Context-Based Data Access Control via Heartbeat Anchoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data security systems rely on user-dependent authentication methods, which are ineffective in preventing data breaches as they grant ownership of data to users, leading to potential misuse and increased risk of data loss, especially when users access sensitive information outside defined boundaries.

Innovation Solution

A data anchor system that uses a heartbeat signal to define access context, unlocking encrypted data only when the user device is within a specified context, and revoking access if the context is violated, thereby maintaining control over sensitive data and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional authentication methods are used to grant users access to sensitive data, then users can access and use the data, but users are granted ownership of the data which leads to potential misuse and increased risk of data loss

Engineering Contradiction:
Improvedata accessVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments data access control into multiple independent components: authentication credentials, context identifiers, and encryption keys. Each component serves a distinct function - authentication verifies user identity, context identifiers define access boundaries, and encryption keys protect data at rest and in transit. This segmentation allows the system to grant access while maintaining security controls, resolving the contradiction between ease of operation and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary data anchor system that sits between users and sensitive data. This intermediary maintains encryption keys and context identifiers, mediating all data access requests. Instead of users directly accessing data with full ownership rights, the intermediary controls access by verifying context identifiers and managing key distribution, thereby maintaining security while enabling operational access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strong security walls are built around data to prevent all breaches, then data security is improved, but usability and performance of computer systems suffer

Engineering Contradiction:
Improvedata securityVSAvoidsystem usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic access control where security parameters are not static but adapt based on context. Context identifiers define dynamic boundaries that can change based on user role, data sensitivity, and operational needs. Encryption keys are dynamically distributed and revoked based on context validation, allowing the system to be secure without imposing rigid constraints that would degrade usability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes security parameters from binary (access granted/denied) to multi-dimensional (context-specific access levels). By introducing context identifiers with various attributes and encryption key hierarchies, the system can adjust security parameters to match the actual risk level of each access request, maintaining strong security where needed while allowing flexible access where appropriate.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If authentication grants users ownership of data, then users can copy and use data freely, but enterprises must rely on human trust to keep data safe which is a flawed foundation

Engineering Contradiction:
Improvedata usage flexibilityVSAvoidsecurity foundation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs preliminary actions by establishing encryption and context constraints before data access is granted. Encryption keys are distributed with built-in constraints that prevent unauthorized copying or usage outside defined contexts. This preliminary structuring of data protection mechanisms eliminates the need to rely on human trust, as the security controls are embedded in the data architecture itself rather than depending on user behavior.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11880490B2Context-based access control and revocation for data governance and loss mitigation
Publication Date: 2024.01.23 OHIO STATE INNOVATION FOUND
  • US11880490B2 patent drawing
  • US11880490B2 patent drawing
  • US11880490B2 patent drawing

AI summary

Systems, methods, and computer program products for controlling use of sensitive data. A heartbeat signal conveying a context identifier is transmitted into areas where access to sensitive data is granted to authorized users. In response to receiving a request to access the sensitive data, access may be granted if the context identifier in the request matches the context identifier in the heartbeat and denied otherwise. If the requestor has exceeded an access threshold, access may be granted at a reduced rate. This reduced rate may be achieved by reducing a rate at which encryption keys are provided to the requestor. An access control layer positioned between an application layer and a communication layer allows the application layer to use plaintext of the sensitive data while protecting the sensitive data as ciphertext in the communication layer.