Method and system for providing content control through a third-party data aggregation service

Through the dual encryption mechanism of data owner and data proxy, the problem of data owner losing control over data is solved, data security and traceability are achieved, and data leakage risks are reduced.

CN115699679BActive Publication Date: 2025-08-01INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180037334.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-06-03
Filing Date
2021-05-17
Publication Date
2025-08-01
Estimated Expiration
2041-05-17

AI Technical Summary

Technical Problem

After providing data to the data agent, the data owner loses control over the data and cannot track or restrict access to the data, resulting in an increased risk of data leakage.

Method used

By using the dual encryption mechanism of the data owner's key and the data proxy's key, the data owner and the data proxy jointly control the access rights of the data, ensuring that the data remains secure and traceable during transmission and use.

Benefits of technology

It realizes the retention of control over data by the data owner, reduces the risk of data leakage, and ensures data security and access traceability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115699679B_ABST
    Figure CN115699679B_ABST
Patent Text Reader

Abstract

Each aspect includes receiving a request for access to data from a user, where the data was obtained by a third party from a data owner and is in an encrypted format that is unreadable by the user. In response to receiving the request for access to data from the user, request a third-party key from the third party and request a data owner key from the data owner. Apply the third-party key and the data owner key to the encrypted format data to generate user-readable unencrypted format data. Provide the user with access to the unencrypted format data.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] The present invention generally relates to computer systems, and more particularly to providing content control through a third-party data aggregation service.

[0002] A common purpose of data aggregation is to obtain more information about a specific population based on specific variables such as age, occupation, or income. Data brokers or data aggregation services typically aggregate information from various sources; process the data to enrich, cleanse, or analyze it; and license the processed data to other organizations. Some data brokers collect personal information about consumers from various public and non-public sources and sell that information to other data brokers or data users. Data can be collected from sources such as public records, online activities, and purchase history and then sold to other companies for marketing purposes. Summary of the Invention

[0003] Embodiments of the present invention relate to providing content control through a third-party data aggregation service. Non-limiting example methods include receiving from a user a request to access data obtained by a third party from a data owner, the data being in an encrypted format that is unreadable by the user. In response to receiving the request from the user to access the data, request a third-party key from the third party and a data owner key from the data owner. Apply the third-party key and the data owner key to the encrypted format data to generate the data in an unencrypted format that is readable by the user. Provide the user with access to the unencrypted format data.

[0004] Other embodiments of the present invention implement the features of the above method in a computer system and a computer program product.

[0005] Additional technical features and advantages are realized through the techniques of the present invention. Embodiments and aspects of the present invention are described in detail herein, and these embodiments and aspects are considered to be part of the claimed subject matter. For a better understanding, reference is made to the detailed description and the drawings. Brief Description of the Drawings

[0006] The details of the exclusive rights described herein are particularly pointed out and distinctly claimed in the appended claims. The foregoing and other features and advantages of embodiments of the present invention will become apparent from the following detailed description taken in conjunction with the drawings, in which:

[0007] Figure 1 A block diagram of a system for providing content control through a third-party data aggregation service in accordance with one or more embodiments of the present invention is depicted;

[0008] Figure 2 A flowchart of generating content that can be controlled by a third-party data aggregation service in accordance with one or more embodiments of the present invention is depicted;

[0009] Figure 3 Depicts a flowchart for providing content control via a third - party data aggregation service according to one or more embodiments of the present invention;

[0010] Figure 4 Depicts a cloud computing environment according to one or more embodiments of the present invention;

[0011] Figure 5 Depicts an abstract model layer according to one or more embodiments of the present invention; and

[0012] Figure 6 Illustrates a system for providing self - reporting and self - upgrading of enterprise systems according to one or more embodiments of the present invention.

[0013] The figures depicted herein are illustrative. Many variations to the drawings or the operations described therein may exist without departing from the spirit of the present invention. For example, actions may be performed in a different order, or actions may be added, deleted, or modified. Also, the term "coupled" and its variants describe having a communication path between two elements and do not imply a direct connection between the elements without intervening elements / connections therebetween. All such variations are considered to be part of the specification. Detailed Description

[0014] One or more embodiments of the present invention provide content control via a third - party data aggregation service. According to one or more embodiments of the present invention, a system using security devices and protocols is used to provide secure third - party data aggregation to allow control of the data to be maintained by both the data owner and the data agent.

[0015] Data agents often purchase data from multiple data owners and then create data sets across the data they purchase. These data sets are then resold to data users who can use the data for different reasons, such as market research. Currently, when a data owner provides data to a third party, such as a data agent, the data agent makes a copy of the data, and the data owner completely relinquishes control over what the data agent does with the data next (e.g., who accesses the data). In the case where the data agent is compromised, all data from all parties that provided data to the data agent is vulnerable to a data breach. A data breach refers to the unauthorized copying, transfer, or retrieval of data. When the data agent sells the data to additional parties, such as other data agents or data users, the inability of the data owner to control or track access to their data increases in scope.

