Data Processing Security via Integrity Measurement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing systems lack effective mechanisms to ensure the secure and controlled access, usage, and propagation of private data across different computing entities, risking data subversion and unauthorized access.

Innovation Solution

A method for controlling data processing by applying individualized usage rules based on the integrity measurement of computing entities, using encryption and masking techniques to secure data items, and ensuring secure data transfer with proof of origin and authenticity, while allowing only authorized access and propagation according to predefined constraints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is made available across multiple computing entities to leverage resources and services, then the utility and accessibility of data is improved, but the risk of unauthorized access and data subversion increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into multiple versions with different levels of sensitivity classification. Each data item is tagged with sensitivity metadata that enables granular control over which computing entities can access which versions of the data, thereby allowing broad accessibility while protecting sensitive portions from unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted computing platform as an intermediary between data owners and computing entities. This platform verifies the integrity of computing entities through measurement verification and enforces usage rules, acting as a mediator that enables data sharing while preventing unauthorized access through cryptographic verification and controlled release mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional access control mechanisms are used to protect private data, then security is improved, but data propagation and sharing between computing entities is restricted

Engineering Contradiction:
Improvedata securityVSAvoiddata propagation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic access control where usage rules are not static but can be verified and adjusted based on the integrity measurements of computing entities. The trusted computing platform can dynamically determine whether to release data based on real-time verification of the computing entity's state, enabling secure data propagation to appropriate entities while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of access control from binary authorized/unauthorized to a spectrum based on integrity measurement verification. By using cryptographic verification of integrity metrics and sensitivity-based release decisions, the system adjusts the level of access granted based on verified parameters, enabling efficient data propagation to trusted entities while maintaining security through parameter-based control.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If data is encrypted and masked to prevent unauthorized access, then confidentiality is improved, but the ability to process and utilize the data is reduced

Engineering Contradiction:
Improvedata confidentialityVSAvoiddata processing capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments data into multiple versions with different levels of sensitivity classification. Less sensitive data versions can be decrypted and processed by computing entities for analysis and utility, while highly sensitive portions remain encrypted or masked. This segmentation enables data processing capabilities to operate on accessible versions while confidentiality is maintained for protected versions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial decryption and selective masking where only the portions of data necessary for a given processing task are decrypted, while other portions remain protected. This partial action approach enables data processing capability to operate effectively on the necessary data subsets while maintaining confidentiality for the full dataset, avoiding the need to fully decrypt everything.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If integrity verification mechanisms are implemented to ensure trustworthy computing platforms, then the reliability of data processing is improved, but the complexity of the system increases

Engineering Contradiction:
Improvecomputing platform trustworthinessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs a trusted computing platform that performs multiple functions including integrity measurement, verification of computing entities, enforcement of usage rules, and controlled data release. By consolidating these functions into a single multi-functional platform, the system achieves high reliability through comprehensive verification while managing complexity through functional integration rather than multiple separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7917752B2Method of controlling the processing of data
Publication Date: 2011.03.29 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7917752B2 patent drawing
  • US7917752B2 patent drawing
  • US7917752B2 patent drawing

AI summary

A method of controlling the processing of data, is provided comprising defining security controls for a plurality of data items, and applying individualised security rules to each of the data items based on a measurement of integrity of a computing entity to which the data items are to be made available.