Secure Data Corridors for Decentralized Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In decentralized computing environments, traditional security measures face challenges in maintaining latency, scalability, and recovery performance due to increased complexity and separation of authentication, authorization, and auditing functions, leading to high costs and potential security vulnerabilities.

Innovation Solution

The implementation of a secure data corridor that uses a communication channel with dynamic security measures, including data sensitivity ratings and control parameters, to ensure secure data transmission and access control, integrating risk and auditing functions at the system level.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are implemented in decentralized computing environments, then security protection is provided, but latency, scalability, and recovery performance are impacted

Engineering Contradiction:
Improvesecurity protectionVSAvoidlatency and scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments security functions into distributed security modules deployed across multiple nodes in the decentralized computing environment. Each node independently enforces security policies, eliminating the need for centralized security validation that would cause latency. This segmentation allows parallel security processing across nodes, maintaining both security protection and scalability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic security policies that adapt to the decentralized environment's changing conditions. Security measures are adjusted in real-time based on node status, data sensitivity, and threat levels, allowing the system to maintain security protection while optimizing performance characteristics like latency and scalability according to current operational requirements.

Inventive Principle:
Principle #15Dynamics

2Reliability

If security functions are separated into authentication, authorization, and auditing, then specialized security control is achieved, but system complexity and costs increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal security modules that perform multiple security functions (authentication, authorization, and auditing) within a single integrated component. Each security module is designed to handle all three functions simultaneously, reducing the number of separate components needed and simplifying the overall system architecture while maintaining specialized security control for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the separated security functions into a unified security enforcement mechanism at each node. Rather than maintaining distinct authentication, authorization, and auditing systems, the patent combines them into an integrated security layer that processes all three functions together, reducing system complexity and synchronization overhead while preserving specialized control capabilities.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If static permission mapping is used in file systems, then simple access control is provided, but the system is blind to data sensitivity and risk controls

Engineering Contradiction:
Improveaccess controlVSAvoiddata sensitivity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the parameters of access control from static permission mappings to dynamic, data-aware security decisions. Security modules evaluate multiple parameters including data sensitivity labels, user context, and risk assessments in real-time, transforming simple static access control into an adaptive system that maintains ease of operation while providing reliable data sensitivity protection through contextual awareness.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10432642B2Secure data corridors for data feeds
Publication Date: 2019.10.01 T MOBILE US INC
  • US10432642B2 patent drawing
  • US10432642B2 patent drawing
  • US10432642B2 patent drawing

AI summary

A system and method of providing a secure data corridor are provided. A request from a subject for at least one data element of a data feed is received. A use-case is identified for the data feed. A security label is assigned to the use-case. A clearance of the subject is compared to the security label of the use-case. Upon determining that a clearance of the subject is at or above the data sensitivity rating of the use-case, the subject is allowed access privilege to the data feed via the secure data corridor.