[0016] One or more embodiments of the present invention address one or more of the above disadvantages by allowing data owners to retain in the data the rights they provide to third parties such as data brokers, including the right to control access to their data, using a network of security devices that are either distributed on-site and accessible to each party to the data or deployed in the cloud for access by some of the parties wishing to participate in the data network.

[0017] In accordance with one or more embodiments of the present invention, a data broker does not have access to the data content it purchases from a data owner. Instead, the data broker has metadata describing the data and uses the data owner's key to protect the content of the data. For example, the data broker can know based on the metadata that the content of the data it receives from the data owner includes credit card transactions, and each credit card transaction includes an encrypted customer name, merchant name, transaction amount, and encrypted customer account number. The only way to access the encrypted customer name and encrypted customer account number is to use the data owner's key, and the distribution of the data owner's key is controlled by the data owner via, for example, the data owner's security device. In accordance with one or more embodiments of the present invention, the data owner can have different keys for giving different access levels to different requesters of the data.

[0018] In accordance with one or more embodiments of the present invention, the data broker provides another layer of security and traceability to the data it purchases from the data owner by applying another encryption key (the data broker key) to the encrypted data it receives from the data owner. Once the data broker key is applied, the only way to access the encrypted customer name and encrypted customer account number is to use both the data owner's key and the data broker's key, and the distribution of the data broker's key is controlled by the data broker via, for example, the data broker's security device. In these one or more embodiments, both the data owner and the data broker must approve access to the data before the data is provided to the data user. Thus, if the data user or the data broker suffers a data breach, the data is still protected because two keys are required to decrypt the data for use by the data user.

[0019] In accordance with one or more embodiments of the present invention, the data owner can also push policy-based controls for data views, which can be used to control the views visible to third parties. For example, a third party may be able to view the entire credit card number or only the first four digits.

[0020] According to one or more embodiments of the present invention, a data broker and / or a data owner may dynamically restrict access to data in response to, for example, restricting future access to the data. For example, in the case where the data broker violates the service terms of the data owner regarding the data, the data owner may dynamically restrict future access by the data user. The data broker may also restrict future access by the data user to the data if, for example, the time period for use of the data has expired.

[0021] According to one or more embodiments of the present invention, a data owner and / or a data broker may have an access log to track who accesses the data. This information may be used, for example, by the data owner to have visibility into how their data is distributed to third parties (e.g., data brokers) and data users.

[0022] Now turning to Figure 1 , according to one or more embodiments of the present invention, a block diagram generally illustrating a system for providing content control through a third-party data aggregation service is shown. Figure 1 The block diagram 100 shown in includes a data owner 122 and its corresponding security device 102 and data source 108, a data broker 124 and its corresponding security device 104 and purchased data source 110, a data user 126 and its corresponding security device 106, a purchased data source 112, and supplied data 114.

[0023] Each of the security devices 102, 104, 106 contains key material for encrypting data elements or data. They may also each communicate with the other security devices and provide them with the key material to be used to decrypt the data elements. As Figure 1 shown, the security device 106 communicates with the security device 102 and the security device 104 to perform key requests 118, 120. According to one or more embodiments of the present invention, the security devices 102, 104, 106 are implemented by any method known in the art, such as but not limited to servers and / or containers, which do not support user login or access to the software or memory of the running system. According to one or more embodiments of the present invention, the security devices 102, 104, 106 are accessed or communicate via an application programming interface (API).

[0024] As Figure 1 shown, the data owner 122 has as Figure 1The data that the data owner 122 shown wishes to monetize serves as data source 108. These data sources 108 can include, but are not limited to, data from the Internet of Things (IoT), user data, and / or relational data sources. When the data owner 122 has identified the data that it wants to provide to the data broker 124, the data security device 102 of the data owner 122 wraps data elements that are part of the data or data set with metadata that describes the data. Then, the data is encrypted with a key owned by the data owner 122 and sent to the data broker 124 along with the metadata, and the data broker 124 stores the encrypted data and metadata (e.g., in a database or other storage configuration) as the purchased data source 110.

[0025] According to one or more embodiments of the present invention, the data broker 124 does not have access to the data owner key and thus cannot open or read the data provided by the data owner. According to one or more embodiments of the present invention, the data broker 124 does not know the content or actual data values of the data received from the data owner 122. Based on the metadata provided by the data owner, the data broker 124 does know the type of data content, and the data broker can use the metadata to place the data in a directory, which can then be resold. As Figure 1 shown, the data broker 124 purchases data sets from one or more data owners 122, shown in Figure 1 as the purchased data source 110. These purchased data sources can contain a combination of plaintext (unencrypted) data and anonymized or non-anonymized personally identifiable information (PII). As is known in the art, PII refers to any data that can potentially be used to identify a specific person, such as but not limited to full name, social security number, driver's license number, bank account number, passport number, and / or email address.

[0026] When the data broker 124 sells data, the data broker 124 repeats the same process as done with the data owner, wrapping and encrypting the data elements, but with a key owned by the data broker 124. As Figure 1 shown, the security device 104 performs the wrapping and encryption of the (already encrypted) data received from the data owner 122. When the data is received by the data user 126, it is encrypted with the owner key and then encrypted again with the data broker key. The data user 126 stores the data as the purchased data source 112 in a storage location.

