Policy-Based Data Management via Trust Authority Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are reluctant to disclose private data online due to the lack of adequate solutions ensuring data privacy policy compliance, leading to concerns about how their information is treated by service providers.

Innovation Solution

A network environment involving a client, service provider, and trust authority, where the client generates and encrypts privacy policies, and the trust authority ensures compliance by providing cryptographic keys only after verifying the service provider's assurance of policy adherence, using cryptographic protocols like PKI and IBE to secure data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If users disclose private data to service providers, then data can be accessed and used for services, but data privacy policy compliance cannot be ensured

Engineering Contradiction:
Improvedata access efficiencyVSAvoidprivacy policy compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a trust authority as an intermediary between users and service providers. The trust authority verifies service provider credentials and enforces privacy policies, acting as a mediator that enables data access while ensuring compliance. This resolves the contradiction by allowing productive data sharing while maintaining reliable policy enforcement through the intermediary's verification and monitoring functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by requiring service providers to obtain verification credentials from the trust authority before accessing user data. Privacy policies are established and encrypted in advance, and service providers must prove their compliance capability before data disclosure. This preliminary enforcement ensures policy compliance is built into the system before data access occurs, resolving the trust issue while enabling efficient data utilization.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If service providers access encrypted data, then data utility is improved, but security risk increases

Engineering Contradiction:
Improvedata utilityVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by encrypting data with different keys for different service providers and differentiating access permissions on a per-provider basis. Each service provider receives only the specific decryption credentials needed for their authorized operations, not universal access. This allows data utility for each provider while minimizing security risk by limiting exposure to only what is necessary for their specific service function.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The trust authority implements continuous feedback monitoring of service provider data access and usage. The system tracks whether providers are using data according to their verified credentials and privacy policies, providing ongoing feedback that enables detection and correction of compliance deviations. This feedback mechanism maintains security while allowing productive data access by actively monitoring and enforcing proper usage.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9628516B2Policy-based data management
Publication Date: 2017.04.18 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9628516B2 patent drawing
  • US9628516B2 patent drawing
  • US9628516B2 patent drawing

AI summary

Compliance to a policy about how to treat data in a computer network environment is ensured by checking that conditions in the policy are satisfied by the entity before access to the data is provided.