Secure policy-controlled processing and auditing on regulated data sets
Abstract
A system and method for secure policy-controlled processing and auditing on regulated data sets utilizing metadata and a plurality of analytics. The system and method combine the ability to restrict and control the transport and processing of data based on specified directives and provide rich auditable provenance to support evidential requirements. The system and method may additionally automatically optimize data routes and specify processing hardware based on data residency, sovereignty, or localization restrictions, furthermore, protect sensitive data from compromise by algorithmically generating digital tokens and employ sensors on all devices in the chain to provide a secure means of data transport.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system for auditable policy-compliant processing and transporting of data, comprising:
a computing device comprising a non-volatile storage device, a memory, and a processor; an authority database stored on the non-volatile storage device; a network analyzer comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the first plurality of programming instructions, when operating on the processor of the computing device, cause the computing device to:
monitor and collect computing device metadata comprising information about the hardware and software on the computing device; and
send the computing device metadata to the ledger engine;
a data packet manager comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor of the computing device, cause the computing device to:
identify a protocol data unit on the network;
amend the protocol data unit to allow enforcement of where computation or persistence of the protocol data unit occurs in the network;
tokenize the protocol data unit to provide security against unauthorized use;
extract protocol data unit metadata from the protocol data unit, the protocol data unit comprising a source and a destination;
send the protocol data unit metadata to a ledger engine;
receive an optimal pathway or rejection from the automated planning service; and
when an optimal pathway is received, transmit the protocol data unit along the optimal pathway; and
when a rejection is received, reject further transmission of the protocol data unit;
a ledger engine comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the third plurality of programming instructions, when operating on the processor of the computing device, cause the computing device to:
receive the protocol data unit metadata;
retrieve a regulatory guideline from the authority database pertaining to the protocol data unit based on the protocol data unit metadata;
extract a rule from the regulatory guideline applicable to the protocol data unit based on the protocol data unit metadata;
retrieve administrative metadata from the source of the protocol data unit, the administrative data comprising an access log;
receive the computing device metadata;
store the protocol data unit metadata, the administrative metadata, the computing device metadata, and the rule on the non-volatile storage device;
a distributed computational graph engine comprising a fourth plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the fourth plurality of programming instructions, when operating on the processor of the computing device, cause the computing device to:
create a distributed computational graph comprising vertices representing metadata attributes and edges representing mapped rules;
retrieve the protocol data unit metadata, the administrative metadata, the computing device metadata, and the rule from the non-volatile storage;
update the distributed computational graph with the protocol data unit metadata, the administrative metadata, the computing device metadata, and the rule from the non-volatile storage
store the distributed computational graph on the non-volatile storage device;
an automated planning service comprising a fifth plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the fifth plurality of programming instructions, when operating on the processor of the computing device, cause the computing device to:
retrieve the distributed computational graph from the non-volatile storage device;
compute one or more policy compliant pathways for the protocol data unit to travel by running one or more graph traversal algorithms on the distributed computational graph;
identify an optimal pathway from the one or more policy compliant pathways; and
send the optimal pathway to the data packet manager.
2 . A system for auditable policy-compliant processing and transporting of data, comprising:
a network comprising a non-volatile storage device and a plurality of computing devices, each computing device being a node in the network and comprising a memory and a processor; an authority database stored on the non-volatile storage device; a network analyzer comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, one of the nodes in the network, wherein the first plurality of programming instructions, when operating on the processor of the node, cause the node to:
monitor and collect node metadata comprising information about the hardware and software on each node; and
send the node metadata to the ledger engine;
a data packet manager comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, one of the nodes in the network, wherein the second plurality of programming instructions, when operating on the processor of the node, cause the node to:
identify a protocol data unit on the network;
amend the protocol data unit to allow enforcement of where computation or persistence of the protocol data unit occurs in the network;
tokenize the protocol data unit to provide security against unauthorized use;
extract protocol data unit metadata from the protocol data unit, the protocol data unit comprising a source and a destination;
send the protocol data unit metadata to a ledger engine;
receive an optimal pathway or rejection from the automated planning service; and
when an optimal pathway is received, transmit the protocol data unit along the optimal pathway; and
when a rejection is received, reject further transmission of the protocol data unit;
a ledger engine comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, one of the nodes in the network, wherein the third plurality of programming instructions, when operating on the processor of the node, cause the node to:
receive the protocol data unit metadata;
retrieve a regulatory guideline from the authority database pertaining to the protocol data unit based on the protocol data unit metadata;
extract a rule from the regulatory guideline applicable to the protocol data unit based on the protocol data unit metadata;
retrieve administrative metadata from the source of the protocol data unit, the administrative data comprising an access log;
receive the node metadata;
store the protocol data unit metadata, the administrative metadata, the node metadata, and the rule on the non-volatile storage device;
a distributed computational graph engine comprising a fourth plurality of programming instructions stored in the memory of, and operating on the processor of, one of the nodes in the network, wherein the fourth plurality of programming instructions, when operating on the processor of the node, cause the node to:
create a distributed computational graph comprising vertices representing metadata attributes and edges representing mapped rules;
retrieve the protocol data unit metadata, the administrative metadata, the node metadata, and the rule from the non-volatile storage;
update the distributed computational graph with the protocol data unit metadata, the administrative metadata, the node metadata, and the rule from the non-volatile storage
store the distributed computational graph on the non-volatile storage device;
an automated planning service comprising a fifth plurality of programming instructions stored in the memory of, and operating on the processor of, one of the nodes in the network, wherein the fifth plurality of programming instructions, when operating on the processor of the node, cause the node to:
retrieve the distributed computational graph from the non-volatile storage device;
compute one or more policy compliant pathways for the protocol data unit to travel by running one or more graph traversal algorithms on the distributed computational graph;
identify an optimal pathway from the one or more policy compliant pathways; and
send the optimal pathway to the data packet manager.
3 . A method for auditable policy-compliant processing and transporting of data, comprising the steps of:
monitoring and collecting node metadata comprising information about the hardware and software on each node of a network, each node being a computing device comprising a memory and a processor; identifying a protocol data unit on the network; amending the protocol data unit to allow enforcement of where computation or persistence of the protocol data unit occurs in the network; tokenizing the protocol data unit to provide security against unauthorized use; extracting protocol data unit metadata from the protocol data unit, the protocol data unit comprising a source and a destination; retrieving administrative metadata from the source of the protocol data unit, the administrative data comprising an access log; retrieving a regulatory guideline from the authority database pertaining to the protocol data unit based on the protocol data unit metadata; extracting a rule from the regulatory guideline applicable to the protocol data unit based on the protocol data unit metadata; creating a distributed computational graph comprising vertices representing metadata attributes and edges representing mapped rules; updating the distributed computational graph with the protocol data unit metadata, the administrative metadata, the node metadata, and the rule from the non-volatile storage; computing one or more policy compliant pathways for the protocol data unit to travel by running one or more graph traversal algorithms on the distributed computational graph; identifying an optimal pathway from the one or more policy compliant pathways; and when an optimal pathway is received, transmit the protocol data unit along the optimal pathway; and when a rejection is received, reject further transmission of the protocol data unit.Join the waitlist — get patent alerts
Track US2020389495A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.