Verification Environment for Secure Data Sharing Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data sharing between organizations is prone to security issues due to lack of effective tools for ensuring data consumers handle data correctly, leading to potential data leakage and intellectual property risks.

Innovation Solution

Implementing a data sharing architecture where the data provider encrypts data and provides it to the data consumer within a verification environment, allowing processing while ensuring compliance with data usage policies through a verification model trained during a setup phase, and preventing abnormal behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is shared between organizations to enable processing and analysis, then productivity and information utility are improved, but data security and risk of data leakage worsen

Engineering Contradiction:
Improvedata processing capabilityVSAvoiddata leakage risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

A verification environment is introduced as an intermediary layer between the data consumer and the external world. This environment receives data from the data consumer, verifies it against compliance rules, and only allows verified data to pass through. The verification environment acts as a mediator that enables data sharing while maintaining security controls, resolving the contradiction between productivity and data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If data consumer processes data outside provider's system to maintain intellectual property, then ease of operation is improved, but reliability of data security worsens

Engineering Contradiction:
Improvedata processing autonomyVSAvoiddata security assurance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The verification environment implements a feedback mechanism where data is verified against compliance rules and the results are used to determine whether data can be processed. The system continuously monitors data flow and provides feedback on compliance status, enabling the data consumer to operate autonomously while maintaining security assurance through automated verification and reporting.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If verification environment is implemented to ensure data compliance, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata leakage preventionVSAvoidsystem architecture complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The verification environment is segmented into distinct functional components: data reception module, verification module with compliance rules, and data transmission module. Each component has a specific responsibility, making the overall complex system manageable through modular design. The segmentation allows the complexity to be distributed and organized, reducing the burden on any single part of the system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11847235B2Data sharing architecture
Publication Date: 2023.12.19 HELIOS DATA INC
  • US11847235B2 patent drawing
  • US11847235B2 patent drawing
  • US11847235B2 patent drawing

AI summary

Techniques are disclosed relating to sharing data. A first computer system may receive data shared by a second computer system to permit the first computer system to perform processing of the data according to a set of policies. The first computer system may instantiate a verification environment in which to process the shared data. The first computer system may process a portion of the shared data by executing a set of processing routines to generate a result based on the shared data. The verification environment may verify whether the result is in accordance with the set of policies. The verification environment may determine whether to output the result based on the verifying and may send an indication of an outcome of the determining to the second computer system. The indication may be usable to determine whether to provide the first computer system with continued access to the shared data.