Self-Aware Data Objects with Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data security technologies, such as passwords and digital rights management, are inadequate in protecting confidential information as they can be circumvented, allowing password-protected data to be copied and distributed after initial extraction, leading organizations to be reluctant to share sensitive information.
Innovation Solution
The creation and use of self-aware data objects (SADOs) with multiple layers of security, including encryption and a self-aware access control component (SAACC), which encapsulate data and restrict access based on context, user authorization, time, and function usage, ensuring that data remains secure even if extracted unauthorizedly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional data security technologies (passwords and digital rights management) are used, then data protection is provided to some extent, but the data can be circumvented and copied after initial extraction
Solution Approach 1:
The patent segments data protection into multiple independent layers: encryption layer, access control layer, and usage monitoring layer. Each layer operates independently to provide comprehensive security, preventing single-point failures and circumvention attempts.
Solution Approach 2:
The patent implements nested security structures where encrypted data containers are protected by multiple concentric layers of access control mechanisms. Each layer must be successfully navigated to reach the underlying data, creating a defense-in-depth architecture that prevents unauthorized access even if outer layers are compromised.
2Adaptability or versatility
If organizations share confidential information for collaboration, then product and service development is enabled, but the risk of information misuse increases
Solution Approach 1:
The patent implements dynamic access control policies that automatically adjust permissions based on context, user behavior, and security conditions. Access rights are not static but evolve over time, enabling collaboration while maintaining adaptive security responses to potential misuse scenarios.
Solution Approach 2:
The patent incorporates continuous monitoring and feedback mechanisms that track data usage patterns, user actions, and access attempts. This feedback loop enables real-time detection of anomalous behavior and automatic response actions, allowing organizations to share information confidently while maintaining control over usage.
3Ease of operation
If password protection is applied to data, then basic access control is achieved, but the protected data can be extracted and distributed after initial access
Solution Approach 1:
The patent applies preliminary actions by embedding watermarks, digital signatures, and usage restrictions into data before distribution. These preemptive measures are built into the data structure itself, enabling automatic tracking and control of data usage throughout its distribution lifecycle without requiring complex ongoing authentication.
Data Source
AI summary
Data may be encrypted using a public key. From a plurality of functions executable on the data, one or more functions may be selected. The selected one or more functions may be associated with the encrypted data. The selected one or more functions may provide exclusive access to the data. A data structure specifying conditions for access to the one or more functions may be created. An exclusive interface to provide access to the one or more functions may be created. The interface, upon determining that one or more conditions from the conditions are satisfied, may grant access to the one or more functions. The encrypted data, the associated one or more functions, the data structure, and the interface may be included into an object.


