System and method for dynamically allocating resources
Abstract
A computer network has a number of resources. One or more trusted localisation provider certifies the location of the resources. Encrypted data is closely associated with a policy package defining privacy policies for the data and metapolicies for their selection. A trusted privacy service enforces the privacy policies. The trusted privacy service is arranged to supply a key to a resource to allow that resource to process data if the trusted privacy service determines from the trusted localisation provider certifying the location and other contextual information of the resource that the privacy policy allows processing of the data on that resource in that location.
Claims
exact text as granted — not AI-modified1 . A method of processing data at a resource, comprising:
receiving, by the resource from a resource allocation service, the data and an associated policy package setting a privacy policy associated with the data; sending, from the resource to a trusted privacy service, a message requesting a key to decrypt the data to allow the data to be processed at the resource; sending, from the resource to the trusted privacy service, the policy package; and receiving, by the resource from the trusted privacy service, the key to allow the resource to decrypt the data and process the data, responsive to the trusted privacy service determining from the policy package that the resource is permitted to process the data.
2 . The method of claim 1 , further comprising:
obtaining, by the resource from a trusted localization provider, localization information regarding the resource.
3 . The method of claim 2 , wherein the localization information identifies a location of the resource.
4 . The method of claim 2 , wherein the localization information identifies a geographic location of the resource.
5 . The method of claim 2 , wherein the localization information comprises an address of the resource.
6 . The method of claim 2 , further comprising:
sending, by the resource to the trusted privacy service, the localization information.
7 . The method of claim 6 , wherein the trusted localization provider and a trusted privacy module are located within the resource, the method further comprising:
digitally signing, by the trusted privacy module, the localization information so that the trusted privacy service is able to check that the localization information is trusted.
8 . The method of claim 7 , further comprising:
sending further information from the resource to the trusted localization provider relating to privacy policies in force in the resource, to allow the trusted localization provider to verify that the resource has suitable privacy policies to process the data.
9 . The method of claim 1 , wherein the policy package is included in the message.
10 . The method of claim 1 , wherein the policy package includes rules that determine how the data is to be processed.
11 . A resource comprising:
a non-transitory storage medium storing instructions; and a processor to execute the instructions to:
receive, from a resource allocation service, data and an associated policy package setting a privacy policy associated with the data;
send a message to a trusted privacy service requesting a key;
send, to the trusted privacy service, the policy package;
receive, from the trusted privacy service, the key responsive to the trusted privacy service determining from the policy package that the resource is permitted to process the data;
decrypt, using the key, the data and process the decrypted data at the resource.
12 . The resource of claim 11 , wherein the processor is to execute the instructions to further:
obtain, from a trusted localization provider, information regarding a location of the resource.
13 . The resource of claim 12 , wherein the processor is to execute the instructions to further send the information regarding the location of the resource to the trusted service provider.
14 . The resource of claim 12 , further comprising the trusted localization provider.
15 . The resource of claim 11 , wherein the policy package is included in the message.
16 . A non-transitory storage medium storing instructions that upon execution cause a resource to:
receive, from a resource allocation service, data and an associated policy package setting a privacy policy associated with the data; send a message to a trusted privacy service requesting a key to decrypt the data; send, to the trusted privacy service, the policy package; receive, from the trusted privacy service, the key responsive to the trusted privacy service determining from the policy package that the resource is permitted to process the data; and decrypt, using the key, the data and process the decrypted data at the resource.
17 . The non-transitory storage medium of claim 16 , wherein the instructions upon execution cause the resource to:
obtain, from a trusted localization provider, information regarding a location of the resource.
18 . The non-transitory storage medium of claim 17 , wherein the instructions upon execution cause the resource to send the information regarding the location of the resource to the trusted service provider.
19 . The non-transitory storage medium of claim 18 , wherein the information regarding the location of the resource comprises information regarding a geographical location of the resource.
20 . The non-transitory storage medium of claim 16 , wherein the policy package is included in the message.Join the waitlist — get patent alerts
Track US2015350165A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.