Policy-Enabled Information Sharing System for Secure Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information sharing technologies face challenges in facilitating timely, secure, and flexible data exchange among diverse government agencies due to complexities in managing user access and dissemination, particularly in centralized databases and ad-hoc point-to-point agreements, which hinder real-time decision-making.
Innovation Solution
A policy-enabled information sharing system that utilizes a data source with visibility attributes, a source adapter, a gatekeeper, and a policy store to manage and encrypt data objects based on need-to-know policies, allowing for real-time, secure, and controlled information sharing across agencies through a communication channel, with bidirectional capabilities and flexible infrastructure support.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a central information repository is used to share information, then users are relieved from managing shared information, but users lose control over dissemination and bureaucracy becomes complex
Solution Approach 1:
The patent introduces a policy engine as an intermediary component that automatically enforces information sharing policies between the central repository and users. This mediator handles access control and dissemination rules automatically, relieving users from manual management while maintaining proper control over information flow without requiring complex bureaucratic processes
Solution Approach 2:
The system implements self-service through automated policy enforcement where the policy engine automatically determines who can access what information based on predefined policies. Users do not need manual approval or complex bureaucratic processes to share or access information - the system automatically enforces the rules, reducing both user burden and administrative complexity
2Ease of manufacture
If point-to-point bi-lateral information sharing agreements are used, then information sharing is simple to establish, but the approach is ad-hoc, prone to mistakes, and fails to leverage infrastructure investments
Solution Approach 1:
The patent creates a universal information sharing infrastructure with standardized policies and a central repository that can serve multiple agencies and purposes. Instead of separate point-to-point agreements for each information exchange, a single standardized system handles diverse information sharing needs reliably, leveraging infrastructure investments across multiple uses while maintaining consistency and reducing errors
Solution Approach 2:
The system uses parameter-based policies that define information sharing rules in terms of configurable parameters (access levels, user roles, information types). This allows the system to adapt to different information sharing scenarios through parameter configuration rather than requiring new agreements, maintaining reliability while being flexible enough to handle various needs
3Reliability
If barriers are constructed to prevent unauthorized use and dissemination of information, then information security is improved, but information sharing is delayed or blocked
Solution Approach 1:
The patent implements preliminary action by pre-defining information sharing policies that specify who can access what information under what conditions. These policies are established in advance, so when information needs to be shared, the system can automatically enforce the pre-established rules without delays. Security barriers are already in place through the policy framework, eliminating the need for real-time authorization delays
Solution Approach 2:
The policy engine provides automatic feedback by continuously monitoring information access requests against predefined policies. When a request complies with the policy, access is granted immediately; when it violates the policy, access is denied. This automated feedback mechanism maintains security while enabling rapid legitimate information sharing without manual intervention delays
Data Source
AI summary
A technique for dynamically sharing information includes executing a sharing policy indicating when to share a data object responsive to the occurrence of an event. The data object is created by formatting a data file to be shared with a receiving entity. The data object includes a file data portion and a sharing metadata portion. The data object is encrypted and then automatically transmitted to the receiving entity upon occurrence of the event. The sharing metadata portion includes metadata characterizing the data file and referenced in connection with the sharing policy to determine when to automatically transmit the data object to the receiving entity.


