Data processing system for the privacy-compliant, zero-knowledge-based generation of manipulation-detectable risk evidence packages via the operation of AI systems for machine use by insurers
DE202026002764U1Undetermined Publication Date: 2026-09-03EXTRA GROUP GMBH
0 Cites 0 Cited by
Patent Information
- Application Number
- DE202026002764
- Authority / Receiving Office
- DE · DE
- Patent Type
- Utility models
- Current Assignee / Owner
- Filing Date
- 2026-06-15
- Publication Date
- 2026-09-03
- Estimated Expiration
- 2036-06-30
Abstract
A data processing system for the automated generation of privacy-preserving and tamper-detectable risk evidence packages concerning the operation of AI systems for machine use by an insurer, comprising: (a) an evidence linking layer (100) executed on at least one processor, which is connected via a read-only data interface to a hash-linked, append-only evidence ledger (90) in which evidence objects concerning the operation of at least one AI system are sequentially anchored with a cryptographic hash of the evidence object and a cryptographic hash of the immediately preceding ledger entry, wherein the evidence linking layer is configured to read evidence objects without modifying the ledger, and wherein the read raw evidence objects do not leave a trust boundary;(b) a risk metric calculation unit (150) that calculates a set of aggregated, insurance-relevant risk metrics over a reporting period from the read evidence objects and forms a cryptographic commitment on each calculated risk metric, binding the risk metric to the underlying evidence objects; (c) a threshold catalog module (200) that manages an insurer-configurable, cryptographically signed catalog of threshold conditions, each threshold condition defining a risk metric, a comparison operator, and a reference value; (d) a zero-knowledge attestation unit (250) that generates a cryptographic zero-knowledge document for at least one threshold condition of the catalog, proving that the specified risk metric meets the threshold condition without disclosing the numerical value of the risk metric and without disclosing the underlying evidence objects;(e) a risk evidence package generation unit (300) that combines the at least one zero-knowledge evidence, a reference value to the head hash of the evidence ledger at the time of calculation, and a description of the threshold catalog into a machine-readable, cryptographically sealed risk evidence package with a unique package identifier, timestamp, and package hash; (f) an insurer verification interface (350) that provides an insurer with read-only access through which the insurer cryptographically verifies the at least one zero-knowledge evidence against the signed threshold catalog and verifies the integrity of the referenced evidence ledger using the head hash reference value included in the package, without the insurer having access to the raw evidence objects or the numerical values of the risk indicators.
Need to check novelty before this filing date? Find Prior Art