Data Dissemination Tracking via Graph Nodes and Security Conformance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data dissemination tracking methods are inadequate for fine-grained monitoring of data usage across diverse networks and devices, particularly in 'Bring Your Own Device' (BYOD) scenarios and open innovation environments, as they rely on server-centric approaches that are not well-suited for a priori prevention of confidentiality breaches.
Innovation Solution
A system utilizing a tracking server with a database to record the transmission path of data sets, where each data set includes a management section with security conformance levels, allowing devices to request and authorize data transfers based on conformance levels, and maintaining graph data sets to track device interactions and transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a server-centric approach is used to control data dissemination, then data transmission can be controlled centrally, but fine-grained monitoring of data usage across diverse networks and devices cannot be achieved
Solution Approach 1:
The system segments the monitoring function by deploying lightweight agents on each device rather than relying on a single centralized server. Each agent independently tracks data usage locally, enabling fine-grained monitoring across diverse networks and devices while distributing system complexity throughout the network infrastructure.
Solution Approach 2:
The patent introduces data usage information as an intermediary element that travels with data packets between devices. This intermediary contains monitoring data and control instructions, enabling precise tracking of data usage without requiring direct complex interactions between all devices and the central authority.
2Reliability
If data is stored on the tracking server, then comprehensive tracking is possible, but data storage requirements and server burden increase
Solution Approach 1:
The system extracts essential tracking information from the data payload itself by embedding data usage information directly in the data packets. This allows devices to track data dissemination locally without storing complete data copies on the server, reducing storage requirements while maintaining tracking reliability through distributed monitoring.
Solution Approach 2:
Instead of storing the actual data payload on the server, the system creates and maintains copies of metadata (data usage information) that describe the data's journey. These metadata copies are lightweight and sufficient for tracking purposes, eliminating the need to store voluminous data while preserving tracking capability.
3Adaptability or versatility
If user-centric access control is used, then ease of operation is improved, but adaptability to open innovation environments and BYOD scenarios is reduced
Solution Approach 1:
The system implements a universal data usage information structure that works across multiple device types, networks, and security contexts. The standardized format enables the same tracking mechanism to adapt to diverse environments including BYOD scenarios, open innovation networks, and traditional corporate infrastructures without requiring operationally complex configurations.
Solution Approach 2:
The patent employs parameter changes in the data usage information structure to adapt to different security contexts and environments. By modifying control parameters within the standardized framework, the system can adjust access control behavior for different scenarios (e.g., BYOD vs. corporate networks) while maintaining operational simplicity through automated parameter-based decision making.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present invention concerns the field of data dissemination tracking, in particular aims at keeping track of the various devices in which a given data was used. It is proposed a method to track the dissemination of a first data set carried out by a first tracking server (CS1), a first device and a second device, said data set comprising a data management section and a data payload, said data management section comprising a data identifier and data usage information defining a security conformance level, said method comprising the steps of: - receiving by the first tracking server (CS1) from the first device(d0), a first device identification and at least a data management section of a first set of data, said data management section comprising at least a security conformance level and a first data identifier, - identifying or creating in the database, a current graph data set corresponding to the first data identifier, said current graph data set comprising a common section, edges and nodes, - storing in the current graph data set, said first data management section in the common section and said first identifier as a first node, - receiving by the first tracking server (CS1) a request to transfer the first data set from the first device to the second device, said request comprising at least a second device identification of the second device and the first data identifier, - retrieving by the first tracking server (CS1) second device security conformance level, based on the second device identification, - verifying by the first tracking server (CS1) that the second device security conformance level meets the security conformance level of the first data set as identifier by the first data identifier, - in the positive event, responding by granting authorisation to the transfer at least the data payload of the first data set to the second device, - recording in the database, in respect with the current graph data set, the second device identifier as a second graph data node, - recording in the database, in respect with the current graph data set, a transaction from the first device to second device as an edge in the current graph data set linking the first graph node and the second graph node.