Data Sharing Resource Restriction via Trusted Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In data sharing systems, existing technologies fail to effectively restrict access to data beyond initial permission, allowing unauthorized use or excessive data access even after initial access controls are bypassed, particularly when security protocols are subverted.
Innovation Solution
A data sharing system comprising a trust engine, access engine, procedure engine, restriction engine, monitor engine, and control engine that restricts data access based on resource limitations and trust levels, ensuring secure data usage by limiting CPU cycles and other resources within a trusted environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control parameters are used to control data access, then authorized sharees can access data views, but security protocols can be subverted allowing unauthorized use or excessive data access
Solution Approach 1:
The patent applies preliminary action by pre-establishing a trusted environment with embedded resource restrictions before data access occurs. The restriction on resource utilization (e.g., CPU cycles) is configured in advance as part of the data sharing setup, so that even if access control parameters are bypassed, the pre-configured resource limits prevent unauthorized or excessive data access. This resolves the contradiction by providing security through pre-configured constraints rather than relying solely on complex access control protocols.
2Reliability
If resource utilization restrictions are imposed on procedures accessing data, then unauthorized data access is prevented even if security protocols are breached, but the system complexity increases
Solution Approach 1:
The patent introduces an intermediary trusted environment that sits between the data source and the accessing procedure. This trusted environment mediates all data access by enforcing pre-configured resource restrictions (such as limiting CPU cycles) on procedures. The intermediary approach simplifies the overall system architecture compared to implementing complex security protocols throughout, while providing robust data protection. The trusted environment acts as a single point of control that prevents unauthorized access even when security protocols are subverted.
3Adaptability or versatility
If access controls allow sharees to view data views, then data sharing functionality is enabled, but sharees can use data without further control from sharers
Solution Approach 1:
The patent applies dynamics by implementing dynamic resource restriction enforcement during data access operations. The trusted environment continuously monitors and enforces resource utilization limits (e.g., CPU cycle constraints) on procedures accessing shared data. This dynamic control mechanism maintains data sharing versatility while ensuring that sharees cannot exceed predetermined resource limits, providing ongoing control over data usage rather than static permission-based access. The system adapts resource allocation in real-time based on the trusted environment's enforcement of restrictions.
Data Source
AI summary
In one implementation, a data sharing system can comprise a trust engine to identify an environment that satisfies a level of trust, an access engine to request access to a set of data, a procedure engine to receive a procedure, a restriction engine to receive a restriction associated with a resource of the environment, a monitor engine to maintain resource utilization information, and a control engine to limit execution of the procedure based on the restriction and the resource utilization information. In another implementation, a method for sharing a set of data can comprise validating an environment satisfies a level of trust, receiving a restriction associated with a resource of the environment, receiving a procedure to access the set of data, ascertaining resource utilization information, and providing a view of the set of data based on the restriction and the resource utilization information.


