Dual-Key Encryption for Third-Party Data Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data owners lose control over their data once it is provided to third-party data brokers, making them vulnerable to data exfiltration and unauthorized access, especially when the data is resold to additional parties.

Innovation Solution

Implementing a system where data is encrypted with both a data owner's key and a data broker's key, requiring both parties' approval for access, and using security appliances to manage and control access, ensuring that only authorized users can decrypt the data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is provided to third-party data brokers, then data aggregation and processing capabilities are improved, but data control and security are worsened

Engineering Contradiction:
Improvedata aggregation capabilityVSAvoiddata control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments data control into multiple independent key holders (data owner key and data broker key). Neither party alone can access the encrypted data - both keys are required simultaneously. This segmentation allows the data broker to process and aggregate data while the data owner retains control through key management, resolving the contradiction between productivity improvement and reliability maintenance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encryption as an intermediary mechanism between the data owner and data broker. The encrypted data acts as a mediator that enables the broker to work with the data without having direct access to its contents, thus improving aggregation capability while maintaining owner control through the encryption key.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If data is resold to additional parties, then data utility and reach are improved, but vulnerability to data exfiltration and unauthorized access is worsened

Engineering Contradiction:
Improvedata distribution reachVSAvoiddata exfiltration risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic access control where the data owner can modify key permissions and revoke access at any time, even after data has been shared with brokers who may have distributed it further. This dynamic control allows the system to adapt to changing security requirements and restrict access to prevent exfiltration, while still allowing broad data distribution when needed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11354439B2Content control through third-party data aggregation services
Publication Date: 2022.06.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11354439B2 patent drawing
  • US11354439B2 patent drawing
  • US11354439B2 patent drawing

AI summary

Aspects include receiving a request from a user to access data that was acquired by a third-party from a data owner, the data in an encrypted format unreadable by the user. In response to receiving the request from the user to access the data, a third-party key from the third-party is requested and a data owner key from the data owner is requested. The third-party key and the data owner key are applied to the data in the encrypted format to generate the data in an unencrypted format readable by the user. The user is provided with access to the data in the unencrypted format.