[0027] According to one or more embodiments of the present invention, when the user 116 wants to use data from the purchased data source 112, a request for data access is made through the security device 106. In response to receiving the request, the security device 106 requests keys from both the security device 102 and the security device 104. This is in Figure 1shown as key request 120 for requesting a data proxy key from security device 104 and key request 118 for requesting a data owner key from security device 102. According to one or more embodiments of the present invention, from the perspective of user 116, this is a single atomic operation, wherein the data requested by user 116 is decrypted using the data proxy key and then using the data owner key. The resulting clear data or clear data element is stored as provisioned data 114. User 116 can use the provisioned data 114 for market research and drive additional revenue in their commercial offerings.

[0028] According to one or more embodiments of the present invention, the policy from data owner 122 can affect whether clear data can be provided to user 116, or whether data leaving security device 106 should be masked, redacted, or some other obfuscation technique applied to it.

[0029] According to one or more embodiments of the present invention, in the case where either party, data owner 122 or data proxy 124, no longer wants to allow user 116 access to their data, they can remove access to their respective keys for that user 116. This removal can be applied to a specific user 116 or all users of data user 126 (e.g., in the case where data user 126 includes multiple individual users 116 requesting data access). Additionally, this removal can be applied to a specific time frame during which access was allowed at other times. Alternatively, data owner 122 or data proxy 124 can delete their respective keys, which will permanently invalidate the data in the purchased data source 112.

[0030] Both data owner 122 and data proxy 124 can have complex schemes to allow granular access to their data. For example, data owner 122 can use different keys for different data proxies 124 such that they can invalidate only the data of a single data proxy. Data proxy 124 can also use different keys for different data users 126 such that they can invalidate only a single data set.

[0031] Any kind of encryption algorithm involving one or more keys can be used to encrypt data. Examples include but are not limited to Advanced Encryption Scheme (AES), Data Encryption Standard (DES), and / or variants of Rivest, Shamir, and Adleman (RSA) encryption.

[0032] In Figure 1Only one third party (data broker 124) is shown between data owner 122 and data user 126 in the figure. However, embodiments of the present invention are not limited to data processed by a single third party before being used by data user 126. According to one or more embodiments of the present invention, there are two or more data brokers 124, each data broker having sequentially applied its own data broker key to the data, and each data broker having its own security device 104. In this case, data user 126 will initiate two or more key requests 120 to obtain two or more data broker keys from security devices 104 associated with each of data brokers 124, along with key request 118 for requesting the data owner key from security device 102.

[0033] Figure 1 Any components shown in the figure may be coupled to each other via a network. For example, security device 102 may be coupled to security device 106 and / or purchased data source 110 via a network. The (one or more) network(s) may be implemented by any (one or more) network known in the art, such as but not limited to a local area network (LAN), a direct cable connection, a cloud computing environment (such as the cloud computing environment shown below Figure 4 in the figure) and / or the Internet.

[0034] In various embodiments, the embodiments described herein with respect to Figure 1 block diagram 100 may be implemented using any suitable logic, where the logic as mentioned herein may include any suitable hardware (e.g., a processor, an embedded controller, or an application specific integrated circuit, etc.), software (e.g., an application, etc.), firmware, or any suitable combination of hardware, software, and firmware. Additionally, the various blocks in Figure 1 may be configured in a manner different from that shown Figure 1 in the figure.

[0035] Now turning to Figure 2 , a flowchart of a method 200 for generating content that can be controlled by a third - party data aggregation service is generally shown according to one or more embodiments of the present invention. Figure 2 All or part of the processing shown in blocks 202 to 208 of Figure 6 may be performed, for example, by a processor 605 executing on a computer 601 located at Figure 4 or by a processor on a cloud computing node 10 located at Figure 1 security device 102. Figure 2 The process shown in the figure starts at block 202, where a data owner (such as Figure 1 data owner 122) identifies data (such as data source 108) to be provided to a third party. The third party may be, but is not limited to, a data broker, such asFigure 1 Data broker 124. At block 204, the identified data is wrapped with metadata to describe the content of the data, and at block 206, the data is encrypted with the data owner key. At block 208, the metadata and the data encrypted with the data owner key are sent to a third party. At Figure 2 the example shown, the third party is a data broker. According to one or more embodiments of the present invention, the third party can be any entity that collects and distributes data.

[0036] Processing continues at Figure 2 block 210. Figure 2 All or part of the processing shown in blocks 210 to 214 of Figure 6 can be performed, for example, by a processor 605 on a computer 601 located at Figure 4 or by a processor on a cloud computing node 10 located at Figure 1 a security device 104. At block 210, the metadata and the data encrypted with the data owner key are received by the data broker. The received data can be stored in a storage location (such as Figure 1 a purchased data source 110). At block 212, the received data encrypted with the data owner key is further encrypted with the data broker key. At block 214, the data encrypted with both the data owner key and the data broker key is sent to a data user, such as Figure 1 data user 126. According to one or more embodiments of the present invention, the metadata is also sent to the data user. The data encrypted with both the data owner key and the data broker key can be stored by the data user in a storage location (such as Figure 1 a purchased data source 112). According to one or more embodiments of the present invention, the metadata is also sent to the data user and can be stored in a storage location.

