Trust Computing Platform for Sensitive Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for controlling access to sensitive information in ubiquitous computing applications fail to integrate trust and privacy effectively, lacking a mechanism to quantify privacy breach probability and provide a trusted platform for secure data sharing, which can lead to severe consequences when private data is shared without adequate confidence in privacy preservation.

Innovation Solution

A processor-implemented information access control method and system that computes a trust score for consumers based on the probability of sensitive information privacy breach, using quasi-identifiers from auxiliary sources to evaluate the exploitation factor and potency of consumers, enabling negotiation and restricted sharing based on trustworthiness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If sensitive information is shared with consumers in ubiquitous computing applications, then data utility and collaboration are improved, but privacy breach risk increases

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidprivacy breach risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted computing platform as an intermediary between information owners and consumers. This platform includes a trust management module that computes trust scores and a negotiation module that mediates data sharing agreements. The intermediary verifies consumer trustworthiness and establishes binding contracts, thereby enabling data sharing while mitigating privacy breach risks through structured trust verification and negotiation protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary trust assessment and negotiation before actual data sharing occurs. The trust management module pre-computes trust scores for consumers based on their credentials and behavior history. The negotiation module establishes data sharing agreements with specific terms and conditions before any sensitive information is transferred. This preliminary action ensures that only trusted consumers can access data, and the terms of sharing are predetermined to protect privacy.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If trust management mechanisms are implemented to protect privacy, then security is improved, but system complexity increases

Engineering Contradiction:
Improvetrust and privacy protectionVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted computing platform is designed as a universal multi-functional system that can serve multiple information owners and consumers across different applications. The trust management module uses a standardized trust score computation framework that can evaluate various types of consumers (individuals, organizations, devices) using the same methodology. The negotiation module handles diverse data sharing scenarios through a unified contract framework. This universality reduces overall system complexity by avoiding the need for separate trust management systems for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

By centralizing trust management functions in a dedicated intermediary platform, the patent avoids distributing complex trust verification logic across all information owners and consumers. The intermediary platform consolidates the computation of trust scores, maintenance of trust databases, and execution of negotiation protocols in one location. This centralization simplifies the architecture by creating a single point of trust management rather than requiring each participant to implement their own complex verification systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If probability-based trust scoring is used to assess privacy breach risk, then decision accuracy is improved, but computational requirements increase

Engineering Contradiction:
Improveprivacy breach probability assessmentVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent transforms the abstract concept of trustworthiness into quantifiable parameters including trust scores, privacy breach probabilities, and exploitation factors. These parameters are computed based on observable consumer attributes such as credentials, behavior history, and data usage patterns. By changing trust assessment from a subjective qualitative judgment to an objective quantitative parameter system, the patent enables automated decision-making with measurable precision while using computationally efficient statistical methods rather than complex simulations.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces manual or heuristic-based trust assessment with automated computational algorithms. The trust management module uses algorithmic computation to calculate trust scores and privacy breach probabilities based on input data about consumers. This substitution of automated computation for manual assessment improves consistency and precision while reducing the computational burden by using efficient algorithms rather than exhaustive analysis methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Object-affected harmful factors

If information owners retain full control over sensitive data sharing, then privacy protection is improved, but data utility and collaboration efficiency deteriorate

Engineering Contradiction:
Improveprivacy protection levelVSAvoiddata sharing efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent implements dynamic data sharing agreements through the negotiation module, which allows terms of data sharing to be adjusted based on trust scores and specific transaction contexts. Rather than static all-or-nothing sharing arrangements, the system enables flexible agreements where information owners can specify different levels of access, usage conditions, and time limits based on the consumer's trustworthiness. This dynamic approach optimizes the balance between privacy protection and data utility by adapting sharing terms to each specific interaction.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables information owners to segment their sensitive data into different categories and share specific subsets with different consumers based on trust levels and negotiation outcomes. Rather than treating all data uniformly, the system allows granular control where owners can permit sharing of certain data elements while restricting others. This segmentation increases data utility by allowing selective sharing without requiring complete data access or rejection, thereby improving collaboration efficiency while maintaining privacy protection.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2946288B1System and method for providing sensitive information access control
Publication Date: 2020.08.05 TATA CONSULTANCY SERVICES LTD
  • EP2946288B1 patent drawingFigure 1
  • EP2946288B1 patent drawingFigure 2
  • EP2946288B1 patent drawing

AI summary

A system and method enabling information access control of the sensitive information, based on a trust computing platform is provided. The trustworthiness of the information seekers is computed and accordingly the information owner is capacitated to decide upon sharing the information completely or sharing with some perturbation. The objective is to provide the information owner with the ability to decide on sharing its private data with respect to a parameter so that the decision is less subjective. This invention allows minimum leakage of sensitive data and makes information owner aware of the risk of privacy breach when private data is shared.