Data Securing System with Node Managers for Secure Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data securing systems face challenges in managing access to shared data in complex organizational structures, particularly in ensuring secure data distribution while maintaining confidentiality and integrity, as they often require trusting a central authority or rely on insecure data processing architectures.

Innovation Solution

A data securing system with Node Managers that control access to shared data storage, using a publish-subscribe model and cryptographic key mechanisms to manage access and ensure secure data distribution among connected nodes, allowing data owners to control access and maintain asymmetry of trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security approaches are used to ensure data confidentiality and access control, then security requirements are met, but data throughput and flexibility of information flows are compromised

Engineering Contradiction:
Improvedata securityVSAvoiddata throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the security management function by introducing intermediary Domain Managers that operate independently for each domain. These Domain Managers handle access control and key distribution locally, eliminating the need for a single centralized security authority that would bottleneck data flows. This segmentation allows parallel security verification across multiple domains, maintaining security while improving throughput.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces Domain Managers as intermediary components between data producers and consumers. These intermediaries handle the complex security verification, authentication, and key distribution tasks, allowing data to flow freely once authorized. The Domain Managers act as mediators that resolve security checks without blocking legitimate data throughput.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a centralized trusted authority is used to manage access control, then security management is simplified, but trust requirements increase and single points of failure are created

Engineering Contradiction:
Improvesecurity management complexityVSAvoidtrust requirements
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the centralized security authority into multiple distributed Domain Managers, each responsible for a specific domain. This segmentation eliminates the single point of failure and reduces trust requirements, as users only need to trust their own Domain Manager rather than a central authority with access to all data. Each Domain Manager operates independently, managing access control locally without creating a centralized vulnerability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If data is processed in a secure data processing centre, then data confidentiality is maintained, but control over resultant information is lost when it leaves the secure centre

Engineering Contradiction:
Improvedata confidentialityVSAvoidcontrol over information
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by embedding security metadata and access control information directly into data objects before they leave the secure processing center. Domain Managers pre-establish trust relationships and attach cryptographic credentials to data, allowing data consumers to verify and maintain control over the information throughout its lifecycle outside the secure center, without requiring continuous centralized verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates cryptographic copies of security credentials and access control information that travel with data objects. Instead of requiring the original secure processing center to verify every access request, the system uses cryptographic copies (digital signatures, certificates) that can be independently verified by any Domain Manager or data consumer, maintaining control without centralized oversight.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If decentralized data access is allowed, then data flexibility and accessibility are improved, but security threats from malicious code and information leakage increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces Domain Managers as intermediary security components that mediate between decentralized data access and security protection. These intermediaries verify the authenticity and integrity of data objects, check access permissions, and enforce security policies at each access point. This allows flexible decentralized access while maintaining security through local verification rather than requiring centralized control or trusting all access points.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements self-service security where data objects carry their own security credentials and Domain Managers perform automatic verification. The security system serves itself through cryptographic validation, authentication, and authorization checks that occur automatically without human intervention. This enables decentralized access with built-in security protection, as each data object proves its legitimacy through self-contained cryptographic evidence.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2890084B1A data securing system and method
Publication Date: 2018.04.18 THALES NEDERLAND BV
  • EP2890084B1 patent drawingFigure 1
  • EP2890084B1 patent drawingFigure 2
  • EP2890084B1 patent drawingFigure 3

AI summary

The invention provides a method and system for controlling data distribution in a system (100) comprising a set of nodes (10) interconnected through a communication system and a shared data storage space (12), each node owning a part of the data maintained in the shared data storage space. Each node comprises a node manager (110) for controlling access by producer and consumer nodes to the data owned by the node. A first group of nodes are associated with a first trusting level and a second group with a second trusting level. A common shared key is generated for all members of the first group, and a unique key derived from the shared key for each member of the second group. Access to the node data part is controlled based on the shared key for the first group and based on the unique derived key for the second group.