Secure Content Sharing Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in maintaining data security and control after sharing content between computing devices, as encryption alone does not ensure continued security and access management once data is decrypted and shared.

Innovation Solution

A system that enables secure content sharing by encrypting data and including a content use policy, allowing the source computing device to maintain control through secure content packages that define access and location permissions, enforced by destination devices using secure media path circuitry and policy enforcement modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If encrypted data is transmitted to another computing device for decryption, then data sharing capability is improved, but control over the data is lost and security is compromised

Engineering Contradiction:
Improvedata sharing capabilityVSAvoiddata security and control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the data protection mechanism into multiple components: encrypted content, separate usage policy, and enforced access controls. The content is divided into secure segments that can be independently controlled, allowing sharing while maintaining security through policy enforcement at the destination device

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary usage policy mechanism that mediates between the source device's security requirements and the destination device's access needs. This policy acts as a trusted intermediary that enables controlled sharing without sacrificing security, by defining and enforcing usage terms between the two devices

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If data is decrypted by the receiving computing device, then data accessibility is improved, but the risk of unauthorized modification or sharing increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized modification or sharing
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing usage policies and access controls before the data is decrypted and accessed at the destination device. The security constraints are predefined and embedded in the encrypted package, so they are in place before any decryption occurs, preventing unauthorized actions from the outset

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the destination device continuously monitors and enforces usage policies during data access. The system provides feedback loops that detect and prevent unauthorized modifications or sharing attempts, ensuring ongoing security compliance even after decryption

Inventive Principle:
Principle #23Feedback

3Reliability

If traditional encryption methods are used, then data confidentiality is improved, but post-sharing control and policy enforcement are lost

Engineering Contradiction:
Improvedata confidentialityVSAvoidpolicy enforcement capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges traditional encryption with usage policy enforcement into a unified secure data sharing system. The encrypted content and usage policies are combined into an integrated package that maintains confidentiality while adding policy control capabilities, rather than treating them as separate layers

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10068101B2Secure content sharing
Publication Date: 2018.09.04 INTEL CORP
  • US10068101B2 patent drawing
  • US10068101B2 patent drawing
  • US10068101B2 patent drawing

AI summary

Technologies for sharing secure content include a source computing device to determine a content use policy for content of the source computing device. The content use policy defines at least one location at which a destination computing device is permitted to access the content. The source computing device encrypts the content with an encryption key to generate encrypted content, generates a secure content package, and transmits the secure content package to the destination computing device. The secure content package includes the encrypted content and the content use policy.