Data Element Modification Using Semantic Security Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a systematic policy-based type-aware protection mechanism for ensuring the confidentiality and integrity of large-scale data, particularly in scenarios involving multiple users, applications, and processors, where data security policies are not effectively enforced across various data elements.

Innovation Solution

The implementation of a processor-based system that modifies data elements using semantic relationships and pre-selected data security policies, applying markers such as integrity markers, confidentiality markers, or cryptographic codes to secure and verify data integrity and confidentiality, while optimizing computational effort and storage efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data security policies are enforced across all data elements using traditional methods, then data confidentiality and integrity are improved, but computational overhead and processing time increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments data into structured types with associated security policies, allowing selective application of security measures only where needed rather than uniformly across all data. This segmentation enables efficient processing by focusing computational resources on specific data elements that require security enforcement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies security policies during data creation and storage operations rather than during every subsequent access operation. By performing security enforcement in advance (preliminarily), the system reduces computational overhead during data retrieval and processing while maintaining security guarantees.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive data security protection is applied to all data elements, then data confidentiality and integrity are improved, but computational effort and resource consumption increase

Engineering Contradiction:
Improvedata securityVSAvoidcomputational effort
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent assigns different security policy qualities to different data types and elements based on their specific requirements. Rather than applying uniform high-level security to all data, the system applies security measures locally where needed, reducing overall computational effort while maintaining appropriate protection levels for each data element.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes security parameters dynamically based on data type, access context, and policy requirements. By adjusting security enforcement parameters rather than maintaining constant maximum security levels, the system reduces computational effort while preserving data security where necessary.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If type-aware security policies are implemented for structured data, then data protection efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvedata protection efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal data type system where structured data types inherently include security policy information. This multi-functional approach allows the same data type mechanism to serve both data organization and security enforcement functions, improving protection efficiency without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3274902B1Modification of data elements using a semantic relationship
Publication Date: 2021.03.24 HEWLETT PACKARD ENTERPRISE DEV LP
  • EP3274902B1 patent drawingFigure 1
  • EP3274902B1 patent drawingFigure 2
  • EP3274902B1 patent drawingFigure 3A

AI summary

An apparatus comprises a memory to store data and a processor coupled to the memory. The processor may modify a plurality of data elements using a semantic relationship between the plurality of data elements and a pre-selected data security policy and to store data representing the modified plurality of data elements in the memory.