Methods, systems, and programs for conditional access to data.
The database system enforces conditional data access based on user consent and processing purposes using data-purpose objects, ensuring compliant and efficient data sharing.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- INTERNATIONAL BUSINESS MACHINE CORPORATION
- Filing Date
- 2022-12-06
- Publication Date
- 2026-04-21
AI Technical Summary
Existing data access methods lack the ability to enforce conditional access based on user consent and processing purposes, leading to potential violations of privacy regulations and unauthorized data sharing.
A database system that stores data-purpose objects indicating subsets of attributes and processing purposes, associating them with authorized entities, and allows access only if the requested view's attributes are a subset of those permitted by user consent, using bitmaps or lists for efficient comparison.
Ensures data access is conditional on user consent and processing purposes, adhering to privacy regulations while minimizing computational overhead.
Smart Images

Figure 0007849130000001 
Figure 0007849130000002 
Figure 0007849130000003
Abstract
Description
Technical Field
[0001] This disclosure generally relates to the field of computing, and more particularly to conditional access to data.
Background Art
[0002] Privacy and data protection regulations are frequently emerging around the world. These include, among others, the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). These regulations often deal with the concept of consent. Consent in this context may relate to whether an individual whose personal data is to be processed consents to that data being processed in a particular way.
Summary of the Invention
[0003] Embodiments of this disclosure are intended for methods for conditional access to data in a database system, the database system comprising records, each record comprising a set of attributes. The database system may further comprise database views, each database view representing a subset of the set of attributes. The method includes storing data-purpose objects, each data-purpose object indicating a subset of attributes from the set of attributes and a processing purpose for processing the subset of attributes. The method further includes associating each processing purpose with one or more entities that have authorized access to the subset of attributes for the processing purpose. The method further includes receiving requests for data for a particular processing purpose and selected views of database views. The method further includes retrieving a data-purpose object that indicates a particular processing purpose. The method further includes comparing a subset of attributes represented by a selected view with a subset of attributes shown in the retrieved data-purpose object. The method further includes providing, in response to determining that a subset of attributes represented by a selected view is a subset of the subset of attributes shown in the retrieved data-purpose object, the values of the subset of attributes represented in the selected view for entities associated with a particular processing purpose.
[0004] The method described above is advantageous in that it only allows conditional access to the data (based on processing purpose and selected view). For example, the method ensures that the data purpose object is searched based on a specific processing purpose for the data. The method further ensures that, before providing the values of the subset of attributes, the subset of attributes represented by the selected view is a subset of the subset of attributes shown in the searched data purpose object. This ensures that the view requested by a third party is within the constraints defined within the data purpose object (for example, based on user consent).
[0005] Embodiments of the present disclosure also relate to a system including one or more processors and one or more computer-readable storage media that store a collection of program instructions, when executed by one or more processors, configured to cause one or more processors to perform methods for conditional access to data in a database system, wherein the database system includes records, each record including a set of attributes. The database system may further include database views, each database view representing a subset of the set of attributes. The method includes storing data-purpose objects, each data-purpose object indicating a subset of attributes from the set of attributes and a processing purpose for processing the subset of attributes. The method further includes associating each processing purpose with one or more entities that have authorized access to the subset of attributes for the processing purpose. The method further includes receiving requests for data for a particular processing purpose and a selected view of a database view. The method further includes retrieving a data-purpose object indicating a particular processing purpose. The method further includes comparing a subset of attributes represented by a selected view with a subset of attributes indicated in the retrieved data-purpose object. The method further includes providing values for a subset of attributes represented in a selected view for an entity associated with a particular processing objective, in response to determining that a subset of attributes represented by a selected view is a subset of the subset of attributes represented in the retrieved data objective object.
[0006] The system described above advantageously allows only conditional access to the data (based on processing purpose and selected view). For example, the system ensures that data purpose objects are retrieved based on a specific processing purpose for the data. The system further ensures that, before providing the values of a subset of attributes, the subset of attributes represented by the selected view is a subset of the subset of attributes shown in the retrieved data purpose object. This ensures that the view requested by a third party is within the constraints defined within the data purpose object (for example, based on user consent).
