Data Securing System with Node Managers for Secure Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data securing systems face challenges in managing access to shared data in complex organizational structures, particularly in ensuring secure data distribution while maintaining confidentiality and integrity, as they often require trusting a central authority or rely on insecure data processing architectures.
Innovation Solution
A data securing system with Node Managers that control access to shared data storage, using a publish-subscribe model and cryptographic key mechanisms to manage access and ensure secure data distribution among connected nodes, allowing data owners to control access and maintain asymmetry of trust.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security approaches are used to ensure data confidentiality and access control, then security requirements are met, but data throughput and flexibility of information flows are compromised
Solution Approach 1:
The patent segments the security management function by introducing intermediary Domain Managers that operate independently for each domain. These Domain Managers handle access control and key distribution locally, eliminating the need for a single centralized security authority that would bottleneck data flows. This segmentation allows parallel security verification across multiple domains, maintaining security while improving throughput.
Solution Approach 2:
The patent introduces Domain Managers as intermediary components between data producers and consumers. These intermediaries handle the complex security verification, authentication, and key distribution tasks, allowing data to flow freely once authorized. The Domain Managers act as mediators that resolve security checks without blocking legitimate data throughput.
2Device complexity
If a centralized trusted authority is used to manage access control, then security management is simplified, but trust requirements increase and single points of failure are created
Solution Approach 1:
The patent divides the centralized security authority into multiple distributed Domain Managers, each responsible for a specific domain. This segmentation eliminates the single point of failure and reduces trust requirements, as users only need to trust their own Domain Manager rather than a central authority with access to all data. Each Domain Manager operates independently, managing access control locally without creating a centralized vulnerability.
3Reliability
If data is processed in a secure data processing centre, then data confidentiality is maintained, but control over resultant information is lost when it leaves the secure centre
Solution Approach 1:
The patent implements preliminary action by embedding security metadata and access control information directly into data objects before they leave the secure processing center. Domain Managers pre-establish trust relationships and attach cryptographic credentials to data, allowing data consumers to verify and maintain control over the information throughout its lifecycle outside the secure center, without requiring continuous centralized verification.
Solution Approach 2:
The patent creates cryptographic copies of security credentials and access control information that travel with data objects. Instead of requiring the original secure processing center to verify every access request, the system uses cryptographic copies (digital signatures, certificates) that can be independently verified by any Domain Manager or data consumer, maintaining control without centralized oversight.
4Adaptability or versatility
If decentralized data access is allowed, then data flexibility and accessibility are improved, but security threats from malicious code and information leakage increase
Solution Approach 1:
The patent introduces Domain Managers as intermediary security components that mediate between decentralized data access and security protection. These intermediaries verify the authenticity and integrity of data objects, check access permissions, and enforce security policies at each access point. This allows flexible decentralized access while maintaining security through local verification rather than requiring centralized control or trusting all access points.
Solution Approach 2:
The patent implements self-service security where data objects carry their own security credentials and Domain Managers perform automatic verification. The security system serves itself through cryptographic validation, authentication, and authorization checks that occur automatically without human intervention. This enables decentralized access with built-in security protection, as each data object proves its legitimacy through self-contained cryptographic evidence.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention provides a method and system for controlling data distribution in a system (100) comprising a set of nodes (10) interconnected through a communication system and a shared data storage space (12), each node owning a part of the data maintained in the shared data storage space. Each node comprises a node manager (110) for controlling access by producer and consumer nodes to the data owned by the node. A first group of nodes are associated with a first trusting level and a second group with a second trusting level. A common shared key is generated for all members of the first group, and a unique key derived from the shared key for each member of the second group. Access to the node data part is controlled based on the shared key for the first group and based on the unique derived key for the second group.