[0037] Figure 2 The process flow diagram of

[0038] is not intended to indicate that the operations of method 200 are to be performed in any particular order, or that all operations of method 200 are to be included in every case. Additionally, method 200 can include any suitable number of additional operations.

[0038] Now turning to Figure 3 , according to one or more embodiments of the present invention, a flowchart generally showing a method 300 for providing content control through a third-party data aggregation service is shown. Figure 3 All or part of the processing shown in Figure 1 can be performed, for example, by a security device 106 located at Figure 6 a computer 601 on a processor 605, or by a processor on a cloud computing node 10 located at Figure 4 .Figure 3 The processing in Figure 1 starts at block 302 and receives from a user (such as Figure 1 user 116) a request to access data received from a third party (such as Figure 1 data broker 124). The data that the user is requesting access to is encrypted by both a data broker key and a data owner key and is readable by the user in its currently encrypted format. According to one or more embodiments of the present invention, the request is received by a security device of the data user (such as

[0039] In Figure 3 block 304, the security device of the data user requests the data broker key from the data broker. According to one or more embodiments of the present invention, a request for the data broker key is made to a security device of the data broker (such as Figure 1 security device 104). In response to receiving the request, if the security device of the data broker determines that the user is a valid or authorized user who should access the data, the security device of the data broker returns the data broker key to the user. Additionally, the security device of the data broker may log the access request. As previously mentioned, the security device of the data broker may determine that the data broker authorizes a user to have access to the data at one point in time and determine that the data broker does not authorize access by the user at another point in time. Additionally, the scope of access (e.g., full access, edit access, etc.) may be modified by the data broker and may be different at different points in time. In this way, even after the data has been sent to the data user, the data broker can control who has access to the data.

[0040] At block 306, the security device of the data user requests the data owner key from the data owner. According to one or more embodiments of the present invention, a request for the data owner key is made to a security device of the data owner (such as Figure 1 security device 102). In response to receiving the request, if the security device of the data owner determines that the user is a valid or authorized user who should have access to the data, the security device of the data owner returns the data owner key to the user. Additionally, the security device of the data owner may log the access request. As previously mentioned, the security device of the data owner may determine that the data owner authorizes a user to have access to the data at one point in time and determine that the data owner does not authorize access by the user at another point in time. Additionally, the scope of access (e.g., full access, edit access, etc.) may be modified by the data owner and may be different at different points in time. In this way, even after the data has been sent by the data broker to the data user, the data owner can control who has access to the data.

[0041] In Figure 3For the frame 308, determine whether both the data proxy key and the data owner key are received in response to the requests at frames 304 and 306. If it is determined at frame 308 that both the data proxy key and the data owner key have been received, the process continues at frame 310. At frame 310, apply the data proxy key to the encrypted data to generate data encrypted by the data owner key. Then, apply the data owner key to the data encrypted by the data owner key to generate data in an unencrypted format readable by the user. This data can be stored as the supplied data, such as Figure 1 the supplied data 114. At Figure 3 frame 312, provide the requesting user with access to the unencrypted or supplied data. As mentioned above, the unencrypted data can include portions of the data obfuscated from the user or a subset of the data through techniques such as editing and / or data masking.

[0042] If it is determined at frame 308 that one or both of the data proxy key and the data owner key have not been received, the process continues at frame 314. At frame 314, the user can be prevented from accessing the data they requested access to because the key for decrypting the data is not available to the user. Although not shown in Figure 3 the embodiment of, the method 300 can include looping back from frame 314 to frame 308 (e.g., after a set period of time or in response to a detected event) to determine whether the key has been received.

[0043] In one or more embodiments of the present invention, the security device of the data proxy and the data owner always provide a response to a request from the security device of the data user. The response can include a key or an indication that the user requester has been denied access to the data.

[0044] Figure 3 The process flow diagram of does not intend to indicate that the operations of the method 300 are to be performed in any particular order, or that all operations of the method 300 are to be included in each case. Additionally, the method 300 can include any suitable number of additional operations.

[0045] It should be understood that although this disclosure includes a detailed description of cloud computing, the implementation of the teachings recited herein is not limited to a cloud computing environment. Instead, embodiments of the present invention are capable of being implemented in conjunction with any other type of computing environment now known or later developed.

[0046] Cloud computing is a model for service delivery that enables convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with the provider of the service. The cloud model can include at least five characteristics, at least three service models, and at least four deployment models.

[0047] The characteristics are as follows:

[0048] On-demand self-service: Cloud consumers can unilaterally and automatically provision computing capabilities, such as server time and network storage, as needed without human interaction with the service provider.

[0049] Broad network access: Capabilities are available over the network and accessed through standard mechanisms that promote the use of heterogeneous thin client platforms or thick client platforms (e.g., mobile phones, laptops, and PDAs).

