Self-Protecting Data Objects for Zero-Trust Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems rely on network and application trust, which can be compromised, leading to vulnerabilities in infrastructure security.

Innovation Solution

A rules-based policy driven engine that employs a zero-trust security principle, enabling self-protecting data objects to make access decisions based on embedded policies and variables, independent of network or application trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network and application trust models are used for security, then access control can be simplified, but security reliability deteriorates when trust is compromised

Engineering Contradiction:
Improveaccess control simplicityVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The data object performs self-protection by embedding security policies directly within itself and autonomously evaluating access requests against these policies. The data object independently makes access decisions without relying on external network or application trust models, thereby maintaining security reliability while simplifying the access control process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of the traditional model where the network or application controls access based on trust, this invention inverts the approach by making the data object itself the controller of its own access. The data object actively evaluates access requests and denies access to untrusted sources, reversing the passive trust-based model into an active security model.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If zero-trust security principles are implemented, then security reliability improves, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security function is segmented and embedded within each individual data object rather than being centralized in the network or application layer. Each data object contains its own security policies and evaluation logic, distributing the complexity across multiple small units rather than concentrating it in a single complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention merges the data object with its security policies, creating a unified self-protecting entity. By combining the data storage function with the security evaluation function within the same object, the system reduces overall complexity while improving security reliability through integrated design.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250209191A1Rules based policy driven engine and methods of use
Publication Date: 2025.06.26 SERTAINTY CORPORATION
  • US20250209191A1 patent drawing
  • US20250209191A1 patent drawing
  • US20250209191A1 patent drawing

AI summary

In an aspect, an apparatus is presented. An apparatus may include a processor and a memory communicatively coupled to the processor. A memory may contain instructions to cause the processor to receive a variable. A processor may compare a variable to one or more policies. A processor may apply one or more rules to a variable base don a comparison to one or more policies. A processor may instruct an actor to perform an action with a variable based on one or more rules. A processor may produce an output based on an action performed, wherein the output is produced using a zero-trust security principle.