Trusted Data Platform with Cryptographic Provenance Assertions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data marketplaces lack robust mechanisms for verifying the integrity, provenance, and chain-of-handling of data, making it difficult for data consumers to trust the authenticity and security of the data they consume.

Innovation Solution

A trusted data management architecture is implemented using a trusted data management platform and a trusted assertion service to securely record information about data provenance and chain-of-handling, allowing data consumers to authenticate and verify the integrity of data through cryptographically signed assertions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional data marketplaces are used, then data access and processing are simple and straightforward, but mechanisms for verifying data integrity, provenance, and chain-of-handling are insufficient

Engineering Contradiction:
Improvedata verification capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted assertion service as an intermediary component between data providers, data processors, and data consumers. This service receives cryptographically signed assertions from data providers and processors, stores them in a secure assertion ledger, and provides verification capabilities to consumers. The intermediary handles the complex cryptographic verification and provenance tracking, allowing the overall system to achieve high reliability without requiring each participant to implement complex verification mechanisms themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by having data providers and processors cryptographically sign assertions about data provenance and handling procedures before data is consumed. These signed assertions are stored in advance in the assertion ledger, enabling consumers to verify data integrity and provenance without needing to trust the data providers directly. The verification infrastructure is established beforehand, allowing rapid verification later without adding complexity to the data consumption process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a trusted data management architecture with cryptographic assertions is implemented, then data authenticity and provenance verification are enhanced, but system complexity and operational overhead increase

Engineering Contradiction:
Improvedata authenticity verificationVSAvoiddata consumption simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trusted assertion service provides self-service verification capabilities through automated cryptographic validation. When a data consumer requests verification, the service automatically retrieves the relevant signed assertions from the ledger, verifies the cryptographic signatures, and returns verification results without requiring the consumer to implement their own cryptographic verification logic. This maintains ease of operation for consumers while achieving high data authenticity verification through automated backend processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The assertion service acts as an intermediary that abstracts the complexity of cryptographic verification from end users. It handles key management, signature verification, and assertion validation internally, presenting a simple verification interface to consumers. This allows consumers to benefit from enhanced data authenticity verification without needing to understand or manage the underlying cryptographic complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cryptographic signing of assertions is performed by multiple parties, then trust and provenance tracking are improved, but processing time and computational overhead increase

Engineering Contradiction:
Improveprovenance tracking accuracyVSAvoidassertion processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Data providers and processors perform cryptographic signing of assertions in advance, before data consumption occurs. These signed assertions are stored in the assertion ledger ahead of time, allowing consumers to perform rapid verification by simply retrieving and validating pre-signed assertions rather than performing complex multi-party cryptographic operations at the moment of data consumption. This preliminary action shifts computational overhead to data production time when resources are more abundant.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates cryptographic copies of provenance information in the form of signed assertions that can be independently verified. Instead of requiring multiple parties to perform real-time cryptographic operations during data consumption, the system pre-creates verified assertion copies that can be quickly retrieved and validated. Each assertion is a self-contained cryptographic proof that can be verified without involving the original data provider or processor, significantly reducing verification time.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP4042736B1Trusted data management systems and methods
Publication Date: 2025.09.17 INTERTRUST TECH CORP
  • EP4042736B1 patent drawingFigure 1
  • EP4042736B1 patent drawingFigure 2
  • EP4042736B1 patent drawingFigure 3

AI summary

This disclosure relates to, among other things, systems and methods for the secure management and verification of data. Certain embodiments disclosed herein provide for a trusted data management platform that may interact with a trusted assertion service to securely record assertion information relating to the generation and/or processing of data managed by the platform. Data consumers interact with the trusted assertion service to authenticate and/or otherwise verify the provenance, chain-of-handling, and/or other information associated with data managed by the trusted data management platform and/or associated data marketplaces.