System and method for manipulation of secure data
A system and method for movement and manipulation of secure data. The system and method combine the ability to restrict and control the transport and processing of data based on specified directives and provide rich auditable provenance to support evidentiary requirements. The system may additionally automatically optimize data routes and specify processing hardware based on data residency, sovereignty, or localization restrictions, constraints, or economic considerations, furthermore, protect sensitive data from compromise by generating and integrating digital tokens and employing observability sensors, processing flows, and analytics on devices in the data transport, storage and compute chain to provide a secure method of data transport and utilization within applications.
1 . A computing system for movement and manipulation of secure data employing a ledger, the computing system comprising:
one or more hardware processors configured for:
collecting computing system metadata comprising information about hardware and software on the computing system;
identifying a protocol data unit (PDU) on the network;
amending the PDU to allow enforcement of where computation or persistence of the PDU occurs in the network;
tokenizing the PDU;
extracting PDU metadata from the PDU, the PDU comprising a source and a destination;
sending the PDU metadata to a ledger comprising persistent transactional metadata;
retrieving a regulatory guideline from an authority database pertaining to the PDU based on the PDU metadata;
extracting a rule from the regulatory guideline applicable to the PDU based on the PDU metadata;
retrieving administrative metadata from the source of the PDU, the administrative data comprising an access log;
updating a cyber-physical graph with the PDU metadata, the administrative metadata, the computing system metadata, and the extracted rule, wherein the cyber-physical graph represents relations between data and rules stored in the authority database;
identifying, based on the cyber-physical graph, an optimal pathway for the tokenized PDU to travel, wherein the optimal pathway is selected from one or more computed policy-compliant pathways based on hardware, software, and user access;
when an optimal pathway is identified, transmitting the tokenized PDU along the optimal pathway; and
when a rejection is received, rejecting further transmission of the tokenized PDU.
2 . The computing system of claim 1 , wherein the authority database is stored and accessed over a network of computing systems, rather than a singular computing system.
3 . The computing system of claim 1 , wherein the computing system is a networked group of computing devices, that may operate different parts of the system in tandem or discretely, to achieve the function of the whole system together over a network.
4 . The computing system of claim 1 , wherein the PDU metadata, the administrative metadata, the computing system metadata, and the extracted rule are maintained in a cache, and wherein the cache is maintained by a database, virtual memory caching system or operating system, content delivery network, or networked memory, rather than the computing system's memory.
5 . The computing system of claim 1 , wherein the optimal pathway is based at least on human and legal considerations.
6 . The system of claim 1 , wherein the authority database is stored and accessed over a network of computing systems, rather than a singular computing system.
7 . The system of claim 1 , wherein the system is a networked group of computing devices, that may operate different parts of the system in tandem or discretely, to achieve the function of the whole system together over a network.
8 . The system of claim 1 , wherein the PDU metadata, the administrative metadata, the computing system metadata, and the extracted rule are maintained in a cache, and wherein the cache is maintained by a database, virtual memory caching system or operating system, content delivery network, or networked memory, rather than the computing system's memory.
9 . The system of claim 1 , wherein the optimal pathway is based at least on human and legal considerations.
10 . A computer-implemented method executed on a ledger for movement and manipulation of secure data, the computer-implemented method comprising:
collecting computing system metadata comprising information about hardware and software on the computing system;
identifying a protocol data unit (PDU) on the network;
amending the PDU to allow enforcement of where computation or persistence of the PDU occurs in the network;
tokenizing the PDU;
extracting PDU metadata from the PDU, the PDU comprising a source and a destination;
sending the PDU metadata to a ledger comprising persistent transactional metadata;
retrieving a regulatory guideline from an authority database pertaining to the PDU based on the PDU metadata;
extracting a rule from the regulatory guideline applicable to the PDU based on the PDU metadata;
retrieving administrative metadata from the source of the PDU, the administrative data comprising an access log;
updating a cyber-physical graph with the PDU metadata, the administrative metadata, the computing system metadata, and the extracted rule, wherein the cyber-physical graph represents relations between data and rules stored in the authority database;
identifying, based on the cyber-physical graph, an optimal pathway for the tokenized PDU to travel, wherein the optimal pathway is selected from one or more computed policy-compliant pathways based on hardware, software, and user access;
when an optimal pathway is identified, transmitting the tokenized PDU along the optimal pathway; and
when a rejection is received, rejecting further transmission of the tokenized PDU.
