Controlled Data Transfer Between Security Levels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies lack a framework for managing data transfers between data environments with different control levels and security clearances, leading to challenges in identifying origination and destination environments, ensuring security compatibility, and authenticating data environments.

Innovation Solution

A system for controlled data transmission between data environments, which includes a data driver for transmitting datasets, a delivery gateway for identifying and authenticating environments, and an auto-sanitization engine for ensuring security compatibility by fragmenting and masking data segments based on security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data transfer occurs between data environments with different control levels and security clearances, then data transmission capability is improved, but security control and identification difficulty worsen

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidsecurity control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway as an intermediary component between data environments with different security levels. The gateway performs identification, authentication, and authorization functions to manage data transfers between environments with varying control levels, thereby enabling versatile data transfer while maintaining security control through a dedicated intermediary layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary identification and authentication actions before data transfer occurs. The system retrieves environment-specific identification information and verifies security clearance levels in advance, ensuring that data transfers between different environments are authorized before the actual transfer begins, thus managing security complexity proactively

Inventive Principle:
Principle #10Preliminary action

2Reliability

If identification checks are performed on original and destination environments, then security authentication is improved, but transfer processing time worsens

Engineering Contradiction:
Improvesecurity authenticationVSAvoidtransfer processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs identification and authentication actions before the data transfer process begins. By retrieving environment-specific identification information and verifying security clearance in advance, the system ensures security authentication is completed prior to transfer initiation, minimizing the time added during the actual data transmission process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway receives feedback information from both the original and destination environments regarding their identification and security status. This feedback mechanism allows the system to verify authentication results and make real-time decisions about whether to permit data transfer, balancing security requirements with processing efficiency

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If data is sanitized and segmented based on security levels, then data security is improved, but data processing complexity worsens

Engineering Contradiction:
Improvedata securityVSAvoiddata processing complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments data into different portions based on security clearance levels before transfer. The gateway divides the dataset and selectively transfers only the portions appropriate for the destination environment's security level, thereby enhancing data security by preventing unauthorized data exposure while managing processing complexity through structured segmentation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different sanitization and processing qualities to different data segments based on their security levels and destination requirements. High-security data receives more stringent processing than low-security data, optimizing the balance between security enhancement and processing complexity by applying appropriate measures only where necessary

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12289316B2Multi-leveled data transfer
Publication Date: 2025.04.29 BANK OF AMERICA CORP
  • US12289316B2 patent drawing
  • US12289316B2 patent drawing
  • US12289316B2 patent drawing

AI summary

Methods, systems and apparatus for controlled data transmission within leveled data environments is provided. Methods may include transmitting a dataset, using a data driver, from a first data environment to a second data environment. Methods may include intercepting the dataset at a reception gateway. Methods may include transmitting an identification. The identification request may request an original data environment from which the data originated; and a destination data environment to which the data is being transmitted. Methods may include in response to receiving a reply to the identification request, authenticating the reply. Methods may include initiating a security level compatibility check. Methods may include determining whether the first data environment is compatible with the second data environment. Methods may include transmitting the dataset through an auto-sanitization engine. Methods may include fragmenting the data into a plurality of data segments. Methods may include assigning to each data segment a security level. Methods may include masking data segments determined to have a security clearance level greater than the security level of the second data environment. Methods may include building a second dataset with remaining data segments. Methods may include storing the second dataset at the second data environment.