[0050] Resource pooling: The provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, where different physical and virtual resources are dynamically assigned and reassigned as needed. There is a sense of location independence, as consumers generally have no control or knowledge of the exact location of the provided resources but may be able to specify location at a higher level of abstraction (e.g., country, state, or data center).

[0051] Rapid elasticity: Capabilities can be provided rapidly and elastically, automatically scaling out quickly and scaling in and releasing quickly in some cases. To the consumer, the capabilities available for provisioning generally appear to be unlimited and can be purchased in any quantity at any time.

[0052] Measured service: The cloud system automatically controls and optimizes resource use by leveraging metering capabilities at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource use can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized service.

[0053] The service models are as follows:

[0054] Software as a Service (SaaS): The capabilities provided to the consumer are to use the provider's applications running on the cloud infrastructure. The applications can be accessed from different client devices through a thin client interface such as a web browser (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even the individual application capabilities, with the possible exception of limited user-specific application configuration settings.

[0055] Platform as a Service (PaaS): The ability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage, but has control over the deployed applications and possibly the application hosting environment configuration.

[0056] Infrastructure as a Service (IaaS): The ability provided to the consumer is to provide processing, storage, networks, and other fundamental computing resources where the consumer is able to deploy and run arbitrary software, which can include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, deployed applications, and possibly limited control of selected networking components (e.g., host firewalls).

[0057] The deployment models are as follows:

[0058] Private cloud: The cloud infrastructure is operated solely for an organization. It can be managed by the organization or a third party and can exist on-premises or off-premises.

[0059] Community cloud: The cloud infrastructure is shared by several organizations and supports a specific community that shares concerns (e.g., mission, security requirements, policies, and compliance considerations). It can be managed by the organizations or a third party and can exist on-premises or off-premises.

[0060] Public cloud: The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization selling cloud services.

[0061] Hybrid cloud: The cloud infrastructure is a composition of two or more clouds (private, community, or public) that remain unique entities but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load balancing between clouds).

[0062] The cloud computing environment is service-oriented, focusing on statelessness, low coupling, modularity, and semantic interoperability. The core of cloud computing is an infrastructure that includes a network of interconnected nodes.

[0063] Now refer to Figure 4, an illustrative cloud computing environment 50 is described. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 with which local computing devices used by cloud consumers can communicate, such as, for example, a personal digital assistant (PDA) or cellular phone 54A, a desktop computer 54B, a laptop computer 54C, and / or an in-vehicle computer system 54N. The nodes 10 can communicate with each other. They can be physically or virtually grouped (not shown) in one or more networks, such as a private cloud, community cloud, public cloud, or hybrid cloud, or a combination thereof, as described above. This allows the cloud computing environment 50 to provide infrastructure, platform, and / or software as a service for which the cloud consumer does not need to maintain resources on a local computing device. It should be understood that Figure 4 the types of computing devices 54A - 54N shown in

[0064] are only illustrative, and the computing nodes 10 and the cloud computing environment 50 can communicate with any type of computerized device via any type of network and / or network addressable connection (e.g., using a web browser). Figure 5 Now referring to Figure 4 , a set of functional abstraction layers provided by the cloud computing environment 50 ( Figure 5 ) is shown. It should be understood in advance that

[0065] the components, layers, and functions shown in

[0066] are only illustrative, and embodiments of the present invention are not limited thereto. As described, the following layers and corresponding functions are provided:

[0067] The hardware and software layer 60 includes hardware and software components. Examples of hardware components include: mainframes 61; servers 62 based on RISC (Reduced Instruction Set Computer) architecture; servers 63; blade servers 64; storage devices 65; and network and networking components 66. In some embodiments, the software components include web application server software 67 and database software 68. The virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual servers 71; virtual memories 72; virtual networks 73, including virtual private networks; virtual applications and operating systems 74; and virtual clients 75.In one example, the management layer 80 can provide the functions described below. Resource provisioning 81 provides for the dynamic purchase of computing resources and other resources for performing tasks within a cloud computing environment. Metering and pricing 82 provides cost tracking when resources are utilized within the cloud computing environment and bills or invoices for the consumption of these resources. In one example, these resources can include application software licenses. Security provides authentication for cloud consumers and tasks, as well as protection for data and other resources. The user portal 83 provides access to the cloud computing environment for consumers and system administrators. Service level management 84 provides cloud computing resource allocation and management such that the required service levels are met. Service level agreement (SLA) planning and fulfillment 85 provides for the pre-arrangement and purchase of cloud computing resources in anticipation of future demands based on the SLA.

[0068] The workload layer 90 provides examples of functions that can utilize the cloud computing environment. Examples of workloads and functions that can be provided from this layer include: maps and navigation 91; software development and lifecycle management 92; virtual classroom education delivery 93; data analysis processing 94; transaction processing 95; and breakpoint generation 96.

[0069] It should be understood that one or more embodiments of the present invention can be implemented in conjunction with any type of computing environment now known or later developed.

