Supervised Data Transfer with Human Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack sufficient automated support to ensure that data transfers between networks are authorized by human users, risking compromise from rogue users or software.

Innovation Solution

A system with separate computing environments for data transfer requests, including a supervisory mechanism to verify human involvement through metrics analysis and challenge-response tests, ensuring that data transfers are initiated by human users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated data transfer control is implemented without human verification, then productivity is improved, but reliability deteriorates due to unauthorized transfers from rogue users or software

Engineering Contradiction:
Improvedata transfer automationVSAvoidauthorization assurance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a supervisory mechanism as an intermediary between the automated data transfer system and the authorization decision-making process. This supervisory mechanism monitors transfer requests, analyzes user behavior patterns, and determines whether human involvement is present, thereby maintaining automated efficiency while ensuring reliable authorization through intermediate verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback loops where the supervisory mechanism continuously monitors data transfer requests, compares user behavior against established patterns, and adjusts authorization decisions based on this feedback. This enables the system to maintain high productivity while dynamically ensuring reliability through continuous verification

Inventive Principle:
Principle #23Feedback

2Reliability

If human verification is required for all data transfers, then reliability is improved, but productivity deteriorates due to manual decision-making requirements

Engineering Contradiction:
Improveauthorization assuranceVSAvoiddata transfer automation
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial automation by requiring human verification only when the supervisory mechanism detects suspicious patterns or uncertain authorization scenarios. For routine transfers with clear authorization patterns, the system operates automatically without human intervention, thus maintaining high productivity while providing reliability assurance where needed

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary analysis of user behavior patterns and authorization contexts before requiring human verification. By pre-establishing behavior baselines and automatically verifying routine requests, the system prepares authorization decisions in advance, reducing the need for manual intervention and maintaining productivity while ensuring reliability

Inventive Principle:
Principle #10Preliminary action

3Reliability

If sophisticated behavior analysis is implemented to detect human users, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvehuman user verificationVSAvoidsupervisory mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The supervisory mechanism leverages existing user behavior data and system logs to automatically establish behavior patterns and perform verification. Rather than requiring complex external verification systems, the mechanism uses self-generated data from normal system operations to detect human users, thereby improving reliability without proportionally increasing device complexity

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2710507B1Supervised data transfer
Publication Date: 2019.10.16 BAE SYSTEMS PLC
  • EP2710507B1 patent drawingFigure 1
  • EP2710507B1 patent drawingFigure 2
  • EP2710507B1 patent drawingFigure 3

AI summary

An apparatus and method are provided for controlling a transfer of data between data communications networks. In a preferred implementation, an apparatus is provided comprising: a data store; computer providing, in a first computing environment, a first network interface for accessing a first data communications network and a first user interface for receiving a first data transfer request to download data from a data source linked to the first data communications network to the data store; computer providing, in a second computing environment isolated from the first computing environment, a second network interface for accessing a second data communications network and a second user interface for receiving a second data transfer request to transfer downloaded data from the data store to a recipient device linked to the second data communications network; and data transfer controller with access to resources in both the first and second computing environments for controlling downloads and transfers of data according to the first and second requests, further comprising a supervisory controller arranged to determine, prior to implementing the second request, that at least the second request originates from a human user.