Secure Data Analysis Safebox Mediates Access Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data analysis on sensitive information poses risks of accidental or intentional disclosure, as well as concerns about the handling competence of analysis providers, necessitating secure processing methods that protect both analytical software and datasets.

Innovation Solution

A secure data analysis system, referred to as a 'safebox,' mediates access rules between analysis and data providers, executes analysis software on sensitive datasets while constraining access, and sanitizes itself after completion, ensuring secure communication and deletion of sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is shared with analysis providers for processing, then data analysis can be performed, but the risk of information disclosure increases

Engineering Contradiction:
Improvedata analysis capabilityVSAvoidinformation disclosure risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted third-party intermediary system that mediates between data providers and analysis providers. This intermediary securely receives sensitive data, controls access during analysis, and manages data deletion afterward, enabling analysis while preventing disclosure risks through controlled intermediation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the data analysis process into distinct phases: data submission, controlled processing with access rules, and post-analysis deletion. Each phase is managed separately with specific security controls, allowing productivity while mitigating risks at each stage

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If analysis software is provided by external providers, then analytical capabilities are enhanced, but trust in handling competence is reduced

Engineering Contradiction:
Improveanalytical capabilityVSAvoidhandling competence trust
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where data providers can verify that their data was handled according to agreed rules, and analysis providers receive feedback on compliance. This builds reliability through verifiable behavior rather than blind trust

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The trusted intermediary acts as a mediator that verifies the competence and behavior of analysis providers, ensuring they follow agreed-upon handling rules while still providing access to enhanced analytical capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access control rules are enforced during data processing, then data security is improved, but analysis flexibility is reduced

Engineering Contradiction:
Improvedata securityVSAvoidanalysis flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The access control system is designed to be dynamic rather than static. Access rules can be adjusted during the analysis process based on verification results and compliance monitoring, allowing flexibility while maintaining security through adaptive control

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11734439B2Secure data analysis
Publication Date: 2023.08.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11734439B2 patent drawing
  • US11734439B2 patent drawing
  • US11734439B2 patent drawing

AI summary

Methods and systems for secure data analysis include determining that analysis provider access rules and data provider access rules are compatible. Analysis software is received from an analysis provider and a dataset is received from a data provider. The analysis software is executed on the dataset to generate an analysis output, with access to data in the dataset being constrained by the analysis provider access rules and the data provider access rules. An output of the analysis is sent to the analysis provider.