying is based on user-application data verified by at least two administrators and stored in the nodes blockchain cluster;

verifying, using an object blockchain cluster in the blockchain and different from the nodes blockchain cluster, that the user exists and is authorized, wherein the verifying is based on the user-application data verified by the at least two administrators and stored in the object blockchain cluster; and

validating, using a passwords blockchain cluster in the blockchain and different from the nodes blockchain cluster and the object blockchain cluster, over three different blockchain clusters, that credentials for the user exist, wherein the verifying is based on the user-application data verified by the at least two administrators and stored in the passwords blockchain cluster, each node of the nodes blockchain cluster comprising data defining which system is allowed to communicate with another system; and

granting, to the user, access to the application in response to successfully completing the three-blockchain cluster verification process, comprising verification using the nodes blockchain cluster, the object blockchain cluster, and the passwords blockchain cluster.

9. The non-transitory, computer-readable medium of claim 8 , the operations further comprising:

receiving user-application data for verification of the user and for verification of the application used by the user;

validating, using validation received from the at least two administrators, the user-application data; and

in response to validating the user-application data using validation received from the at least two administrators, generating, using the user-application data:

at least one host record in the nodes blockchain cluster,

at least one identity record in the object blockchain cluster, and

at least one password record in the passwords blockchain cluster.

10. The non-transitory, computer-readable medium of claim 9 , further comprising storing, on an identity server different from a web server, the at least one host record, the at least one identity record, and the at least one password record.

11. The non-transitory, computer-readable medium of claim 8 , wherein a majority of cluster nodes of the nodes blockchain cluster, the object blockchain cluster, and the passwords blockchain cluster reside in a corporate network.

12. The non-transitory, computer-readable medium of claim 8 , wherein performing the three-blockchain cluster verification process comprises accessing a plurality of records in the nodes blockchain cluster, the object blockchain cluster, and the passwords blockchain cluster.

13. The non-transitory, computer-readable medium of claim 12 , wherein the plurality of records comprise n records, n+1 records, and n+2 records.

14. The non-transitory, computer-readable medium of claim 12 , wherein the plurality of records are linked with block hashes.

15. A computer-implemented system, comprising:

one or more processors; and

a non-transitory computer-readable storage medium coupled to the one or more processors and storing programming instructions for execution by the one or more processors, the programming instructions instructing the one or more processors to perform operations comprising:

receiving, in a blockchain, a request for a user to use an application, the blockchain comprising a host validator module providing application firewall functionality, blocking unauthorized user devices from accessing the application;

performing, in response to receiving the request, a three-blockchain cluster verification process, comprising:

verifying, using a nodes blockchain cluster in the blockchain, that the application is authorized, wherein the verifying is based on user-application data verified by at least two administrators and stored in the nodes blockchain cluster;

verifying, using an object blockchain cluster in the blockchain and different from the nodes blockchain cluster, that the user exists and is authorized, wherein the verifying is based on the user-application data verified by the at least two administrators and stored in the object blockchain cluster; and

validating, using a passwords blockchain cluster in the blockchain and different from the nodes blockchain cluster and the object blockchain cluster, over three different blockchain clusters, that credentials for the user exist, wherein the verifying is based on the user-application data verified by the at least two administrators and stored in the passwords blockchain cluster, each node of the nodes blockchain cluster comprising data defining which system is allowed to communicate with another system; and

granting, to the user, access to the application in response to successfully completing the three-blockchain cluster verification process, comprising verification using the nodes blockchain cluster, the object blockchain cluster, and the passwords blockchain cluster.

16. The computer-implemented system of claim 15 , the operations further comprising:

receiving user-application data for verification of the user and for verification of the application used by the user;

validating, using validation received from the at least two administrators, the user-application data; and

in response to validating the user-application data using validation received from the at least two administrators, generating, using the user-application data:

at least one host record in the nodes blockchain cluster,

at least one identity record in the object blockchain cluster, and

at least one password record in the passwords blockchain cluster.

17. The computer-implemented system of claim 15 , wherein a majority of cluster nodes of the nodes blockchain cluster, the object blockchain cluster, and the passwords blockchain cluster reside in a corporate network.

