Trust Broker Privity Core for Secure Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for secure exchange of private information between information owners and application service providers lack fine-grained control and dynamic trust management, leading to increased business overhead and mistrust due to reliance on bilateral agreements and coarse-grained control mechanisms, which are unsuitable for dynamic open information marketplaces.
Innovation Solution
A workflow-based system utilizing a privity core to generate user-specific tokens and manage trust relationships between end-users, information providers, and application service providers, enabling secure and controlled exchange of sensitive information through secure communication channels and dynamic permission management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If bilateral agreements are used between information owners and application service providers, then trust relationships can be established, but business overhead and time to market significantly increase
Solution Approach 1:
The patent introduces a trust broker as an intermediary entity that mediates between information owners and application service providers. The trust broker establishes centralized trust relationships and issues credentials that enable ASPs to access information without requiring separate bilateral agreements with each information owner, thereby reducing business overhead while maintaining trust.
Solution Approach 2:
The trust broker provides universal trust validation services that can be used across multiple information owners and application service providers. A single trust relationship established with the broker enables an ASP to access information from multiple owners, eliminating the need for repeated bilateral negotiations and reducing overall system complexity.
2Reliability
If bilateral vetting processes are implemented, then information owners can verify application service providers, but the process becomes time-consuming and impractical for small ASPs working with large information providers
Solution Approach 1:
The trust broker performs preliminary vetting and verification of application service providers in advance, issuing credentials that are valid for multiple information owners. This preliminary action eliminates the need for time-consuming bilateral verification processes when small ASPs want to work with large information providers, significantly reducing time to market.
3Ease of operation
If coarse-grained control mechanisms are used for information access, then simple access decisions can be made, but fine-grained control over specific information elements cannot be achieved
Solution Approach 1:
The patent segments information into distinct elements or attributes that can be independently controlled. The trust broker issues credentials that specify exactly which information elements an ASP is authorized to access, enabling fine-grained control over specific data points while maintaining simple overall access management through the centralized broker.
Data Source
AI summary
The invention disclosed here is aimed at enabling a trusted third party to manage user opt-ins which would enable growth of personalized information services, that is, enabling trusted business relationships between three types of entities—an end-user, an information source/provider, and an application service provider/developer—so that they can have a controlled, secure and private exchange of sensitive and/or confidential information. The inventive system has modes of operation recommended based on various conditions, enabling a secure exchange of private information between personal information repository owners and application services providers to enable deliver of personalized services. One mode is Durable Subscription Management, which is used when per transaction approval is not needed, that is, when an end-user has given permission to access data for a given or predefined period of time. A second mode is Per-Transaction Subscription Management Without Logs and a third mode is Per-Transaction Subscription Management With Logs.


