Geo-located Provenance Metadata for Secure Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security measures do not guarantee that data is accessed or modified only in approved locations throughout its lifecycle, especially when the list of approved locations changes over time.

Innovation Solution

A computer program product that identifies target data with location requirements, obtains and verifies provenance metadata for each access instance, determines the current location of a computing device, and allows access only if it meets the established location requirements, updating the metadata with new location records.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data security measures limit data movement to predetermined locations, then data access control is improved, but the system cannot adapt when approved locations change over time

Engineering Contradiction:
Improvedata access controlVSAvoidlocation requirement flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic location requirements that can be modified over time. The system transitions from static predetermined locations to dynamic location sets that can be updated, allowing the data owner to add or remove approved locations without requiring system reconfiguration. This resolves the contradiction by making the security control adaptable to changing location requirements while maintaining reliable access control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary validation of location requirements before data access is granted. By pre-establishing location requirements and validating them against provenance metadata before allowing data operations, the system ensures reliable access control while accommodating future location changes through the update mechanism. The preliminary action establishes a framework that is both controlling and adaptable.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If provenance metadata tracks every data access location, then data integrity is improved, but system complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidmetadata management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts location tracking functionality into a separate provenance metadata structure that is independent from the core data. By separating the location provenance information from the data itself, the system maintains data integrity through comprehensive tracking while reducing overall system complexity. The metadata can be managed, validated, and updated independently without affecting the core data operations.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If the system validates location requirements for each data access, then security is improved, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess validation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary validation of location requirements and stores the validated state in provenance metadata. By pre-validating location requirements and caching the validation results, the system reduces the time required for subsequent access validations. The preliminary action establishes a trust foundation that speeds up future access decisions while maintaining security through the provenance verification framework.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11934544B2Securing data via encrypted geo-located provenance metadata
Publication Date: 2024.03.19 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US11934544B2 patent drawing
  • US11934544B2 patent drawing
  • US11934544B2 patent drawing

AI summary

Target data may be associated with a location requirement established by a data owner. A data access module may be used to attempt access to the target data. Location requirement and provenance metadata associated with the target data are obtained. The provenance metadata must be validated, and evidence only approved data access locations identified in the location requirement. A current location of a computing device attempting access to the target data must also meet the location requirement. The computing device is allowed to access the target data only in response to the current location and each location identified in the provenance metadata meeting the location requirement. The provenance metadata is updated to include a new record including the current data access location.