Data Control Ledgers for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices in data communication environments face challenges in controlling data leakage and unauthorized access, as compromised devices can exploit connections to exfiltrate data or upload malicious content, posing security risks due to direct interactions with provisioning service devices.

Innovation Solution

Implementing a data control system that uses data control ledgers to track and manage service requests, creating an immutable log of user account changes, and employing an integrated data control ledger architecture to compartmentalize user account information across multiple groups, ensuring end-to-end tracking and error correction, thereby preventing direct modification or exfiltration by compromised network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network devices directly interact with provisioning service devices to exchange data, then data sharing and service provisioning efficiency are improved, but network security deteriorates due to vulnerability to attacks and data exfiltration

Engineering Contradiction:
Improveservice provisioning efficiencyVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces data control devices as intermediaries between network devices and provisioning service devices. These devices manage service requests and control access to user account information, preventing direct connections that could be exploited for attacks while maintaining efficient service provisioning through centralized control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If network devices have complete knowledge about provisioning service devices for direct access, then service operation simplicity is improved, but information security deteriorates due to increased attack surface

Engineering Contradiction:
Improveservice access simplicityVSAvoidattack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the knowledge that network devices have about provisioning service devices. Instead of having complete knowledge, network devices only have partial information stored in data control ledgers. This segmentation reduces the attack surface while maintaining operational simplicity through the intermediary data control devices that manage access

Inventive Principle:
Principle #1Segmentation

3Device complexity

If a single group manages all user account changes in existing systems, then system complexity is reduced, but productivity deteriorates due to inefficiency and lack of parallel processing

Engineering Contradiction:
Improveaccount management structureVSAvoidaccount modification efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent divides user account management into multiple groups, each responsible for specific aspects of account changes. Different groups can work in parallel on different modifications, significantly improving productivity while the data control ledger architecture manages the complexity of coordinating these distributed changes

Inventive Principle:
Principle #1Segmentation

4Reliability

If data control ledgers implement immutable logging of all service requests, then reliability is improved through auditability, but device complexity increases due to additional tracking infrastructure

Engineering Contradiction:
ImproveauditabilityVSAvoidledger infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data control ledgers serve multiple functions: they log service requests immutably for auditing, store partial knowledge about provisioning service devices for security, and coordinate changes across multiple groups. This multi-functionality justifies the infrastructure complexity by delivering comprehensive reliability and security benefits

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11763296B2Information security using integrated data control ledgers
Publication Date: 2023.09.19 BANK OF AMERICA CORP
  • US11763296B2 patent drawing
  • US11763296B2 patent drawing
  • US11763296B2 patent drawing

AI summary

A device configured to receive a service request for modifying a user account. The device is further configured to add an entry in a service request log and in an event log in response to receiving the first service request. The device is further configured to apply the modifications instructions from the service request to a current status of the user account in a status log and to modify the current status of the user account in the status log. The device is further configured to determine a second data control device is associated with the user account. The device is further configured to determine the first set of service instructions based on the updated first current status of the user account, to generate a second service request that comprises the first set of service instructions, and to send the second service request to the second network device.