Data Element Modification Using Semantic Security Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack a systematic policy-based type-aware protection mechanism for ensuring the confidentiality and integrity of large-scale data, particularly in scenarios involving multiple users, applications, and processors, where data security policies are not effectively enforced across various data elements.
Innovation Solution
The implementation of a processor-based system that modifies data elements using semantic relationships and pre-selected data security policies, applying markers such as integrity markers, confidentiality markers, or cryptographic codes to secure and verify data integrity and confidentiality, while optimizing computational effort and storage efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data security policies are enforced across all data elements using traditional methods, then data confidentiality and integrity are improved, but computational overhead and processing time increase significantly
Solution Approach 1:
The patent segments data into structured types with associated security policies, allowing selective application of security measures only where needed rather than uniformly across all data. This segmentation enables efficient processing by focusing computational resources on specific data elements that require security enforcement.
Solution Approach 2:
The patent applies security policies during data creation and storage operations rather than during every subsequent access operation. By performing security enforcement in advance (preliminarily), the system reduces computational overhead during data retrieval and processing while maintaining security guarantees.
2Reliability
If comprehensive data security protection is applied to all data elements, then data confidentiality and integrity are improved, but computational effort and resource consumption increase
Solution Approach 1:
The patent assigns different security policy qualities to different data types and elements based on their specific requirements. Rather than applying uniform high-level security to all data, the system applies security measures locally where needed, reducing overall computational effort while maintaining appropriate protection levels for each data element.
Solution Approach 2:
The patent changes security parameters dynamically based on data type, access context, and policy requirements. By adjusting security enforcement parameters rather than maintaining constant maximum security levels, the system reduces computational effort while preserving data security where necessary.
3Productivity
If type-aware security policies are implemented for structured data, then data protection efficiency is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal data type system where structured data types inherently include security policy information. This multi-functional approach allows the same data type mechanism to serve both data organization and security enforcement functions, improving protection efficiency without proportionally increasing system complexity.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
An apparatus comprises a memory to store data and a processor coupled to the memory. The processor may modify a plurality of data elements using a semantic relationship between the plurality of data elements and a pre-selected data security policy and to store data representing the modified plurality of data elements in the memory.