Policy Filter Data Flow Control for Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing systems lack effective control over data flow and security, particularly in ensuring the integrity and privacy of data as it is processed and transmitted between interconnected modules, leading to potential leaks and unauthorized access.

Innovation Solution

A data processing apparatus and method that incorporates an input policy filter, processing environment, and output policy filter, along with a management environment to manage provenance and attestation, ensuring secure data flow by forwarding data and provenance based on predefined policies, including input and output policies that restrict data based on source, type, and target, and utilizing cryptographic signatures for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is freely transmitted between interconnected modules, then system productivity and ease of operation are improved, but security and data integrity deteriorate due to potential leaks and unauthorized access

Engineering Contradiction:
Improvedata flow efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces policy filters as intermediary components between data sources and processing environments. These filters act as mediators that inspect, control, and regulate data flow according to predefined policies, allowing secure data transmission while maintaining system productivity. The input policy filter controls data entering the processing environment, and the output policy filter controls data leaving it, ensuring security without blocking legitimate data flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict security controls are implemented to prevent unauthorized access, then data security is improved, but system complexity and ease of operation worsen

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the data processing system into distinct functional components: input policy filter, processing environment, and output policy filter. Each component has a specific responsibility for security or processing, which simplifies the overall system architecture. By dividing security controls into modular policy filters rather than implementing monolithic security mechanisms, the system achieves strong security with manageable complexity.

Inventive Principle:
Principle #1Segmentation

3Reliability

If data provenance tracking is implemented to ensure integrity, then data reliability is improved, but processing time and system complexity worsen

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements provenance tracking by preliminarily assigning unique identifiers to data at the input policy filter before data enters the processing environment. This preliminary action establishes the data's origin and journey early in the process, enabling efficient tracking without requiring complex real-time analysis during processing. The output policy filter then uses these pre-established identifiers to verify data integrity, significantly reducing processing overhead compared to post-processing verification methods.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12086253B2Attestation of processing
Publication Date: 2024.09.10 ARM IP
  • US12086253B2 patent drawing
  • US12086253B2 patent drawing
  • US12086253B2 patent drawing

AI summary

There is provided a data processing apparatus that includes an input policy filter that receives input data and an input provenance that relates to the input data. The filter forwards some or all of the input data and the input provenance according to at least one input policy. A processing environment receives the input data forwarded by the input policy filter and processes the input data to generate output data. A management environment produces an attestation of the processing environment and produces an output provenance based on the input provenance and the attestation. An output policy filter receives the output data and the output provenance and forwards the output data and the output provenance according to at least one output policy.