18. The computer-implemented system of claim 15 , wherein performing the three-blockchain cluster verification process comprises accessing a plurality of records in the nodes blockchain cluster, the object blockchain cluster, and the passwords blockchain cluster.

19. The computer-implemented system of claim 18 , wherein the plurality of records comprise n records, n+1 records, and n+2 records.

20. The computer-implemented system of claim 18 , wherein the plurality of records are linked with block hashes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2022
From: ZIDEK, MAREK; BARAGABA, MAZEN A.; ALJUAID, MUHAMMAD S.
To: SAUDI ARABIAN OIL COMPANY
Reel/Frame 059219/0139 →
Continuity (1)
Related Publication 20230291564A1 · Sep 14, 2023
References Cited (101)
US 5864662A · Brownmiller et al. · 1999 [cited by applicant]
US 6072777A · Bencheck et al. · 2000 [cited by applicant]
US 7237138B2 · Greenwald et al. · 2007 [cited by applicant]
US 7428300B1 · Drew · 2008 [cited by applicant]
US 7600007B1 · Lewis · 2009 [cited by applicant]
US 8782225B2 · Bali · 2014 [cited by applicant]
US 9432865B1 · Jadunandan et al. · 2016 [cited by applicant]
US 9491764B1 · Ross et al. · 2016 [cited by applicant]
US 9729414B1 · Oliveira et al. · 2017 [cited by applicant]
US 9992022B1 · Chapman et al. · 2018 [cited by applicant]
US 10116539B1 · Fuchs et al. · 2018 [cited by applicant]
US 10045252B2 · Agarwal et al. · 2018 [cited by applicant]
US 10191778B1 · Yang et al. · 2019 [cited by applicant]
US 10313213B1 · Aygun · 2019 [cited by applicant]
US 10567243B2 · Tippenhauer et al. · 2020 [cited by applicant]
US 10601684B2 · Hasmi et al. · 2020 [cited by applicant]
US 10644979B2 · Samadi · 2020 [cited by applicant]
US 10680889B2 · Vasseur et al. · 2020 [cited by applicant]
US 10764142B2 · Bertsche et al. · 2020 [cited by applicant]
US 11316700B1 · Michaelis · 2022 [cited by examiner]
US 11689918B2 · Sethi · 2023 [cited by examiner]
US 20010039577A1 · Barkai et al. · 2001 [cited by applicant]
US 20030126254A1 · Cruickshank, III et al. · 2003 [cited by applicant]
US 20030145081A1 · Lau · 2003 [cited by applicant]
US 20030225549A1 · Shay et al. · 2003 [cited by applicant]
US 20040064760A1 · Hicks et al. · 2004 [cited by applicant]
US 20040103181A1 · Chambliss · 2004 [cited by applicant]
US 20060056389A1 · Monk · 2006 [cited by applicant]
US 20060182034A1 · Klinker et al. · 2006 [cited by applicant]
US 20060215564A1 · Breitgand et al. · 2006 [cited by applicant]
US 20060221876A1 · Kosanovic et al. · 2006 [cited by applicant]
US 20060276995A1 · Breitgand et al. · 2006 [cited by applicant]
US 20060293777A1 · Breitgand et al. · 2006 [cited by applicant]
US 20080016412A1 · White et al. · 2008 [cited by applicant]
US 20080027961A1 · Arlitt et al. · 2008 [cited by applicant]
US 20080049753A1 · Heinze et al. · 2008 [cited by applicant]
US 20090059895A1 · Yasrebi · 2009 [cited by applicant]
US 20090089438A1 · Agarwal et al. · 2009 [cited by applicant]
US 20090181665A1 · Sater et al. · 2009 [cited by applicant]
US 20100088410A1 · Ridley · 2010 [cited by applicant]
US 20100103822A1 · Montwill · 2010 [cited by applicant]
US 20100211673A1 · Kosbab et al. · 2010 [cited by applicant]
US 20110129071A1 · Blackburn et al. · 2011 [cited by applicant]
US 20110295942A1 · Raghunath et al. · 2011 [cited by applicant]