[0007] Embodiments of this disclosure also relate to a computer program product comprising one or more computer-readable storage media and program instructions stored together on one or more computer-readable storage media, wherein the program instructions include instructions configured to cause one or more processors to perform a method for conditional access to data in a database system, and the database system includes records, each record including a set of attributes. The database system may further include database views, each database view representing a subset of the set of attributes. The method includes storing data-purpose objects, each data-purpose object indicating a subset of attributes from the set of attributes and a processing purpose for processing the subset of attributes. The method further includes associating each processing purpose with one or more entities that have authorized access to the subset of attributes for the processing purpose. The method further includes receiving requests for data for a particular processing purpose and a selected view of a database view. The method further includes retrieving a data-purpose object indicating a particular processing purpose. The method further includes comparing a subset of attributes represented by a selected view with a subset of attributes indicated in the retrieved data-purpose object. The method further includes providing values for a subset of attributes represented in a selected view for an entity associated with a particular processing objective, in response to determining that a subset of attributes represented by a selected view is a subset of the subset of attributes represented in the retrieved data objective object.
[0008] The computer program products described above advantageously allow only conditional access to the data (based on processing purpose and selected view). For example, the computer program products ensure that data-purpose objects are retrieved based on a specific processing purpose for the data. The computer program products further ensure that, before providing the values of a subset of attributes, the subset of attributes represented by the selected view is a subset of the subset of attributes shown in the retrieved data-purpose object. This ensures that the view requested by a third party is within the constraints defined within the data-purpose object (for example, based on user consent).
[0009] The above summary is not intended to describe any of the exemplary embodiments of this disclosure or any embodiment thereof.
[0010] The drawings included in this disclosure are incorporated into and form part of the specification. The drawings illustrate embodiments of the disclosure and, together with the descriptions, illustrate the principles of the disclosure. The drawings are illustrative of typical embodiments and do not limit the disclosure. [Brief explanation of the drawing]
[0011] [Figure 1] This is a block diagram of a computer system according to an embodiment of the present disclosure. [Figure 2] This is a flowchart illustrating an exemplary method for conditional access to data according to embodiments of the present disclosure. [Figure 3] This figure shows a collection of information regarding processing purposes and user agreements according to embodiments of the present disclosure. [Figure 4] This is a flowchart illustrating an exemplary method for conditional access to data according to embodiments of the present disclosure. [Figure 5A] This is a flowchart illustrating an exemplary method for conditional access to data according to embodiments of the present disclosure. [Figure 5B]This figure shows a database system and governance catalog according to an embodiment of the present disclosure. [Figure 6] This is a high-level block diagram showing an exemplary computer system used to implement one or more of the methods, tools, and modules described herein, as well as any related functions, according to embodiments of the present disclosure. [Figure 7] This figure shows a cloud computing environment according to an embodiment of the disclosure. [Figure 8] This figure shows the abstract model layer according to an embodiment of the present disclosure. [Modes for carrying out the invention]
[0012] The embodiments described herein follow various modifications and alternative forms, the details of which are shown in the drawings as examples and described in detail. However, it should be understood that the specific embodiments described are not to be taken as limiting. Rather, the intention is to encompass all modifications, equivalents, and alternatives that fall within the spirit and scope of the disclosure.
[0013] The aspects of this disclosure generally relate to the field of computing, and more specifically to conditional access to data. While this disclosure is not necessarily limited to such uses, various aspects of this disclosure can be understood through consideration of various embodiments using this context.
[0014] Access to data is necessary to perform actions on data, such as modifying data, deleting data, or using data for a particular processing purpose. Sharing access to data (e.g., granting access to data to one or more users) has its advantages. However, there are situations where data sharing can be problematic (e.g., with medical data). This can be addressed by incorporating conditional access to data. By applying conditional access to data, certain criteria may need to be met before granting access to data (e.g., access to data may be granted conditionally, such as consent policies and geographical restrictions). An entity may or may not authorize (e.g., consent to) access to its data depending on the processing purpose and the requesting party. For example, access to data for fraud analysis may require different access criteria than access to data for marketing purposes. Setting criteria for conditional data access can vary based on specific uses and can be challenging to implement properly.
