Trusted Intermediary for Secure Tenant Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computing systems face challenges in ensuring data privacy and security when sharing data between tenants in cloud-computing environments, as existing digital rights management systems often reveal the identity of the data receiver to the sender, compromising anonymity and access control.

Innovation Solution

A system that establishes trusted connections between tenants to enable secure data sharing while maintaining anonymity, using a connection module to create trusted links between tenants, a data transfer module to transfer data portions, and an authorization module to grant access requests without revealing the identity of the data recipient, ensuring that only authorized parties access sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital rights management systems rely on the identity of the receiver being made available to the sender, then the sender can ensure the receiver is authorized to access the data, but the receiver's anonymity is compromised

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidreceiver identity anonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a trusted intermediary (the second tenant) that mediates between the first tenant (sender) and the third tenant (receiver). The intermediary establishes trusted connections with both parties, allowing the first tenant to verify authorization through the intermediary without directly knowing the third tenant's identity. This resolves the contradiction by enabling reliable access control through the intermediary while preserving the receiver's anonymity from the sender.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If data is transferred directly from sender to receiver without an intermediary, then transfer speed is improved, but security and anonymity controls are weakened

Engineering Contradiction:
Improvedata transfer speedVSAvoidsecurity control
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system uses a trusted intermediary (second tenant) to facilitate data transfer between the first and third tenants. The intermediary establishes trusted connections with both parties and controls the data transfer process, ensuring security and anonymity requirements are met while enabling efficient data transfer through established trust relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the sender can identify the receiver, then access authorization can be verified, but the receiver's privacy is compromised

Engineering Contradiction:
Improveauthorization verificationVSAvoidreceiver identity privacy
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The trusted intermediary (second tenant) enables the first tenant to verify that the third tenant is authorized to receive data without the first tenant directly knowing the third tenant's identity. The intermediary handles the authorization verification process while preserving the receiver's privacy, resolving the contradiction between ease of authorization verification and identity privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12034725B2Data management system
Publication Date: 2024.07.09 FOMTECH LTD
  • US12034725B2 patent drawing
  • US12034725B2 patent drawing
  • US12034725B2 patent drawing

AI summary

A system for sharing data between tenants served by a software instance. In the system, a first tenant can ensure that data is transferred to a trusted connection by virtue of a trusted established between the first tenant and a second tenant, and a trusted connection between the second tenant and a third tenant. The system allows the identity of the third tenant to be kept secret from the first tenant, thus maintaining the privacy of the third tenants. In addition, the system allows for the first tenant to force control over the tenants with which the second tenant is allowed to share the first portion of the data, and the second tenant can provide an additional layer of this control.