Attribute Information Processing Device for Data Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems that utilize a trusted third party to manage and distribute personal data face increased risks of information leakage due to the need to share location information of data providers, allowing malicious operators to target and compromise data sources.

Innovation Solution

An attribute information processing device and system that acquires and evaluates attribute information by generating pseudo attribute values and evaluation information, separating the sources of real and pseudo attribute values, and using these to create an evaluation function, thereby reducing the risk of information leakage by obscuring the origin of attribute data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a trusted third party is used to manage and distribute personal data, then data distribution and service provision are enabled, but the risk of information leakage increases due to exposure of data provider location information

Engineering Contradiction:
Improvedata distribution capabilityVSAvoidinformation leakage risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an evaluation device as an intermediary between attribute providing devices and data users. This evaluation device verifies the credibility of attribute providing devices without exposing their location information, thus enabling data distribution while reducing information leakage risk. The intermediary performs evaluation and authentication functions that protect the identities of data providers while still allowing legitimate access to their data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If location information of data providers is shared with the trusted third party, then data management and distribution are facilitated, but malicious operators can target and compromise specific data sources

Engineering Contradiction:
Improvedata management efficiencyVSAvoiddata source security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the functionality of the trusted third party into separate components: the evaluation device handles credibility assessment and authentication, while the actual data distribution is performed by attribute providing devices. This segmentation allows efficient data management without requiring the exposure of complete location information to all parties, thereby maintaining security while preserving operational efficiency.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If personal data are obtained from the trusted third party, then centralized data management is achieved, but the leakage source is not limited to data providers only

Engineering Contradiction:
Improvedata management structureVSAvoidleakage vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the core authentication and evaluation functions from the centralized trusted third party structure and implements them through the evaluation device. This allows the system to maintain centralized management capabilities while reducing the attack surface, as the evaluation device verifies credentials without necessarily holding or exposing all personal data in one centralized location.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9201915B2Attribute information processing device, attribute information processing method and attribute information evaluation system
Publication Date: 2015.12.01 NEC CORP
  • US9201915B2 patent drawing
  • US9201915B2 patent drawing
  • US9201915B2 patent drawing

AI summary

An attribute information processing device includes: an attribute information acquiring unit that acquires attribute information; an attribute value acquiring unit that acquires at least two types of attribute values including a first-type attribute value and a second-type attribute value corresponding to an attribute value of the acquired attribute information; a generating unit that determines a function for obtaining an evaluation value from the acquired two or more types of attribute values, determines a acquisition source of the first-type attribute value to be a first-attribute providing device that can provide the first-type attribute value concerning attribute information serving as a comparison target, determines an acquisition source of the second-type attribute value to be a second-attribute providing device different from the first-attribute providing device, and generates attribute evaluation information containing information on the function, an evaluation value, information for identifying the first-attribute providing device, and information for identifying the second-attribute providing device; and an output unit that outputs the second-type attribute value and the attribute evaluation information.