Secure Device Relay Using Smart Intermediary for Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data exchange systems lack secure mechanisms to control access to sensitive data, particularly in scenarios involving data collection devices and servers, which poses risks to user privacy and data integrity.

Innovation Solution

A secure device relay system that uses a smart device to transmit a unique identifier and digital signature to a server, receives a key pair and exchange configuration, and manages access control by determining if data exchange requests are permitted based on predefined conditions, notifying users or physicians if access is denied, and modifying access controls with user consent.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data exchange between data collection device and server is enabled, then data accessibility and functionality are improved, but data security and user privacy protection deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A smart device intermediary is introduced between the data collection device and server. The smart device receives exchange requests, validates them against stored exchange configurations, and only permits data exchange when conditions are met. This intermediary layer enables data accessibility while maintaining security by filtering and controlling all data exchange operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Exchange configurations including access control rules, conditions, and triggers are pre-established and stored on the smart device before any data exchange occurs. The system performs preliminary validation of exchange requests against these pre-configured rules, ensuring that only authorized data exchanges are permitted while maintaining security constraints.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If access control mechanisms are implemented for data exchange, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The access control system is segmented into distinct components: exchange configurations stored on the smart device, validation logic in the application, and predefined conditions/triggers. This segmentation allows the complex security functionality to be distributed and managed in modular units, reducing overall system complexity while maintaining comprehensive access control.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If granular access control over data type, amount, and frequency is implemented, then data privacy protection is improved, but device complexity increases

Engineering Contradiction:
Improvedata privacy protectionVSAvoidaccess control complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The exchange configurations implement local quality by defining specific access control rules for different data types, amounts, and frequencies. Each data category can have its own tailored access rules stored on the smart device, allowing granular privacy protection for sensitive data while simplifying access for less sensitive data, thereby managing complexity through differentiated control.

Inventive Principle:
Principle #3Local quality

4Object-affected harmful factors

If user consent mechanisms are required for data exchange, then user privacy control is improved, but data exchange efficiency deteriorates

Engineering Contradiction:
Improveuser privacy controlVSAvoiddata exchange efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system uses periodic triggers and conditions defined in the exchange configurations to automate user consent requests. Instead of requiring manual consent for every single data exchange, the system periodically checks predefined conditions (such as time intervals, data types, or exchange frequencies) and automatically processes exchanges when conditions are met, maintaining user privacy control while improving efficiency.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11363004B2Secure device relay
Publication Date: 2022.06.14 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11363004B2 patent drawing
  • US11363004B2 patent drawing
  • US11363004B2 patent drawing

AI summary

Embodiments of the present invention disclose a method, a computer program product, and a computer system for providing a secure device relay between a data collection device and a server using a smart device. The present invention comprises transmitting to a server a unique identifier corresponding to a data collection device and a digital signature corresponding to a smart device. In addition, the present invention provides for receiving from the server a key pair and an exchange configuration defining access control to data stored on the data collection device. Moreover, the present invention includes transmitting to the data collection device a public key of the received key pair and the exchange configuration.