[0070] Now turning Figure 6 , in accordance with one or more embodiments of the present invention, a computer system 600 for providing content control through a third-party data aggregation service is generally shown. The methods described herein can be implemented in hardware, software (e.g., firmware), or a combination thereof. In one or more exemplary embodiments of the present invention, the methods described herein are implemented in hardware as part of a microprocessor of a dedicated or general-purpose digital computer (e.g., a personal computer, workstation, minicomputer, or mainframe). Thus, the system 600 can include a general-purpose computer or mainframe 601 capable of running multiple instances of the O / S simultaneously.

[0071] In one or more exemplary embodiments of the present invention, in terms of the hardware architecture, as Figure 6As shown, computer 601 includes one or more processors 605, a memory 610 coupled to a memory controller 615, and one or more input and / or output (I / O) devices 640, 645 (or peripheral devices) communicatively coupled via a local input / output controller 635. The input / output controller 635 can be, for example but not limited to, one or more buses or other wired or wireless connections known in the art. The input / output controller 635 can have additional elements, such as controllers, buffers (caches), drivers, repeaters, and receivers, which are omitted for simplicity, to enable communication. Further, the local interface can include address, control, and / or data connections to enable proper communication among the above components. The input / output controller 635 can include a plurality of sub-channels configured to access the output devices 640 and 645. The sub-channels can include fiber optic communication ports.

[0072] The processor 605 is a hardware device for executing software (specifically, software stored in a memory 620, such as a cache memory or the memory 610). The processor 605 can be any custom or commercially available processor, a central processing unit (CPU), an auxiliary processor among several processors associated with the computer 601, a semiconductor-based microprocessor (in the form of a microchip or chipset), a macroprocessor, or any device generally used for executing instructions.

[0073] The memory 610 can include any one or a combination of volatile memory elements (e.g., random access memory (RAM), such as DRAM, SRAM, SDRAM, etc.) and non-volatile memory elements (e.g., ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic tape, compact disc read-only memory (CD-ROM), disk, magnetic disk, cassette tape, cartridge tape, etc.). In addition, the memory 610 can incorporate electronic, magnetic, optical, and / or other types of storage media. Note that the memory 610 can have a distributed architecture where different components are located far from each other but can be accessed by the processor 605.

[0074] The instructions in the memory 610 can include one or more individual programs, each program including an ordered list of executable instructions for implementing a logical function. In Figure 6 the example, the instructions in the memory 610 are a suitable operating system (OS) 611. The operating system 611 substantially controls the execution of other computer programs and provides scheduling, input-output control, file and data management, memory management, and communication control and related services.

[0075] According to one or more embodiments of the present invention, the memory 610 may include a plurality of logical partitions (LPARs), each running an instance of an operating system. The LPARs may be managed by a hypervisor, which may be a program stored in the memory 610 and executed by the processor 605.

[0076] In one or more exemplary embodiments of the present invention, a conventional keyboard 650 and a mouse 655 may be coupled to the input / output controller 635. Other output devices such as I / O devices 640, 645 may include input devices, such as but not limited to, printers, scanners, microphones, etc. Finally, the I / O devices 640, 645 may further include devices that transfer both input and output, such as but not limited to, a network interface card (NIC) or a modem / demodulator (for accessing other files, devices, systems, or networks), a radio frequency (RF) or other transceiver, a telephone interface, a bridge, a router, etc. The system 600 may also include a display controller 625 coupled to the display 630.

[0077] In one or more exemplary embodiments of the present invention, the system 600 may further include a network interface 660 for coupling to a network 665. The network 665 may be an IP-based network for communication between the computer 601 and any external servers, clients, etc. via a broadband connection. The network 665 sends and receives data between the computer 601 and an external system. In an exemplary embodiment, the network 665 may be a managed IP network managed by a service provider. The network 665 may be implemented wirelessly, such as using wireless protocols and technologies, such as WiFi, WiMax, etc. The network 665 may also be a packet-switched network, such as a local area network, a wide area network, a metropolitan area network, an Internet network, or other similar types of network environments. The network 665 may be a fixed wireless network, a wireless local area network (LAN), a wireless wide area network (WAN), a personal area network (PAN), a virtual private network (VPN), an intranet, or other suitable network systems, and includes devices for receiving and transmitting signals.

[0078] If the computer 601 is a PC, a workstation, a smart device, etc., the instructions in the memory 610 may further include a basic input / output system (BIOS) (omitted for simplicity). The BIOS is a collection of basic software routines that initialize and test the hardware at startup, start the OS 611, and support data transfer between hardware devices. The BIOS is stored in the ROM so that the BIOS can be executed when the computer 601 is activated.

