Data Ownership Platform Multicast Encryption Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack the capability to automate the processing of granting and withdrawing consent for accessing personal data, and existing blockchain-based solutions face scalability issues and security vulnerabilities.

Innovation Solution

A data-ownership platform (DOP) that uses a blockchain-based governance layer to control access to data streams, allowing publishers to grant or revoke access to subscribers without intermediaries, and tokenizes data streams for secure and regulated sharing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If blockchain-based solutions are used to control data access, then data security and individual control are improved, but scalability and system complexity worsen due to massive storage requirements and additional data access layers

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the data access control logic from the blockchain layer and implements it at the application layer. The blockchain is used only to store immutable access policies and consent records, while the actual data access control is handled by the data processing system through event subscriptions and key management, eliminating the need for complex blockchain-based data access protocols

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the data access control functionality into separate components: blockchain stores only the access policies and consent records, while the data processing system handles the actual access control execution. This separation allows each component to be optimized independently, reducing overall system complexity

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If data is propagated to persistence providers before tokenization, then data access control is enabled, but security vulnerabilities increase due to exposed data during the propagation process

Engineering Contradiction:
Improvedata access controlVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing access policies and obtaining consent records on the blockchain before any data propagation occurs. The data processing system then uses these pre-established policies to control access from the outset, eliminating the security vulnerability window that exists in systems where data is propagated before access control is implemented

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by using blockchain-stored access policies to prevent unauthorized access before data can be compromised. The immutable consent records and access control policies are established in advance to counteract potential security threats during data propagation

Inventive Principle:
Principle #9Preliminary anti-action

3Adaptability or versatility

If custom data access layers are added to existing communication protocols, then data access control functionality is improved, but system complexity and integration difficulty worsen

Engineering Contradiction:
Improvedata access control functionalityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal data access control mechanism that works across multiple existing communication protocols (MQTT, HTTP, CoAP, etc.). The access control functionality is implemented through standard subscription and event mechanisms that are already supported by these protocols, eliminating the need for custom protocol extensions and reducing integration complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If automated consent processing is implemented, then data access efficiency is improved, but technology capability requirements worsen as no known technologies currently support this function

Engineering Contradiction:
Improveconsent processing efficiencyVSAvoidtechnology capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system implements self-service automated consent processing where the data processing system automatically subscribes to data streams based on blockchain-stored access policies and automatically manages data access without human intervention. The smart contracts on the blockchain automatically execute consent granting and revocation, eliminating the need for manual consent processing and existing intermediary technologies

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250080326A1Multicast encryption scheme for data-ownership platform
Publication Date: 2025.03.06 ECOSTEER SRL
  • US20250080326A1 patent drawing
  • US20250080326A1 patent drawing
  • US20250080326A1 patent drawing

AI summary

Disclosed herein are embodiments for implementing periodic management of cryptographic keys. An embodiment includes a processor configured to perform operations comprising receive a first input associating a first set of subscribers with a first data stream published by the first publisher device, and a first cryptographic key. Processor may transmit, to the first publisher device, a first confirmation, indicating that the first cryptographic key is ready for use, for example. In some embodiments, processor may release the first cryptographic key to a first set of subscribers, receive a second input from a publishing user, associating a different, second set of subscribers with the first data stream, and receive a second cryptographic key after a certain time period. Processor may further transmit, to the first device, a second confirmation, indicating that the second cryptographic key is ready for use, and release the second cryptographic key to the second set of subscribers.