Data Compute Agent Access Control with Cryptographic Identity Bids

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing attribute-based encryption schemes for user data protection are complex and inefficient, lacking effective mechanisms to manage access control based on user-specified attributes.

Innovation Solution

A user data attribute-based data protection protocol that allows entities to access and process user data only when specific attributes, such as location, time, and trusted hardware are met, using cryptographic signatures and tamper-proof silicon chips to ensure data integrity and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If attribute-based encryption schemes are used for user data protection, then data security is improved, but system complexity increases and efficiency decreases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a data compute agent as an intermediary component that mediates between the distributed service and user data. This agent verifies entity attributes, manages access control decisions, and enforces attribute-based policies, thereby simplifying the overall system architecture while maintaining strong security through a dedicated security management layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If attribute-based encryption schemes are used for user data protection, then data security is improved, but processing efficiency decreases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary attribute verification through the data compute agent before data processing operations begin. Entity attributes are verified in advance against required attributes, and access control decisions are made beforehand, allowing efficient data processing to proceed without repeated security checks during execution

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If distributed services process user data, then service capabilities are expanded, but access control management becomes more difficult

Engineering Contradiction:
Improveservice capabilitiesVSAvoidaccess control management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The data compute agent serves as a universal access control mechanism that can be deployed across multiple distributed services and data types. It provides a unified attribute verification framework that works consistently across different services, simplifying access control management while maintaining expanded service capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12423453B2Methods and apparatus to control access to user data based on user-specified attributes
Publication Date: 2025.09.23 INTEL CORP
  • US12423453B2 patent drawing
  • US12423453B2 patent drawing
  • US12423453B2 patent drawing

AI summary

Methods, apparatus, systems, and articles of manufacture for controlling access to user data are disclosed herein. One such apparatus to control access to user data includes memory, instructions, and at least one processor to execute the instructions to attempt to verify an identity bid associated with a request for access to user data to be processed. The identity bid includes a cryptographic signature based on a secret embedded in a data compute agent that generated the identity bid. The processor is also to determine whether agent attributes included in the identity bid satisfy user data attributes associated with the user data, and to permit the data compute agent to access the user data when the identity bid is verified, and when the agent attributes satisfy the user data attributes.