Dual-Key Encryption for Third-Party Data Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data owners lose control over their data once it is provided to third-party data brokers, making them vulnerable to data exfiltration and unauthorized access, especially when the data is resold to additional parties.
Innovation Solution
Implementing a system where data is encrypted with both a data owner's key and a data broker's key, requiring both parties' approval for access, and using security appliances to manage and control access, ensuring that only authorized users can decrypt the data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is provided to third-party data brokers, then data aggregation and processing capabilities are improved, but data control and security are worsened
Solution Approach 1:
The patent segments data control into multiple independent key holders (data owner key and data broker key). Neither party alone can access the encrypted data - both keys are required simultaneously. This segmentation allows the data broker to process and aggregate data while the data owner retains control through key management, resolving the contradiction between productivity improvement and reliability maintenance.
Solution Approach 2:
The patent introduces encryption as an intermediary mechanism between the data owner and data broker. The encrypted data acts as a mediator that enables the broker to work with the data without having direct access to its contents, thus improving aggregation capability while maintaining owner control through the encryption key.
2Adaptability or versatility
If data is resold to additional parties, then data utility and reach are improved, but vulnerability to data exfiltration and unauthorized access is worsened
Solution Approach 1:
The patent implements dynamic access control where the data owner can modify key permissions and revoke access at any time, even after data has been shared with brokers who may have distributed it further. This dynamic control allows the system to adapt to changing security requirements and restrict access to prevent exfiltration, while still allowing broad data distribution when needed.
Data Source
AI summary
Aspects include receiving a request from a user to access data that was acquired by a third-party from a data owner, the data in an encrypted format unreadable by the user. In response to receiving the request from the user to access the data, a third-party key from the third-party is requested and a data owner key from the data owner is requested. The third-party key and the data owner key are applied to the data in the encrypted format to generate the data in an unencrypted format readable by the user. The user is provided with access to the data in the unencrypted format.