[0015] This disclosure may enable data sharing in database systems, such as master data management (MDM) systems. A database system may include a database of records, each record having a set of attribute values. This disclosure may enable data subjects or entities to control specific uses of that data (e.g., through user consent). This can be achieved by preventing data entities from accessing records they have not consented to. Consent can be enforced at the database system level. The aspects of this disclosure are more flexible than methods of enforcing consent only at the application level. Consent can be enforced at the database level with very limited performance impact, as it can leverage existing storage capabilities. Many third-party systems with individual data access requirements may be supported. Third-party processing purposes may be defined, for example, in a governance catalog and incorporated into the database system.
[0016] This disclosure may incorporate criteria for conditional data access based on third parties requiring access to the data, entities owning the data, and available resources in the database system. This may enable the automated enforcement of conditional access to data in the database system. Information regarding third parties and associated authorizations may be collected. Relevant information about third parties may be stored as data purpose objects (e.g., in a business glossary or governance catalog). Data purpose objects refer to data structures such as files, arrays, and trees. Each data purpose object may contain information indicating a third-party system, the data processing purpose of the third-party system, and a subset of the set of attributes required for the data processing purpose. For example, a data purpose object may consist of a data structure such as a bitmap or list to represent the name of the processing purpose and a subset of attributes.
[0017] One or more data purpose objects may be associated with a third-party system. For example, a data purpose object may refer to specific data to be accessed and the reason for access by the third-party system. Authorization information may be provided as an array of pairs of entities and corresponding data processing purposes (for example, entries in the array may include user identification (ID) and the processing purpose to which the user has consented). Entities may have separate, isolated entities (e.g., a second entry in the database) and may have certain attributes to which values are assigned. For example, an employee or a company may be an entity. Possible attributes for an employee include name, date of birth, employee ID, etc. Entities may be represented by records, which may be a collection of attribute values.
[0018] Using database views and collected information, a database system can enable systematic conditional access to database data for different third parties based on the available resources of the database system. A database view may represent a stored query result set about data that a database user can query in the same way they would query persistent database collectible objects. Each database view in a database system may represent a subset of the data contained in the database. A database view may refer to a subset of attributes from a set of attributes. For example, a view may externalize an individual's social media handles.
[0019] In the embodiment, a data object includes a first bitmap (for example, configured to show a subset of attributes) that maps bits to a set of attributes in order, and a database view includes a second bitmap that maps bits to a set of attributes in the same order, the second bitmap configured to show a subset of attributes of the database view, and comparison is performed using the first and second bitmaps.
[0020] Each required attribute type may be mapped onto a bitmap, with each position within the bitmap corresponding to a type. The bitmap contains a number of bits equal to the number of sets of attributes, with each bit representing a respective attribute. Each bit of the bitmap may be set to indicate whether the associated attribute is to be considered (e.g., 0 may indicate that it is not considered and 1 may indicate that it is considered). For example, if the set of attributes includes address, date of birth, and name, the bitmap may contain three bits representing the three attributes in the order address -> date of birth -> name. Similarly, the bitmap of a database view may have the same number of bits following the same order as the attribute representation. If a subset of the attributes of a data target object includes name and address, the bits of the bitmap may be set to 101 (e.g., the bits associated with the subset of attributes are set to 1 and the remaining bits are set to 0). The bitmap of the database view may be provided and set in a similar manner so that comparisons between bitmaps can be completed. For example, if a subset of the attributes of a database view includes name, the bitmap may be set to 001.
[0021] By comparing the bitmap of the target object and the required database view, the method can determine whether the required view is included in the target. Following the above example, by comparing 101 and 001, it can be determined that the database view is included in the target (e.g., the subset of attributes of the target, address and name, includes the subset of attributes of the database view, name). This can save computing resources as it enables bit-level comparison which may occupy less storage space compared to other structures and be faster (e.g., compared to comparing strings). For example, a new view can be generated simply by specifying a bitmap without mapping it to a target. Consents can be added / removed by adding to / removing from the consent table.
