Private Data Area Information Sharing via Invocation Framework
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic device architectures face challenges in securely sharing information between processing entities while maintaining data integrity and confidentiality, as not all architectures are inherently friendly to information sharing, especially when system security is involved.
Innovation Solution
The solution involves an apparatus and method that allows direct data transfer from one processing entity's private data area to another without using an intervening shared data area or invoking a system administrator, utilizing an invocation framework to manage the transfer and provide secure access through pre-populated directories with one-to-one correspondence to predetermined recipients.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If an intervening shared data area is used for information sharing between processing entities, then the ease of information sharing is improved, but the data integrity and confidentiality are compromised
Solution Approach 1:
The patent employs the invocation framework as an intermediary mechanism that enables direct data transfer between private data areas without requiring a shared data area. The framework acts as a mediator that coordinates the transfer while maintaining security boundaries, allowing processing entities to share information directly through controlled access rather than through a public shared space.
Solution Approach 2:
The patent extracts the shared data area from the information sharing process entirely. Instead of relying on a common shared space, the system enables direct点对点 (point-to-point) data transfer between private data areas of different processing entities, removing the intermediary shared storage component that compromises security.
2Reliability
If a system administrator-like entity is invoked to manage data sharing, then the security control is improved, but the device complexity and operational overhead increase
Solution Approach 1:
The invocation framework enables processing entities to autonomously share data between their private data areas without requiring system administrator intervention. The framework provides self-service capabilities where entities can directly invoke data transfer operations, automatically managing security and access control without human administrative overhead.
Solution Approach 2:
The invocation framework serves as an automated intermediary that replaces the need for system administrator-like entities. It handles security control, access management, and data transfer coordination automatically through programmed frameworks, eliminating the need for manual administrative intervention while maintaining security.
3Productivity
If direct data transfer between private data areas is implemented, then the productivity is improved, but the security risks increase
Solution Approach 1:
The invocation framework acts as a secure intermediary layer that enables direct data transfer while mitigating security risks. It provides controlled access mechanisms, authentication, and authorization checks during the direct transfer process, allowing high-speed data exchange without exposing private data areas to unauthorized access.
Solution Approach 2:
The patent implements localized security measures within the invocation framework that apply specific security controls to each data transfer operation. Different security policies can be applied to different processing entities or data types, providing tailored security protection that enables direct transfer while managing risks through context-aware security enforcement.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
Information is shared between processing entities that each have a corresponding private data area by placing data corresponding to information for a first one of the private data areas for a first one of the processing entities directly into a second one of the private data areas for a second one of the processing entities without placing the data in an intervening shared data area and without directly invoking a system administrator-like entity. In addition, these private data areas can be pre-populated with a plurality of directories that each have a one-to-one correspondence to a particular predetermined information recipient and then providing a link to a given one of the recipients as corresponds to a given one of the directories when information is placed in that directory to provide the corresponding predetermined information recipient with at least read access to the information.