NIST Issues Blockchain Guidance For Access Control Systems

FL
Foley & Lardner

Contributor

Foley & Lardner LLP looks beyond the law to focus on the constantly evolving demands facing our clients and their industries. With over 1,100 lawyers in 24 offices across the United States, Mexico, Europe and Asia, Foley approaches client service by first understanding our clients’ priorities, objectives and challenges. We work hard to understand our clients’ issues and forge long-term relationships with them to help achieve successful outcomes and solve their legal issues through practical business advice and cutting-edge legal insight. Our clients view us as trusted business advisors because we understand that great legal service is only valuable if it is relevant, practical and beneficial to their businesses.
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) issued Blockchain guidance for Access Control (AC) which "…is concerned with determining the allowed activities of...
United States Technology

The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) issued Blockchain guidance for Access Control (AC) which "...is concerned with determining the allowed activities of legitimate users and mediating every attempt by a user to access a resource in the system. The objectives of an AC system are often described in terms of protecting system resources against inappropriate or undesired user access." The May 19, 2022 publication entitled "Blockchain for Access Control Systems" included these comments about "the following infrastructural properties that are not included in traditional AC mechanisms unless specifically implemented":

  • Tamper-evident and tamper-resistant design prevents the alteration AC data (i.e., attributes, policy rules, environment conditions, and access requests) and AC logs (i.e., request permissions and previous AC data) and reduces the probability of frauds.
  • The control of authorization processing is decentralized, and the storage of AC data/logs has no single point of failure, thus providing more system tolerance and availability.
  • The traceability of blocks allows AC data/logs and system states to be seen and tracked.
  • The execution of arbitrary programs in smart contracts allows for controls on distributed AC data and authorization processes.
  • Consensus mechanisms and protocols jointly regulate the participating AC entities/organizations in determining policy rules through blocks or smart contracts.

Great news for AC!

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More