Trusted Execution Environment for Data Permission Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data sharing frameworks face challenges in ensuring that permissions associated with shared data are consistently enforced, especially across multiple systems and platforms, leading to security risks and unauthorized data usage, as data copies are generated without maintaining the original permissions, making it difficult to track and enforce intended uses.

Innovation Solution

A trusted execution environment is established with distributed execution environments for data providers and consumers, where the core environment monitors and manages data usage in real-time by comparing permissions with intended uses, detecting and addressing data usage violations promptly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is shared across multiple systems and platforms, then data accessibility and collaboration are improved, but permission enforcement consistency deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidpermission enforcement consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a centralized permission management system that acts as an intermediary between data providers and consumers across multiple systems. This mediator maintains a unified permission registry and enforces permissions consistently regardless of which system or platform accesses the data, resolving the contradiction by centralizing control while allowing distributed access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The permission management system is designed to be universal across different systems and platforms. It implements a standardized permission framework that can be applied consistently across diverse environments, enabling the same permission policies to enforce reliably whether data is accessed locally or remotely through various platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If data copies are generated for processing, then data processing efficiency is improved, but permission tracking deteriorates

Engineering Contradiction:
Improvedata processing efficiencyVSAvoidpermission tracking
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where data copies are equipped with metadata or watermarks that reference the original permission set. When data is copied for processing, the system automatically tracks these copies and ensures they inherit and maintain the original permissions. This feedback loop allows efficient data copying while preserving permission information through automated tracking and validation.

Inventive Principle:
Principle #23Feedback

3Reliability

If real-time monitoring of data usage is implemented, then unauthorized usage detection is improved, but system complexity increases

Engineering Contradiction:
Improveunauthorized usage detectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing permission policies and monitoring rules in advance, before data access occurs. Permission constraints are predefined and registered with the data, and monitoring agents are pre-positioned in the system. When data is accessed, these pre-configured rules automatically enforce and monitor compliance without requiring complex real-time analysis, thereby improving detection capability while limiting system complexity through advance preparation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240419781A1Trusted execution environment for data sharing
Publication Date: 2024.12.19 CAPITAL ONE SERVICES LLC
  • US20240419781A1 patent drawing
  • US20240419781A1 patent drawing
  • US20240419781A1 patent drawing

AI summary

In some implementations, a device may obtain an indication of one or more permissions associated with a dataset shared by a data provider via a first execution environment. The device may obtain an indication of one or more data processing applications associated with respective intents, wherein the one or more data processing applications are executable via a second execution environment, and wherein the respective intents indicate an intended use of data in association with the one or more data processing applications. The device may detect a data usage violation associated with a data processing application, from the one or more data processing applications, that has accessed and processed data from the dataset in the second execution environment, based on an intent associated with the data processing application not being permitted by the one or more permissions. The device may perform an action based on detecting the data usage violation.