Trusted Access Control Value Systems for Selective Data Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data access control systems in computer networks employ an all-or-nothing approach, failing to selectively manage access permissions for different network devices, and are vulnerable to man-in-the-middle attacks that compromise data security and system performance.
Innovation Solution
The system employs a tagging engine to link data elements with access control tag arrays, providing context information for permission levels, and includes a verification engine to detect tampering and a routing engine to selectively route data based on access control tags, enhancing security and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an all-or-nothing approach for data access control is used, then data security is simplified to implement, but the system cannot selectively specify access control permission for various network devices
Solution Approach 1:
The patent segments the access control system into multiple components: access control tags attached to data elements, verification engines at network devices, and policy servers. This segmentation enables selective access control by allowing different tags and verification rules for different data and devices, resolving the contradiction between adaptability and complexity
Solution Approach 2:
The patent applies local quality by attaching specific access control tags to individual data elements and configuring verification engines at specific network devices with device-specific policies. This allows each part of the system to have customized access control characteristics, enabling selective permission specification without requiring system-wide complexity
2Reliability
If traditional access control systems are used, then system implementation is straightforward, but they are vulnerable to man-in-the-middle attacks that compromise data security
Solution Approach 1:
The patent implements preliminary action by pre-attaching access control tags to data elements before transmission and pre-configuring verification engines at network devices with the necessary verification logic. This preliminary preparation enables automatic verification during transmission, enhancing security against man-in-the-middle attacks without requiring complex real-time processing
Solution Approach 2:
The patent introduces an intermediary verification engine that acts as a mediator between data elements and network devices. This verification engine checks access control tags and enforces policies, providing a security layer that protects against attacks while maintaining system manageability through centralized policy control
3Adaptability or versatility
If access control tags are attached to data elements, then selective routing and access control are enabled, but the system becomes more complex to manage
Solution Approach 1:
The patent applies universality by designing access control tags with multiple functions: they identify data elements, encode access permissions, and enable verification. This multi-functionality reduces the need for separate management systems, as the same tag structure serves multiple purposes, thereby improving ease of operation while maintaining routing flexibility
Data Source
AI summary
A system that includes a tagging engine and a routing engine. The tagging engine is configured to link a data element with an access control tag array that links access control tags with end user groups. The tagging engine is configured to encrypt a hash of the access control tag array using a first key and to apply a second key to the access control tag array to obfuscate the access control tag array. The tagging engine is configured to send the data element, the encrypted hash, and the obfuscated access control tag array to a target network node. The routing engine is configured to compute a hash of the access control tag array and to forward the data element to the target network node in response to determining that the received hash of the access control tag array to the computed access control tag array are the same.


