Blockchain-Based Privacy Event Logging for Enterprise Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for systems and methods that provide transparency to users regarding actions taken on their private data by entities other than themselves, such as administrators or intruders, within enterprise mobility management systems, ensuring that private information is protected from unauthorized access.

Innovation Solution

A system and method that detects access to private data by entities other than the user, generates events reflecting such access, and stores these events in a database using a blockchain application for immutability, allowing users to be notified of any unauthorized access through a user device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If employers monitor worker activities on worker-owned computers to ensure secure use of company software, then security monitoring is improved, but worker privacy is worsened

Engineering Contradiction:
Improvesecurity monitoringVSAvoidworker privacy
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments monitoring into two distinct categories: authorized monitoring of company software usage and unauthorized monitoring of private data. By tracking and differentiating between these types of access, the system enables selective transparency where workers can see authorized monitoring actions but remain protected from unauthorized intrusion into their private data, thus resolving the contradiction between security monitoring and privacy protection

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements feedback mechanisms that notify workers when their private data is accessed by unauthorized entities. This feedback loop allows workers to be informed about security events affecting their privacy, enabling them to take corrective action while maintaining trust in the monitoring system's ability to protect both security and privacy interests

Inventive Principle:
Principle #23Feedback

2Reliability

If employers are permitted to monitor certain activities including unauthorized programs, then network security is improved, but worker trust is worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidworker trust
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system introduces an intermediary layer in the form of a transparency platform that mediates between employer monitoring capabilities and worker concerns. This intermediary provides workers with visibility into monitoring activities through a user-friendly interface, building trust by demonstrating that monitoring is conducted responsibly and transparently while maintaining network security through authorized monitoring of unauthorized programs

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses visual indicators and status displays to communicate the state of monitoring and data access to workers. By providing clear visual feedback about what is being monitored and by whom, the system builds worker trust in the transparency of the monitoring process while maintaining the ability to detect and respond to security threats

Inventive Principle:
Principle #32Color changes

3Device complexity

If private data access events are stored in traditional databases, then data storage is simplified, but data integrity is worsened

Engineering Contradiction:
Improvedata storageVSAvoiddata integrity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system merges traditional database storage with blockchain technology to create a hybrid data storage solution. The blockchain component provides immutable, tamper-evident storage of private data access events, while the traditional database handles the bulk data storage. This combination maintains simplicity for most operations while ensuring data integrity through blockchain's cryptographic hashing and chaining mechanisms

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary hashing of data before storage in the blockchain. By creating cryptographic hashes of the access event data and storing these hashes on the blockchain, the system ensures data integrity is established in advance. Any subsequent tampering with the stored data would result in hash mismatches that can be detected, thereby maintaining reliability without significantly complicating the storage architecture

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11087020B2Providing transparency in private-user-data access
Publication Date: 2021.08.10 OMNISSA LLC
  • US11087020B2 patent drawing
  • US11087020B2 patent drawing
  • US11087020B2 patent drawing

AI summary

Examples described herein include systems and methods for providing privacy information to a user of a user device. An example method can include detecting, at a management server, access of the private data by an entity other than the user, such as an administrator who is authorized to access the management server. The method further includes generating an event reflecting the access of the private data. The generated event can be stored as part of an event log in a database. The method further includes providing the event to the user device for display to the user. The event displayed on the user device can include information such as an identity of the accessing entity, a description of the private data that was accessed, and when the access occurred. The user can select a displayed event at the user device and request further information on the event from an administrator.