Secure Device Relay Using Smart Intermediary for Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data exchange systems lack secure mechanisms to control access to sensitive data, particularly in scenarios involving data collection devices and servers, which poses risks to user privacy and data integrity.
Innovation Solution
A secure device relay system that uses a smart device to transmit a unique identifier and digital signature to a server, receives a key pair and exchange configuration, and manages access control by determining if data exchange requests are permitted based on predefined conditions, notifying users or physicians if access is denied, and modifying access controls with user consent.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data exchange between data collection device and server is enabled, then data accessibility and functionality are improved, but data security and user privacy protection deteriorate
Solution Approach 1:
A smart device intermediary is introduced between the data collection device and server. The smart device receives exchange requests, validates them against stored exchange configurations, and only permits data exchange when conditions are met. This intermediary layer enables data accessibility while maintaining security by filtering and controlling all data exchange operations.
Solution Approach 2:
Exchange configurations including access control rules, conditions, and triggers are pre-established and stored on the smart device before any data exchange occurs. The system performs preliminary validation of exchange requests against these pre-configured rules, ensuring that only authorized data exchanges are permitted while maintaining security constraints.
2Object-affected harmful factors
If access control mechanisms are implemented for data exchange, then data security is improved, but system complexity increases
Solution Approach 1:
The access control system is segmented into distinct components: exchange configurations stored on the smart device, validation logic in the application, and predefined conditions/triggers. This segmentation allows the complex security functionality to be distributed and managed in modular units, reducing overall system complexity while maintaining comprehensive access control.
3Object-affected harmful factors
If granular access control over data type, amount, and frequency is implemented, then data privacy protection is improved, but device complexity increases
Solution Approach 1:
The exchange configurations implement local quality by defining specific access control rules for different data types, amounts, and frequencies. Each data category can have its own tailored access rules stored on the smart device, allowing granular privacy protection for sensitive data while simplifying access for less sensitive data, thereby managing complexity through differentiated control.
4Object-affected harmful factors
If user consent mechanisms are required for data exchange, then user privacy control is improved, but data exchange efficiency deteriorates
Solution Approach 1:
The system uses periodic triggers and conditions defined in the exchange configurations to automate user consent requests. Instead of requiring manual consent for every single data exchange, the system periodically checks predefined conditions (such as time intervals, data types, or exchange frequencies) and automatically processes exchanges when conditions are met, maintaining user privacy control while improving efficiency.
Data Source
AI summary
Embodiments of the present invention disclose a method, a computer program product, and a computer system for providing a secure device relay between a data collection device and a server using a smart device. The present invention comprises transmitting to a server a unique identifier corresponding to a data collection device and a digital signature corresponding to a smart device. In addition, the present invention provides for receiving from the server a key pair and an exchange configuration defining access control to data stored on the data collection device. Moreover, the present invention includes transmitting to the data collection device a public key of the received key pair and the exchange configuration.


