Export-Controlled Data Access via Encrypted Indexing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current corporate information management systems face challenges in efficiently managing export-controlled data, particularly in ensuring compliance with export regulations and protecting sensitive information from unauthorized access.
Innovation Solution
The implementation of an export-controlled corporate asset infrastructure that includes a plurality of controlled item storage systems and an export review management system, which assists in assigning vendor access to zones and managing export compliance through rigorous factor consideration and programmable export policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is used to protect valuable information in a database, then data security is improved, but data accessibility and search efficiency deteriorate
Solution Approach 1:
The patent introduces an intermediary mechanism (encrypted index structure) that mediates between the encrypted data and search queries. The index stores encrypted or hashed versions of search terms that can be compared against encrypted data without requiring full decryption, enabling efficient search while maintaining security.
Solution Approach 2:
The patent segments the data protection approach by applying encryption selectively to different parts of the data structure. Rather than encrypting entire databases uniformly, it encrypts specific fields, indexes, or portions of data that require protection while leaving other portions accessible, enabling differentiated access control and efficient querying of non-sensitive data.
2Reliability
If comprehensive export control review processes are implemented, then compliance reliability is improved, but operational efficiency and time consumption worsen
Solution Approach 1:
The patent implements preliminary action by establishing export control classification numbers and compliance criteria in advance during data ingestion and metadata creation. This allows the system to automatically evaluate export control requirements before actual data sharing or transfer operations, eliminating the need for time-consuming manual reviews during operational phases.
Solution Approach 2:
The patent incorporates feedback mechanisms where the system automatically evaluates data against stored export control criteria and classification numbers, providing real-time compliance feedback. This automated evaluation loop enables the system to identify and flag potential export control violations without requiring manual intervention, maintaining high compliance reliability while preserving operational efficiency.
3Measurement precision
If manual export review processes are used to assess vendor access, then access control precision is improved, but system complexity and processing time worsen
Solution Approach 1:
The patent enables self-service by designing a system where vendor access rights are automatically determined based on pre-configured export control classification numbers and compliance criteria. The system autonomously evaluates vendor requests against stored policies and automatically grants or denies access without requiring manual review, reducing system complexity while maintaining precise access control through rule-based automation.
Data Source
AI summary
Encrypted export controlled items within a corporate asset infrastructure may be searched for vendor access. Different versions of an export policy may change the ways in which the search is performed based on calculation of a numerical representation of a classification to identify the best forwarding location for a vendor access that is not subject to a Restricted Destination List. An indexing value may be determined, transparently with respect to a vendor, based on a desired plaintext item of data and a redacted technical data list. The indexing value may be used to access an entry in an indexing structure to obtain a corresponding document-oriented record which includes an encrypted ciphertext item. Positions of items of the indexing structure may be based on corresponding plaintext items.


