Dynamic Resource Allocation for Context-Aware Privacy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Dynamic allocation of computing resources in networked systems poses challenges in ensuring privacy enforcement, as existing methods are based on static assumptions that do not account for varying geographical and contextual factors, leading to inadequate protection of confidential data.

Innovation Solution

A method and system for dynamically allocating computing resources that involve selecting resources based on contextual information, encrypting data, and using a trusted privacy service to enforce privacy policies by decrypting data only on compliant resources, ensuring compliance with location-specific privacy laws and policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static privacy management methods are used in networked computer systems, then implementation simplicity is maintained, but privacy protection adequacy deteriorates due to inability to account for varying geographical and contextual factors

Engineering Contradiction:
Improveprivacy protection adequacyVSAvoidprivacy management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic privacy management by transitioning from static privacy policies to context-aware dynamic policies that adapt based on geographical location, device characteristics, and data sensitivity. The system continuously evaluates contextual factors and adjusts privacy enforcement accordingly, ensuring adequate protection across varying environments without requiring complete system redesign.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies local quality by implementing location-specific privacy policies that tailor protection measures to geographical jurisdictions and their specific legal requirements. Different regions receive customized privacy enforcement based on local laws and regulations, while the overall system maintains a unified architecture that manages these diverse local requirements.

Inventive Principle:
Principle #3Local quality

2Reliability

If dynamic resource allocation is implemented based on contextual information, then privacy policy compliance is improved, but resource selection and verification complexity increases

Engineering Contradiction:
Improveprivacy policy complianceVSAvoidresource selection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-establishing privacy policies, contextual information requirements, and resource verification criteria before data transmission occurs. Resources are pre-screened and categorized based on their privacy compliance capabilities, allowing the system to quickly match data with appropriate resources during dynamic allocation without performing complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary privacy management component that acts as a mediator between data sources and processing resources. This intermediary evaluates contextual information, selects appropriate privacy policies, verifies resource compliance, and facilitates matching between data and suitable resources, thereby reducing the complexity burden on the overall system while ensuring policy adherence.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If data is encrypted and decrypted only on compliant resources, then data security is improved, but processing time increases due to key management and decryption overhead

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing encryption schemes, key management protocols, and identifying compliant resources before data transmission. Encryption keys are pre-distributed to authorized resources, and decryption capabilities are pre-configured, allowing rapid decryption upon data arrival without time-consuming key exchange or setup procedures during actual processing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9137113B2System and method for dynamically allocating resources
Publication Date: 2015.09.15 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9137113B2 patent drawing
  • US9137113B2 patent drawing
  • US9137113B2 patent drawing

AI summary

A computer network has a number of resources. One or more trusted localization provider certifies the location of the resources. Encrypted data is closely associated with a policy package defining privacy policies for the data and metapolicies for their selection. A trusted privacy service enforces the privacy policies. The trusted privacy service is arranged to supply a key to a resource to allow that resource to process data if the trusted privacy service determines from the trusted localization provider certifying the location and other contextual information of the resource that the privacy policy allows processing of the data on that resource in that location.