[0079] When computer 601 is running, the processor 605 is configured to execute instructions stored in the memory 610, transfer data to and from the memory 610, and generally control the operation of the computer 601 according to the instructions. According to one or more embodiments of the present invention, the computer 601 is Figure 4 an example of the cloud computing node 10 of

[0080] Various embodiments of the present invention are described herein with reference to the related drawings. Alternative embodiments of the present invention may be designed without departing from the scope of the present invention. In the following description and drawings, various connection and positional relationships (e.g., above, below, adjacent, etc.) are set forth between elements. Unless otherwise specified, these connections and / or positional relationships may be direct or indirect, and the present invention is not restrictive in this regard and the schematic diagrams are not restrictive. Thus, the connection of entities may refer to a direct or indirect connection, and the positional relationship between entities may be a direct or indirect positional relationship. In addition, the various tasks and process steps described herein may be incorporated into a more comprehensive program or process having additional steps or functions not detailed herein.

[0081] One or more methods described herein may be implemented using any of the following techniques or combinations of the following techniques, each of which is well known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application specific integrated circuits (ASICs) having appropriate combinations of logic gates, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0082] For the sake of brevity, conventional techniques related to aspects of manufacturing and using the present invention may or may not be described in detail herein. Specifically, aspects of the computing systems and specific computer programs for implementing the different technical features described herein are well known. Thus, for the sake of brevity, many conventional implementation details are only briefly mentioned or completely omitted herein without providing well-known system and / or process details.

[0083] In some embodiments, the various functions or actions may occur at a given location and / or in conjunction with the operation of one or more devices or systems. In some embodiments, a portion of a given function or action may be performed at a first device or location, and the remainder of the function or action may be performed at one or more additional devices or locations.

[0084] The terms used in this specification are for the purpose of describing particular embodiments only and are not intended to be limiting. As used herein, unless the context clearly dictates otherwise, the singular forms "a", "an" and "the" are intended to include the plural forms as well. It should also be understood that when the terms "comprises" and / or "comprising" are used in this specification, they specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or combinations thereof.

[0085] All apparatus or steps in the appended claims, plus the corresponding structures, materials, acts, and equivalents of the functional elements, are intended to include any structure, material, or act for performing the recited function in combination with other claimed elements as specifically claimed. This disclosure has been presented for purposes of illustration and description, but is not intended to be exhaustive or limited to the forms disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the disclosure. The embodiments were chosen and described in order to best explain the principles of the disclosure and its practical application, and to enable others of ordinary skill in the art to understand the disclosure for various embodiments with different modifications as are suited to the particular use contemplated.

[0086] The figures depicted herein are illustrative. Many variations to the illustrations or steps (or operations) described herein may be made without departing from the spirit of the disclosure. For example, the acts may be performed in a different order, or acts may be added, deleted, or modified. Also, the term "coupled" describes having a signal path between two elements and does not imply a direct connection between the elements with no intervening elements / connections therebetween, and all such variations are considered to be part of the disclosure.

[0087] The following definitions and abbreviations will be used to explain the claims and the specification. As used herein, the terms "comprise", "comprising", "include", "including", "has", "having", "contain" or "containing" or any other variation thereof are intended to cover a non-exclusive inclusion. For example, a composition, mixture, process, method, article, or apparatus that comprises a list of elements is not necessarily limited to only those elements, but may include other elements not expressly listed or inherent to such composition, mixture, process, method, article, or apparatus.

[0088] In addition, the term "exemplary" is used herein to mean "serving as an example, instance, or illustration". Any embodiment or design described herein as "exemplary" is not necessarily to be construed as preferred or superior to other embodiments or designs. The terms "at least one" and "one or more" should be understood to include any integer greater than or equal to one, i.e., one, two, three, four, etc. The term "plurality" should be understood to include any integer greater than or equal to two, i.e., two, three, four, five, etc. The term "connected" may include indirect "connection" and direct "connection".

[0089] The terms "about", "substantially", "approximately" and variations thereof are intended to include the degree of error associated with a particular quantity measurement based on the equipment available at the time of filing the application. For example, "about" may include a range of ±8% or 5%, or 2% of a given value.

[0090] The present invention may be a system, method, and / or computer program product of any possible level of integration of technical details. The computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions thereon for causing a processor to execute aspects of the present invention.

[0091] A computer-readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. A computer-readable storage medium may be, for example but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanical encoding device such as a punched card or a raised structure in a groove having instructions recorded thereon, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium should not be construed as a transitory signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through an optical fiber cable) or an electrical signal transmitted through a wire.

[0092] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network), or to an external computer or an external storage device. The network may include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the corresponding computing / processing device.

[0093] The computer-readable program instructions for carrying out operations of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages (such as Smalltalk, C++, etc.) and procedural programming languages (such as the "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter case, the remote computer may be connected to the user's computer through any type of network (including a local area network (LAN) or a wide area network (WAN)), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, an electronic circuit, including, for example, a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA), can execute the computer-readable program instructions by utilizing state information of the computer-readable program instructions to personalize the electronic circuit, so as to carry out aspects of the present invention.

[0094] The present invention will be described below with reference to the flowchart and / or block diagram of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each block of the flowchart and / or block diagram, and the combinations of blocks in the flowchart and / or block diagram, can be implemented by computer-readable program instructions.

[0095] These computer-readable program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions executed via the processor of the computer or other programmable data processing apparatus create means for implementing the functions / acts specified in one or more boxes of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, so that the computer-readable storage medium storing the instructions comprises an article of manufacture including instructions that implement aspects of the functions / acts specified in one or more boxes of the flowchart and / or block diagram.

