Encrypted Personal Data Release via Policy-Based Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in controlling and securing the release of their personal data when requested by various entities, as it is vulnerable to security threats during transmission and often shared without consent, leading to privacy concerns and lack of accountability.

Innovation Solution

A system that encrypts personal data and manages its release based on established policies, using decryption keys only when the user agrees to share it, with features like hierarchical encryption and watermarking to track and control access, ensuring secure and controlled dissemination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If personal data is transmitted to applications, then the application can access and use the data, but the data becomes vulnerable to security threats and unauthorized sharing

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by encrypting personal data before transmission to applications. The encryption occurs in advance, so that even if data is intercepted during transmission, it remains protected. The decryption keys are only released after user consent is obtained, ensuring security is maintained throughout the data lifecycle.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (encryption/decryption key management system) between the data and the application. This intermediary controls access to the data by managing decryption keys, allowing the system to balance data accessibility with security. The intermediary ensures that applications can only access decrypted data when proper authorization is verified.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If personal data is shared with multiple entities, then the data can be utilized in various contexts, but user consent and accountability are compromised

Engineering Contradiction:
Improvedata utilizationVSAvoidaccountability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary action by obtaining user consent before releasing decryption keys to any application. This advance authorization ensures that every data sharing event is pre-approved by the user, maintaining accountability even as data is shared across multiple entities for different purposes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms by tracking and recording which applications receive decryption keys and when. This feedback loop allows users to monitor data dissemination and maintain awareness of where their personal data is being shared, thereby preserving accountability in multi-entity data sharing scenarios.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If decryption keys are provided to applications, then data can be decrypted and accessed, but security control is reduced

Engineering Contradiction:
Improvedata accessVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies dynamics by making decryption key availability conditional and changeable based on user consent. Rather than providing static, permanent access, the system dynamically controls key release based on real-time user authorization. This allows easy data access when consent is given while maintaining security control when consent is withheld or revoked.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10411892B2Providing encrypted personal data to applications based on established policies for release of the personal data
Publication Date: 2019.09.10 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10411892B2 patent drawing
  • US10411892B2 patent drawing
  • US10411892B2 patent drawing

AI summary

A request is received for personal data associated with a user from an application. One or more policies are established for release of the requested personal data. The requested personal data is provided to the application in encrypted form. One or more decryption keys are then sent to the application in accordance with the established policies, the one or more decryption keys being utilizable for decrypting the encrypted personal data.