Multi-Computer Data Security Platform for Selective Ledger Disclosure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributed ledger systems often provide public audibility and verifiability, leading to users losing control over the types of data visible to others and unnecessary data sharing among transaction parties.
Innovation Solution
Implementing a data security control computing platform that categorizes and encrypts data elements based on user preferences and regulatory rules, allowing secure data transmission to a distributed ledger system and controlled access by target nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is made publicly auditable and verifiable in distributed ledger systems, then transparency and trust are improved, but user control over data visibility is lost and unnecessary data sharing occurs
Solution Approach 1:
The patent segments data into different types (public data, private data, confidential data) and applies different visibility controls to each segment. This allows the system to maintain public auditability for transaction validity while protecting user-controlled private and confidential information, thus resolving the contradiction between transparency and user control.
Solution Approach 2:
The patent implements local quality by allowing different data elements within the same transaction to have different visibility properties. Each data element can be independently tagged with access control metadata, enabling selective disclosure where only necessary information is publicly visible while sensitive information remains protected, achieving both transparency and user control.
2Reliability
If all transaction data is shared among parties for processing, then transaction completeness is improved, but data privacy is compromised and regulatory compliance becomes difficult
Solution Approach 1:
The patent applies preliminary action by pre-tagging data elements with access control metadata and encryption requirements before transaction processing. This allows the system to automatically enforce privacy controls and regulatory compliance during transaction execution without compromising data completeness, as the necessary data is available but protected according to pre-established rules.
Solution Approach 2:
The patent introduces an intermediary layer of smart contracts and access control mechanisms that mediate between data sharing needs and privacy protection. This intermediary enforces regulatory rules and user preferences automatically, allowing complete transaction processing while preventing unauthorized access to sensitive information through cryptographic protection and access control.
3Object-affected harmful factors
If data is encrypted and anonymized before storage, then user privacy is protected and regulatory compliance is achieved, but data accessibility and utility are reduced
Solution Approach 1:
The patent applies parameter changes by using different encryption and anonymization parameters for different data elements based on their sensitivity and access requirements. Less sensitive data may use lighter protection mechanisms while highly sensitive data receives stronger encryption, thus maintaining data accessibility and utility while providing appropriate privacy protection.
Solution Approach 2:
The patent implements dynamic access control where data accessibility changes based on user authentication, authorization context, and transaction requirements. Data elements can be dynamically decrypted and made accessible to authorized parties during transaction processing while remaining protected in storage, thus balancing privacy protection with data utility.
Data Source
AI summary
Arrangements for providing data security control functions are provided. In some aspects, a request to process a transaction may be received. The transaction request may include identification of one or more destinations or target nodes for data, transaction details, a source of the transaction, and the like. In some examples, one or more data elements may be identified and a category of each data element may be identified. One or more rules engines may be identified and executed. Based on the application of rules in the one or more rules engines, secure data elements may be generated and encrypted. The encrypted data elements may be sent to a distributed ledger system for storage. One or more notifications may be transmitted to one or more target nodes indicating that data has been sent to the distributed ledger system. The target nodes may retrieve and decrypt the data to process the transaction.


