Decentralized Data Sharing with Enforced Usage Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data providers are hesitant to share their data due to concerns over losing control, as existing methods lack effective enforcement of data usage policies, leading to potential violations and costly legal proceedings, especially under regulations like GDPR.
Innovation Solution
A decentralized data sharing system that enforces data usage control by determining availability of data inputs and interpreting policies to execute atomic actions, such as dispatching analytics tasks to remote domains for execution, ensuring data remains within specified domains and adheres to usage constraints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is shared from data providers to data consumers, then data value and revenue potential increase, but data control and security are compromised
Solution Approach 1:
The patent introduces a decentralized policy enforcement mechanism that acts as an intermediary between data providers and data consumers. This mechanism includes policy interpretation components that translate high-level data usage policies into executable atomic actions, and enforcement points that monitor and control data access without requiring centralized trust. The intermediary enables data sharing while maintaining provider control through automated policy compliance checking.
Solution Approach 2:
The patent segments the data sharing control into multiple independent components: policy definition, policy interpretation, atomic action generation, and enforcement points. Each component operates independently but coordinates through standardized interfaces. This segmentation allows the system to enforce data control policies distributed across multiple domains without requiring a single centralized authority, thus maintaining both data value and control.
2Reliability
If data usage policies are enforced through legal agreements, then data provider control is maintained, but enforcement costs and complexity increase
Solution Approach 1:
The patent replaces the mechanical/legal enforcement system with an automated technical enforcement mechanism. Instead of relying on legal proceedings and manual compliance monitoring, the system uses automated policy interpretation engines that translate legal-style data usage agreements into machine-executable constraints. Enforcement points automatically monitor data access and trigger compliance violations without human intervention, dramatically reducing enforcement complexity and cost.
Solution Approach 2:
The patent implements self-service enforcement where the data sharing system automatically monitors and enforces its own policies without requiring external legal intervention. The policy enforcement mechanism includes built-in compliance checking, automated violation detection, and self-correcting capabilities that allow the system to maintain data control autonomously, eliminating the need for costly external enforcement mechanisms.
3Ease of operation
If data is shared without control mechanisms, then data accessibility and utility improve, but policy violations and legal risks increase
Solution Approach 1:
The patent implements preliminary action by establishing policy enforcement mechanisms before data sharing occurs. The system pre-defines data usage policies, pre-translates them into executable constraints, and pre-configures enforcement points at data access boundaries. This preliminary setup ensures that policy compliance is automatically checked before any data access operation, preventing violations rather than detecting them afterward, thus maintaining both accessibility and security.
Data Source
AI summary
Systems and methods for controlling data usage in a distributed environment among multiple entity domains. A method include steps of: receiving, in a local entity domain, a data consuming application comprising or identifying at least a first analytics task, wherein the first analytics task processes data inputs to produce first output data; determining availability of the data inputs; interpreting data usage policies, or data control policies, to determine atomic actions to be executed, wherein at least one of the data usage policies indicates that one of the data inputs for the first analytics task must remain in a remote entity domain; and executing the atomic actions, wherein the atomic actions include dispatching the first analytics task to the remote entity domain for remote execution of the first analytics task and receiving the first output data of the first analytics task from the remote entity domain.


