Data Intermediary Registry Security via Segmentation and Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data security systems lack flexibility in managing access to data intermediaries, often providing all or no access, which increases security risks when sharing data between parties.
Innovation Solution
A system that includes a processor and memory for managing a registry of authorized data intermediaries and recipients, blocking access to identities and providing data based on this registry, using encryption keys to secure sensitive information and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all or no access is provided to data intermediaries, then data security is maintained, but flexibility and adaptability in data sharing are reduced
Solution Approach 1:
The patent segments data access into multiple levels: public data, private data, and confidential data. Each level has different access controls and visibility rules. Intermediaries can be granted access to specific segments based on their authorization, allowing flexible data sharing while maintaining security through hierarchical segmentation of information.
Solution Approach 2:
The patent implements local quality by allowing different intermediaries to have different access rights to different data segments. Each intermediary receives only the specific data portions they are authorized to access, rather than uniform all-or-nothing access. This enables tailored access control where each intermediary's data view is customized to their specific needs and authorization level.
2Loss of information
If identities of data recipients are made visible in the registry, then transparency and traceability are improved, but security risks and exposure to unauthorized access increase
Solution Approach 1:
The patent extracts sensitive identity information from the publicly visible registry portion. While the registry maintains traceability through recording data flows and transactions, actual recipient identities are removed from general view and only accessible to authorized parties through secure channels. This separation allows transparency in data movement without exposing sensitive identity information to potential threats.
Solution Approach 2:
The patent introduces an intermediary layer between the registry and identity information. The registry system acts as a mediator that can provide identity information to authorized intermediaries while preventing direct access by other parties. This intermediary mechanism enables controlled disclosure of identities for legitimate purposes while blocking unauthorized access attempts.
3Ease of operation
If a registry system is implemented to manage data intermediaries, then control and monitoring capabilities are enhanced, but system complexity increases
Solution Approach 1:
The patent implements a universal registry system that performs multiple functions: authorization management, data routing, access control enforcement, and transaction monitoring. By consolidating these functions into a single multi-functional platform, the system reduces overall complexity compared to having separate systems for each function, while maintaining comprehensive control and monitoring capabilities.
Solution Approach 2:
The patent applies preliminary action by pre-configuring authorization rules, data segments, and access policies in the registry before data sharing occurs. Intermediaries are pre-authorized with specific permissions, and data is pre-segmented into accessible portions. This preliminary setup reduces operational complexity during actual data exchanges, as the system automatically enforces pre-established rules rather than requiring complex real-time decision-making.
Data Source
AI summary
Apparatuses, systems, methods, and computer program products are disclosed for data intermediary registry security. A method includes managing a registry of data intermediaries authorized to receive data from a data provider and of data recipients associated with the data intermediaries. A method includes blocking access in the registry to identities of the data recipients associated with one of the data intermediaries by one or more other of the intermediaries. A method includes providing data to at least one of the data intermediaries and the data recipients based on the registry.