11 . The computer-implemented method of claim 10 , wherein the authority database is stored and accessed over a network of computing systems, rather than a singular computing system.
12 . The computer-implemented method of claim 10 , wherein the PDU metadata, the administrative metadata, the computing system metadata, and the extracted rule are maintained in a cache, and wherein the cache is maintained by a database, virtual memory caching system or operating system, content delivery network, or networked memory, rather than the computing system's memory.
13 . The computer-implemented method of claim 10 , wherein the optimal pathway is based at least on human and legal considerations.
14 . A system for movement and manipulation of secure data employing a ledger, comprising one or more computers with executable instructions that, when executed, cause the system to:
collect computing system metadata comprising information about hardware and software on the computing system;
identify a protocol data unit (PDU) on the network;
amend the PDU to allow enforcement of where computation or persistence of the PDU occurs in the network;
tokenize the PDU;
extract PDU metadata from the PDU, the PDU comprising a source and a destination;
send the PDU metadata to a ledger comprising persistent transactional metadata;
retrieve a regulatory guideline from an authority database pertaining to the PDU based on the PDU metadata;
extract a rule from the regulatory guideline applicable to the PDU based on the PDU metadata;
retrieve administrative metadata from the source of the PDU, the administrative data comprising an access log;
update a cyber-physical graph with the PDU metadata, the administrative metadata, the computing system metadata, and the extracted rule, wherein the cyber-physical graph represents relations between data and rules stored in the authority database;
identify, based on the cyber-physical graph, an optimal pathway for the tokenized PDU to travel, wherein the optimal pathway is selected from one or more computed policy-compliant pathways based on hardware, software, and user access;
when an optimal pathway is identified, transmitting the tokenized PDU along the optimal pathway; and
when a rejection is received, rejecting further transmission of the tokenized PDU.
15 . Non-transitory, computer-readable storage media having computer-executable instructions embodied thereon that, when executed by one or more processors of a computing system employing a ledge for movement and manipulation of secure data, cause the computing system to:
collect computing system metadata comprising information about hardware and software on the computing system;
identify a protocol data unit (PDU) on the network;
amend the PDU to allow enforcement of where computation or persistence of the PDU occurs in the network;
tokenize the PDU;
extract PDU metadata from the PDU, the PDU comprising a source and a destination;
send the PDU metadata to a ledger comprising persistent transactional metadata;
retrieve a regulatory guideline from an authority database pertaining to the PDU based on the PDU metadata;
extract a rule from the regulatory guideline applicable to the PDU based on the PDU metadata;
retrieve administrative metadata from the source of the PDU, the administrative data comprising an access log;
update a cyber-physical graph with the PDU metadata, the administrative metadata, the computing system metadata, and the extracted rule, wherein the cyber-physical graph represents relations between data and rules stored in the authority database;
identify, based on the cyber-physical graph, an optimal pathway for the tokenized PDU to travel, wherein the optimal pathway is selected from one or more computed policy-compliant pathways based on hardware, software, and user access;
when an optimal pathway is identified, transmitting the tokenized PDU along the optimal pathway; and
when a rejection is received, rejecting further transmission of the tokenized PDU.
16 . The non-transitory, computer-readable storage media of claim 15 , wherein the authority database is stored and accessed over a network of computing systems, rather than a singular computing system.
17 . The non-transitory, computer-readable storage media of claim 15 , wherein the computing system is a networked group of computing devices, that may operate different parts of the system in tandem or discretely, to achieve the function of the whole system together over a network.
18 . The non-transitory, computer-readable storage media of claim 15 , wherein the PDU metadata, the administrative metadata, the computing system metadata, and the extracted rule are maintained in a cache, and wherein the cache is maintained by a database, virtual memory caching system or operating system, content delivery network, or networked memory, rather than the computing system's memory.
19 . The non-transitory, computer-readable storage media of claim 15 , wherein the optimal pathway is based at least on human and legal considerations.