Third-Party Portal Access Control for Question Delegation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of clear and enforceable mechanisms for translating non-disclosure agreement (NDA) access control requirements into technically verifiable and auditable measures, particularly for sensitive information related to third-party vendor assessments, leading to potential mishandling of data.

Innovation Solution

A method involving a third-party portal system that enforces access controls based on security policies, including time duration and user access limitations, with client-side encryption using symmetric key pairs to secure sensitive data, ensuring explicit and enforceable access control requirements between companies and third parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control requirements are specified in NDA agreements, then data security is improved, but the requirements cannot be technically enforced or verified

Engineering Contradiction:
Improvedata securityVSAvoidtechnical enforceability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces manual legal enforcement mechanisms (NDA agreements requiring human compliance monitoring) with automated technical enforcement mechanisms (encryption systems, access control lists, and policy engines that automatically enforce data access rules). This substitution transforms unenforceable legal requirements into technically enforceable constraints through cryptographic and software-based controls.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If NDA requirements are made more specific and enforceable, then data protection is improved, but the complexity of the system increases

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal policy engine and standardized data structure framework that can enforce multiple different access control requirements through a single unified system. Rather than creating separate complex mechanisms for each type of access control, the system uses universal components (policy definitions, encryption frameworks, access control lists) that can be configured to enforce various data protection requirements, thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If access controls are enforced with time duration and user limits, then data security is improved, but the difficulty of monitoring and evaluating access increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess monitoring
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements automated monitoring and evaluation systems that continuously track data access events, user identities, timestamps, and access durations. The system provides feedback by automatically comparing actual access patterns against defined security policies and generating compliance reports. This automated feedback mechanism makes it easier to detect and measure access control enforcement without manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11258603B2Access controls for question delegation environments
Publication Date: 2022.02.22 EMC IP HLDG CO LLC
  • US11258603B2 patent drawing
  • US11258603B2 patent drawing
  • US11258603B2 patent drawing

AI summary

Techniques are provided for access controls for question delegation environments. One method comprises obtaining a security policy for a question obtained from a user; monitoring responses to the question; and enforcing, by a third-party portal processing system, access controls within the security policy for data associated with the question and/or the responses to the question, wherein the access controls comprise one or more restrictions with respect to a time duration to access the data and/or a number of people that may access the data. The third-party portal processing system evaluates whether the time duration to access the data has expired before providing access to the data and/or whether the number of people that may access the data has been exceeded before providing access to the data. A client-side encryption of the data is optionally performed by a provider of the data.