US 20120163386A1 · Wang · 2012 [cited by applicant]
US 20130021933A1 · Kovvali et al. · 2013 [cited by applicant]
US 20130107715A1 · Szabo et al. · 2013 [cited by applicant]
US 20130242775A1 · Taylor · 2013 [cited by applicant]
US 20130304842A1 · Zachariassen et al. · 2013 [cited by applicant]
US 20140189097A1 · Sidi · 2014 [cited by applicant]
US 20140192668A1 · Yamany et al. · 2014 [cited by applicant]
US 20150089054A1 · Rizzi et al. · 2015 [cited by applicant]
US 20150128056A1 · Rizzi et al. · 2015 [cited by applicant]
US 20150138989A1 · Polehn · 2015 [cited by applicant]
US 20150149631A1 · Lissack · 2015 [cited by applicant]
US 20160155076A1 · Fix et al. · 2016 [cited by applicant]
US 20160162346A1 · Kushnir et al. · 2016 [cited by applicant]
US 20160360361A1 · Ross et al. · 2016 [cited by applicant]
US 20170046243A1 · Shinde · 2017 [cited by applicant]
US 20170111807A1 · Townend et al. · 2017 [cited by applicant]
US 20170126475A1 · Mahkonen et al. · 2017 [cited by applicant]
US 20170237851A1 · Hassan et al. · 2017 [cited by applicant]
US 20170250880A1 · Akens et al. · 2017 [cited by applicant]
US 20170279703A1 · Wasmundt et al. · 2017 [cited by applicant]
US 20170302505A1 · Zafer et al. · 2017 [cited by applicant]
US 20170302553A1 · Zafer et al. · 2017 [cited by applicant]
US 20170353991A1 · Tapia et al. · 2017 [cited by applicant]
US 20170359272A1 · Srinivasan et al. · 2017 [cited by applicant]
US 20180024867A1 · Gilsdorf et al. · 2018 [cited by applicant]
US 20180054772A1 · Tan et al. · 2018 [cited by applicant]
US 20180109564A1 · Rahman · 2018 [cited by applicant]
US 20180167446A1 · Lewis et al. · 2018 [cited by applicant]
US 20180176095A1 · Diwakar · 2018 [cited by applicant]
US 20180262414A1 · Burbridge · 2018 [cited by applicant]
US 20180270126A1 · Tapia · 2018 [cited by applicant]
US 20180343192A1 · Antonyraj et al. · 2018 [cited by applicant]
US 20190036772A1 · Agerstam et al. · 2019 [cited by applicant]
US 20190052518A1 · Gal et al. · 2019 [cited by applicant]
US 20190082286A1 · Tata et al. · 2019 [cited by applicant]
US 20190141113A1 · Ganapathi et al. · 2019 [cited by applicant]
US 20190141543A1 · Ganapathi et al. · 2019 [cited by applicant]
US 20190200243A1 · Anand et al. · 2019 [cited by applicant]
US 20190205153A1 · Niestemski et al. · 2019 [cited by applicant]
US 20190213514A1 · Gonzalez et al. · 2019 [cited by applicant]
US 20190280950A1 · Alshafei et al. · 2019 [cited by applicant]
US 20190289013A1 · Makmel et al. · 2019 [cited by applicant]
US 20190319868A1 · Svennering et al. · 2019 [cited by applicant]
US 20190356535A1 · Li et al. · 2019 [cited by applicant]
US 20190363960A1 · Fuchs et al. · 2019 [cited by applicant]
US 20200028782A1 · Li et al. · 2020 [cited by applicant]
US 20200029240A1 · Li et al. · 2020 [cited by applicant]
US 20200106602A1 · Santos et al. · 2020 [cited by applicant]
US 20200106610A1 · Doddavula · 2020 [cited by examiner]
US 20200125738A1 · Mahatwo · 2020 [cited by examiner]
US 20210342471A1 · Larsen · 2021 [cited by examiner]
US 20210344507A1 · Peng · 2021 [cited by examiner]
US 20220045849A1 · Jing · 2022 [cited by examiner]
EP 3211831 · 2017 [cited by applicant]
GB 2481422 · 2011 [cited by applicant]
TW 201812674A · 2017 [cited by applicant]
WO WO2017072614 · 2017 [cited by applicant]