Multi-Provider Data Vaults for Permission-Based Local Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to provide secure and separate access to data from multiple data providers on a single computer platform, where data access is controlled by permissions from each provider, especially in scenarios involving travel-related applications.

Innovation Solution

A computer platform with separate data vaults for different data providers, using distinct encryption keys to store and manage encrypted data, allowing decryption based on provider permissions, and enabling local data processing to reduce network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data from multiple data providers is stored on a single computer platform, then data accessibility and local processing capability are improved, but data security and isolation between providers deteriorate

Engineering Contradiction:
Improvedata processing capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system divides the storage space into separate data vaults, with each vault dedicated to a specific data provider. This segmentation ensures that data from different providers remains isolated while being accessible locally on the same computer platform, thus maintaining both security and processing capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component that manages encryption keys and controls access to encrypted data. This intermediary enables secure retrieval and processing of data from multiple providers without compromising the isolation and security of each provider's data vault.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate storage structures are created for each data provider, then data security and provider isolation are improved, but system complexity and storage overhead increase

Engineering Contradiction:
Improveprovider isolationVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple encrypted data vaults into a single unified storage structure on the computer platform. This combining approach maintains provider isolation through encryption and separate vault boundaries while simplifying the overall system architecture compared to completely separate storage systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified storage structure serves multiple functions: it stores data from different providers, maintains security isolation, enables local processing, and manages encryption keys centrally. This multi-functionality reduces system complexity while maintaining provider isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If data is encrypted with provider-specific keys, then data security and access control are improved, but decryption and data retrieval complexity increase

Engineering Contradiction:
Improveaccess controlVSAvoiddecryption process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service mechanisms where the intermediary automatically manages encryption key storage, retrieval, and application. This automation reduces the manual complexity of handling multiple provider-specific encryption keys while maintaining strict access control and security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4625878A1Separately and securely processing data associated with different data providers
Publication Date: 2025.10.01 AMADEUS SAS
  • EP4625878A1 patent drawingFigure 1
  • EP4625878A1 patent drawingFigure 2
  • EP4625878A1 patent drawingFigure 3

AI summary

A computer platform for separately and securely processing data associated with different data providers is provided. The computer platform comprises a first and second data vault, and a plurality of applications. The computer platform is arranged to: store first encryption key(s) associated with the first data provider and encryption key(s) associated with the second data provider, receive first/second encrypted data associated with a first/second data provider, wherein the first/second encrypted data is encrypted using the first/second encryption key(s), store the first/second encrypted data on the respective first/second data vault, decrypt the first/second encrypted data stored on the first/second data vault using the respective first/second encryption key(s) to obtain respective first decrypted data and second decrypted data, decide to provide the first/second decrypted data from the first/second data vault to a first and/or second application on the computer platform, depending on permissions of the first/second data provider.