Policy-Based Data Management via Trust Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are reluctant to disclose private data online due to the lack of adequate solutions ensuring data privacy policy compliance, leading to concerns about how their information is treated by service providers.

Innovation Solution

A network environment involving a client, service provider, and trust authority, where the client encrypts data and sets privacy policies, which are enforced by the trust authority ensuring the service provider complies with the policies before accessing the data, using cryptographic keys and audit trails to ensure policy adherence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If users disclose private data to service providers, then data utility and service quality improve, but data privacy security deteriorates

Engineering Contradiction:
Improvedata utilityVSAvoidprivacy security risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

A trust authority is introduced as an intermediary between users and service providers. The trust authority issues cryptographic keys to service providers after verifying their policy compliance, acting as a mediator that enables data sharing while maintaining privacy security through decentralized policy enforcement

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If service providers access user data, then service quality improves, but policy compliance reliability deteriorates

Engineering Contradiction:
Improveservice qualityVSAvoidpolicy compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Policy compliance verification is performed in advance before data access is granted. The trust authority verifies service provider policies and issues cryptographic keys beforehand, ensuring compliance is established prior to any data processing activities

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements audit trails that log all data access and processing activities. These feedback mechanisms allow users and trust authorities to monitor and verify ongoing policy compliance, creating accountability through continuous observation

Inventive Principle:
Principle #23Feedback

3Ease of operation

If cryptographic keys are distributed to service providers, then data accessibility improves, but system complexity increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidkey management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The complex key management burden is extracted from individual service providers and centralized at the trust authority. The trust authority generates, secures, and distributes cryptographic keys, while service providers only need to implement simple key usage following standardized procedures

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9203621B2Policy-based data management
Publication Date: 2015.12.01 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9203621B2 patent drawing
  • US9203621B2 patent drawing
  • US9203621B2 patent drawing

AI summary

Compliance to a policy about how to treat data in a computer network environment is ensured by checking that conditions in the policy are satisfied by the entity before access to the data is provided.