US20110145593A1

Verifiable trust for data through wrapper composition

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A digital escrow pattern for data services can include selective access for obscured data at a remote site or in a cloud service, distributing trust across multiple entities to avoid a single point of data compromise. Based on the pattern, a “trustworthy envelope” for any kind of payload enables curtained access through a variety of decorations or seals placed on the envelope that allow for a gamut of trust ranging with guarantees such as, but not limited to, confidentiality, privacy, anonymity, tamper detection, integrity, etc. Verifiable trust is provided through families of techniques that are referred to as wrapper composition. Multiple concentric and/or lateral transform wrappers or layers can wholly or partially transform data, metadata or both to mathematical transform (e.g., encrypt, distribute across storage, obscure) or otherwise introduce lack of visibility to some or all of the data, metadata or both.

US20110145593A1, drawing sheet 1
Sheet 1 of 68

Term

Projected expiry 17 August 2033.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

46 claims: 3 independent, 43 dependent

  1. 1
    Broadest claimClaim Score 57, average(NHIP)A method for hosting data, comprising:receiving at least one of data or metadata associated with the data, where the data, the metadata or both are protected by a composite wrapper formed from at least one mathematical transformation of the data, the metadata or both including at least a first mathematical transformation defining a first wrapper for the data, the metadata or both based on a first set of criteria and a second mathematical transformation defining a second wrapper for the data, the metadata or both based on a second set of criteria;and receiving a request for access to the data, metadata or both as protected by the composite wrapper based on a set of capabilities included in the request;and based on the set of capabilities, determining at least one access privilege for the data, metadata or both based on evaluating visibility through the first wrapper and independently evaluating visibility through the second wrapper.
  2. 41
    A system, comprising:at least one mathematical transformation component distributed at least partially by a mathematical transformation technology provider, implemented independently from an access information generator that generates capability information for at least one of publishing data, metadata or both, or subscribing to published data, published metadata, or both, the at least one mathematical transformation component including at least one processor configured to perform at least one encoding algorithm or decoding algorithm based on the capability information generated by the access information generator;and a network service provider, implemented independently from the access information generator and the at least one mathematical transformation component, including at least one processor configured to implement a network service with respect to computer data, computer metadata or both encrypted by the at least one mathematical transformation component, the network service provider is configured to communicate with the at least one mathematical transformation component to perform generation, regeneration, alteration, augmentation or deletion of at least two mathematical transformation wrappers applied to the computer data, computer metadata or both.
  3. 46
    A method for requesting access to data, comprising:based on a set of capabilities, requesting access to data, metadata or both as protected by a composite wrapper formed from at least one mathematical transformation of the data, the metadata or both including at least a first mathematical transformation defining a first wrapper for the data, the metadata or both based on a first set of criteria and a second mathematical transformation defining a second wrapper for the data, the metadata or both based on a second set of criteria;and based on at least one access privilege for the data, metadata or both determined from the set of capabilities, being granted visibility through at least one of the first wrapper or the second wrapper based on independent evaluations of the first wrapper and the second wrapper relative to the at least one access privilege.