Trusted Information Exchange via Rights Expression Licenses
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to securely and efficiently exchange sensitive digital information across organizational boundaries, lacking trust and control mechanisms, which hampers information sharing and can lead to unauthorized access.
Innovation Solution
The implementation of Trusted Information Exchange (TIE) systems using Service-Oriented Architecture (SOA) and Rights Expression Language (REL) licenses for secure, controlled sharing of digital assets, enabling trusted entities to exchange information based on granted rights and agreed conditions, with mechanisms for asset collection, distribution, acquisition, and disposition.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security measures are strengthened to protect sensitive information, then information security is improved, but information sharing capability deteriorates
Solution Approach 1:
The patent introduces a trust agreement as an intermediary mechanism that mediates between information providers and consumers. The trust agreement includes rights expression language (REL) licenses that define authorized access conditions, enabling secure information sharing without requiring direct trust between parties. This intermediary structure resolves the contradiction by allowing information flow while maintaining security controls through the trust agreement framework.
Solution Approach 2:
The system dynamically changes security parameters based on the trust agreement terms. Instead of applying fixed security restrictions, the system adjusts access rights, permissions, and monitoring levels according to the specific conditions defined in each trust agreement. This enables flexible security management that adapts to different sharing scenarios, improving both security and sharing capability.
2Reliability
If control mechanisms are implemented to manage information distribution, then information control is improved, but system complexity increases
Solution Approach 1:
The trust agreement framework serves multiple functions simultaneously: it establishes security policies, defines access rights, tracks information distribution, and enforces compliance. By consolidating these control mechanisms into a single universal framework, the system achieves comprehensive information control without proportionally increasing complexity. The rights expression language (REL) provides a standardized syntax that handles multiple control requirements uniformly.
Solution Approach 2:
The system establishes control mechanisms in advance through pre-defined trust agreements and rights expressions. Instead of implementing complex real-time control decisions, the system prepares authorization rules, access policies, and distribution constraints before information exchange occurs. This preliminary configuration reduces runtime complexity while maintaining strong control capabilities.
3Reliability
If trust verification processes are enhanced to ensure authorized access, then trust reliability is improved, but processing time increases
Solution Approach 1:
The system performs trust verification in advance by establishing trust agreements and rights expressions before information exchange. The rights expression language (REL) licenses pre-define authorized access conditions, so during actual information transfer, the system only needs to verify compliance with pre-established rules rather than performing comprehensive trust assessment. This preliminary action significantly reduces processing time while maintaining verification accuracy.
Solution Approach 2:
The system uses rights expression language (REL) to create standardized templates and copies of trust verification rules. Instead of performing unique complex verification for each information exchange, the system replicates and applies pre-validated trust rules. This copying approach maintains high trust verification accuracy while reducing processing time through template reuse.
Data Source
AI summary
Techniques are provided for allowing organizations to preserve the trust and allow this trust to be propagated across multiple agencies and/or enterprises. A technology is provided that allows (mutually) trusted entities to share content (information, digital assets) over any protocol-based network such as the Internet based on granted rights and agreed conditions. In one embodiment, Trusted Information Exchange (TIE) systems have a Service Oriented Architecture (SOA) and use content (information, asset) repositories to store and forward content to trusted entities on the Internet. Techniques are provided to permit source TIE systems to manage the specific disposition and management of their assets to receiving TIE systems through directions conveyed in licenses that reflect apriori agreements.