[0096] The computer-readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device, such that a series of operational steps are performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, so that the instructions executed on the computer, other programmable apparatus, or other device implement the functions / acts specified in one or more boxes of the flowchart and / or block diagram.

[0097] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions, which comprises one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It should also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by special purpose hardware-based systems that perform the specified functions or acts or combinations of special purpose hardware and computer instructions.

[0098] The description of the various embodiments of the present invention has been presented for purposes of illustration, but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terms used herein have been chosen to best explain the principles of the embodiments, the practical application, or technical improvements over technologies found in the marketplace, or to enable those of ordinary skill in the art to understand the embodiments described herein.

Claims

1. A computer-implemented method, comprising: Receiving from a user a request to access data, the data being obtained by a third party from a data owner and being in an encrypted format unreadable by the user; In response to receiving the request from the user to access the data: Requesting a third-party key from the third party, the requesting of the third-party key from the third party including communicating with a security device of the third party to request the third-party key, wherein the security device of the third party returns the third-party key in response to determining that the third party authorizes the user to access the data; and Requesting a data owner key from the data owner by a security device of the user, the requesting of the data owner key from the data owner including communicating with a security device of the data owner to request the data owner key, wherein the security device of the data owner returns the data owner key in response to determining that the data owner authorizes the user to access the data; and In response to receiving the third-party key and the data owner key: Applying the third-party key and the data owner key to the encrypted-format data to generate user-readable unencrypted-format data; and Providing the user with access to the unencrypted-format data.

2. The method according to claim 1, wherein The third party is a data broker.

3. The method according to claim 1, wherein, The encrypted-format data is generated by encrypting the data using the data owner key and encrypting the data encrypted using the data owner key using the third-party key.

4. The method according to claim 1, further comprising logging the request from the user to access the data in response to receiving the request from the user to access the data.

5. The method according to claim 1 further comprises: Logging providing the user with access to the unencrypted-format data in response to providing the user with access to the unencrypted-format data.

6. The method according to claim 1, wherein The unencrypted-format data includes at least a subset of the data that is masked or redacted.

7. A computer system, comprising: One or more processors for executing computer-readable instructions that control the one or more processors to perform operations, the operations including: Receiving from a user a request to access data, the data being obtained by a third party from a data owner and being in an encrypted format unreadable by the user; In response to receiving the request from the user to access the data: Requesting a third-party key from the third party, the requesting of the third-party key from the third party including communicating with a security device of the third party to request the third-party key, wherein the security device of the third party returns the third-party key in response to determining that the third party authorizes the user to access the data; and Requesting a data owner key from the data owner by a security device of the user, the requesting of the data owner key from the data owner including communicating with a security device of the data owner to request the data owner key, wherein the security device of the data owner returns the data owner key in response to determining that the data owner authorizes the user to access the data; and In response to receiving the third-party key and the data owner key: Apply the third - party key and the data - owner key to the encrypted - format data to generate user - readable unencrypted - format data; and Provide the user with access to the unencrypted - format data.

8. The system according to claim 7, wherein, The third - party is a data broker.

9. The system according to claim 7, wherein, The encrypted - format data is generated by encrypting the data using the data - owner key and encrypting the data encrypted using the data - owner key using the third - party key.

10. The system according to claim 7, wherein, The operation further includes: logging the request from the user to access the data in response to receiving the request from the user to access the data.

11. The system according to claim 7, wherein, The operation further includes: logging providing the user with access to the unencrypted - format data in response to providing the user with access to the unencrypted - format data.

12. The system according to claim 7, wherein The unencrypted - format data includes at least a subset of the data that is masked or redacted.

13. A computer program product comprising program instructions executable by one or more processors to cause the one or more processors to perform operations, the operations including: Receive a request from a user to access data, the data being in an encrypted format that is unreadable by the user and obtained by a third - party from a data owner; In response to receiving the request from the user to access the data: Request a third - party key from the third - party, requesting a third - party key from the third - party includes communicating with a security device of the third - party to request the third - party key, wherein the security device of the third - party returns the third - party key in response to determining that the third - party authorizes the user to access the data; and Request a data - owner key from the data - owner by a security device of the user, requesting a data - owner key from the data - owner includes: communicating with a security device of the data - owner to request the data - owner key, wherein the security device of the data - owner returns the data - owner key in response to determining that the data - owner authorizes the user to access the data; and In response to receiving the third - party key and the data - owner key: Apply the third - party key and the data - owner key to the encrypted - format data to generate user - readable unencrypted - format data; and Provide the user with access to the unencrypted - format data.

14. The computer program product according to claim 13, wherein, The encrypted - format data is generated by encrypting the data using the data - owner key and encrypting the data encrypted using the data - owner key using the third - party key.

Citation Information

Patent Citations

  • Fine-grained access control method for data in cloud storage

    CN103179114A

  • Method for safely sharing mobile cloud storage light-level data

    CN103763319A