Attribute-Based Data Segmentation for Privacy Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In participatory sensing frameworks, there is a concern about privacy leakage and data security due to the involvement of third-party vendors and limited scope of custom-developed applications that do not provide adequate data security and privacy measures, discouraging participants from actively sharing confidential data.
Innovation Solution
A device and system that employs attribute-based access control using a processor and memory with modules for segmenting, defining access policies, encrypting data segments, and uploading them securely, utilizing attribute-based encryption schemes and public key infrastructure to ensure authorized access and protect privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is shared with third-party vendors in participatory sensing frameworks, then data analysis capability is improved, but privacy leakage risk increases
Solution Approach 1:
The patent segments data into multiple data segments before sharing with third-party vendors. Each segment can be independently accessed and analyzed, but none alone reveals complete private information. This segmentation approach enables data analysis capability while reducing privacy leakage risk by ensuring that even if one segment is compromised, the full private information remains protected.
Solution Approach 2:
The patent introduces an intermediary mechanism (the system server) that mediates between data owners and third-party vendors. The server manages attribute-based access control, verifying vendor credentials and granting access only to authorized data segments. This intermediary layer enables productive data sharing while protecting privacy by filtering and controlling what information reaches third parties.
2Reliability
If attribute-based access control is implemented, then data security is improved, but system complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where data owners automatically define access policies and attributes for their data segments without manual intervention. The system automatically matches vendor credentials against defined attributes and grants access accordingly. This automation reduces system complexity by eliminating manual access control management while maintaining strong security through attribute-based policies.
Solution Approach 2:
The patent uses attribute parameters to control access, where data security is enforced through configurable attribute definitions rather than hard-coded security rules. Access policies are defined in terms of flexible attributes (e.g., vendor type, clearance level, purpose) that can be adjusted without changing system structure. This parameter-based approach improves data security while managing system complexity through configurable rather than fixed security mechanisms.
3Adaptability or versatility
If custom-developed participatory sensing applications are used, then specific research purposes are achieved, but data security and privacy protection are worsened
Solution Approach 1:
The patent implements a universal attribute-based access control framework that can be applied across multiple custom-developed participatory sensing applications. Rather than each application implementing its own security mechanism, they all use the same attribute-based system defined by data owners. This universal framework enables research-specific functionality while maintaining consistent data security and privacy protection across all applications.
Data Source
AI summary
Disclosed are devices, systems, and methods for securing data using attribute based data access. The data may correspond to a sensory environment, and the data is secured at the device. The device secures the data by segmenting the data into number of segments and defining an access policy, further submitting the access policy to a PKG of system for generating Access Tree having attributes at different level for accessing the data. These Access Trees are securely stored on the device using IBE mechanism. Further, the data after being secured, is uploaded to a system for analysis. At the system, an access request may be received for accessing the data. The access request further includes a request attribute, whereby the system verifies if the attribute satisfies the Access Policy. If the verification is positive, an access may be provided to the data accessor for accessing the data.


