Data Control Ledger for Secure Account Modification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices in data communication environments face challenges in controlling data leakage and unauthorized access, as compromised devices can be used for exfiltrating data or uploading malicious content, posing security risks due to direct interactions with provisioning service devices.

Innovation Solution

Implementing a data control ledger system that tracks and manages service requests, creating an immutable log to monitor and secure user account changes, and using an integrated data control ledger architecture to compartmentalize user account information across multiple groups within an enterprise, ensuring end-to-end tracking and error correction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network devices send service requests directly to provisioning service devices, then service processing is efficient and direct, but security is compromised as compromised devices can exfiltrate data or upload malicious content

Engineering Contradiction:
ImprovesecurityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a data control device as an intermediary between network devices and provisioning service devices. This mediator receives service requests from network devices, processes them, and communicates with provisioning service devices on behalf of the network devices. The data control device maintains a data control ledger to track all service requests and actions, preventing direct interactions that would compromise security while enabling efficient service processing through the intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a data control ledger is introduced to track service requests and create immutable logs, then security and auditability are improved, but system complexity and overhead increase

Engineering Contradiction:
ImproveauditabilityVSAvoidledger management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data control ledger serves multiple functions within the system: it tracks service requests, records actions performed on user accounts, maintains immutable audit logs, and provides the basis for error correction. By consolidating these functions into a single ledger structure managed by the data control device, the system achieves comprehensive auditability without proportionally increasing complexity, as the same ledger infrastructure supports all auditing and tracking needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If integrated data control ledger architecture is used to compartmentalize user account information across multiple groups, then security and data management are improved, but system complexity and integration overhead increase

Engineering Contradiction:
Improvedata compartmentalizationVSAvoidintegrated ledger architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements segmentation by creating separate data control ledgers for different groups within an enterprise. Each group has its own ledger that tracks user account information specific to that group, allowing data compartmentalization and targeted security control. The integrated data control ledger architecture connects these segmented ledgers, enabling end-to-end tracking while maintaining security boundaries. This segmentation approach allows different groups to manage their data independently while the integration layer provides overall coordination.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11658832B2Information security using data control ledgers
Publication Date: 2023.05.23 BANK OF AMERICA CORP
  • US11658832B2 patent drawing
  • US11658832B2 patent drawing
  • US11658832B2 patent drawing

AI summary

A device configured to receive a service request for modifying a user account. The device is further configured to add an entry in a service request log and an event log in response to receiving the service request. The device is further configured to query a status log to determine a current status of the user account. The device is further configured to apply modification instructions from the service request to the current status of the user account to update the current status of the user account and to modify the current status of the user account in the status log. The device is further configured to identify a provisioning service device that is associated with the user account, to determine service instructions for the provisioning service device based on the updated current status of the user account, and to send the service instructions to the provisioning service device.