Trusted Access Control Value Systems for Selective Data Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data access control systems in computer networks employ an all-or-nothing approach, failing to selectively manage access permissions for different network devices, and are vulnerable to man-in-the-middle attacks that compromise data security and system performance.

Innovation Solution

The system employs a tagging engine to link data elements with access control tag arrays, providing context information for permission levels, and includes a verification engine to detect tampering and a routing engine to selectively route data based on access control tags, enhancing security and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an all-or-nothing approach for data access control is used, then data security is simplified to implement, but the system cannot selectively specify access control permission for various network devices

Engineering Contradiction:
Improveselective access control permissionVSAvoidaccess control system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the access control system into multiple components: access control tags attached to data elements, verification engines at network devices, and policy servers. This segmentation enables selective access control by allowing different tags and verification rules for different data and devices, resolving the contradiction between adaptability and complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by attaching specific access control tags to individual data elements and configuring verification engines at specific network devices with device-specific policies. This allows each part of the system to have customized access control characteristics, enabling selective permission specification without requiring system-wide complexity

Inventive Principle:
Principle #3Local quality

2Reliability

If traditional access control systems are used, then system implementation is straightforward, but they are vulnerable to man-in-the-middle attacks that compromise data security

Engineering Contradiction:
Improvedata securityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-attaching access control tags to data elements before transmission and pre-configuring verification engines at network devices with the necessary verification logic. This preliminary preparation enables automatic verification during transmission, enhancing security against man-in-the-middle attacks without requiring complex real-time processing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification engine that acts as a mediator between data elements and network devices. This verification engine checks access control tags and enforces policies, providing a security layer that protects against attacks while maintaining system manageability through centralized policy control

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If access control tags are attached to data elements, then selective routing and access control are enabled, but the system becomes more complex to manage

Engineering Contradiction:
Improvedata routing flexibilityVSAvoidsystem management ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent applies universality by designing access control tags with multiple functions: they identify data elements, encode access permissions, and enable verification. This multi-functionality reduces the need for separate management systems, as the same tag structure serves multiple purposes, thereby improving ease of operation while maintaining routing flexibility

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10872164B2Trusted access control value systems
Publication Date: 2020.12.22 BANK OF AMERICA CORP
  • US10872164B2 patent drawing
  • US10872164B2 patent drawing
  • US10872164B2 patent drawing

AI summary

A system that includes a tagging engine and a routing engine. The tagging engine is configured to link a data element with an access control tag array that links access control tags with end user groups. The tagging engine is configured to encrypt a hash of the access control tag array using a first key and to apply a second key to the access control tag array to obfuscate the access control tag array. The tagging engine is configured to send the data element, the encrypted hash, and the obfuscated access control tag array to a target network node. The routing engine is configured to compute a hash of the access control tag array and to forward the data element to the target network node in response to determining that the received hash of the access control tag array to the computed access control tag array are the same.