[0022] In an embodiment, the data target object further includes a public key. The received request further indicates a signature (e.g., an encrypted digital signature). The method is to verify the signature using the public key of the retrieved data target object, and further includes verifying by comparing only when the validity of the signature is confirmed. Using the public key, a third party on the request side can authenticate the purpose by providing a signature encrypted with its own private key.
[0023] The signature may be, for example, a digital signature such as a hash of a message. The signature can be encrypted with the private key of a third party associated with the public key. To confirm the validity of the digital signature, the hash of the same message is calculated, the signature is decrypted using the public key, and they can be compared so that the validity of the signature is confirmed when the two resulting hash values are the same.
[0024] In an embodiment, associating each processing purpose of the processing purpose with one or more entities that have authorized access to a subset of the attributes of the above processing purpose includes generating a consent table, and each entry in the consent table includes the entity identifier (ID) of the entity and the associated processing purpose. Providing the values of the subset of attributes includes joining the consent table with the selected view so that it only includes the values of the subset of attributes for the entity associated with a particular processing purpose.
[0025] According to the above example, the consent table may include two entries referring to data target objects having a subset of attributes, an address, and a name. These two entries may be associated with two entity identifications (IDs) (e.g., user IDs). That is, the two entities have authorized or consented to access their names and addresses for the purposes indicated in the data target object. By joining the consent table and the selected view, the names of two users having the above user ID can be provided.
[0026] In this embodiment, the data object includes a first list containing a subset of its attributes, and the database view includes a second list containing a subset of the database view's attributes, and the comparison is performed using the first and second lists. For sparse data, lists may be more advantageous than bitmaps.
[0027] In embodiments, the method further includes providing a procedure. The procedure is configured to receive a specific processing purpose and a selected view as input, to perform the steps of searching, comparing, and providing, and is configured to be executed via an Application Programming Interface (API), where the receipt of requests is done by a function of the API that calls the procedure. By using stored procedures for access to a database system, consent can be enforced, and a third party may be able to access an individual's data for a given purpose only if that individual has consented to that purpose.
[0028] In embodiments, the method further includes receiving a request from a third-party system to register a processing purpose in the third-party system, and generating data purpose objects, each data purpose object further indicating the respective third-party system. For example, each data purpose object includes the name of the third-party system. This name of the third-party system may be, for example, the message used to generate the signature. This may be advantageous because both the third-party system and the database system can access the same message used for validating the signature.
[0029] Figure 1 shows a computer system 100 according to an embodiment of the present disclosure. The computer system 100 includes a database system 101 and one or more client systems 102a-102n (also called third-party systems 102a-102n). The database system 101 may be configured to communicate with each of the client systems 102a-102n via one or more networks 103. For simplicity of explanation, only one network is shown, but the database system 101 may connect to the client systems 102a-102n via more than one network (for example, the database system 101 may connect to each of the computer systems 102a-102n via their respective networks). Network 103 may include, but is not limited to, cable networks, fiber optic networks, hybrid fiber coaxial networks, wireless networks (e.g., Wi-Fi or mobile telephone networks or both), satellite networks, the Internet, intranets, local area networks, any other suitable networks, or any combination of these networks or combinations thereof.
[0030] The database system 101 may be remote to client systems 102a-102n, accessible via network 103. The database system 101 has a set of attributes att1, att2...att k Database 120 may contain values. A set of attributes represents an entity such as an individual or a company. Database 120 may be associated with database views 121a-121n. Each database view 121a-121n has a set of attributes att1, att2...att kIt may provide data for each subset of the attributes. For the sake of simplicity in the diagram, only one database view 121a is shown (but others may be constructed similarly). Database view 121a contains a bitmap or list 130 in which the data represents the subset of attributes provided by database view 121a.
[0031] The database system 101 may provide conditional access to the database 120 by client systems 102a to 102n using criteria. Criteria may be defined based on the data processing purpose and the authorization or consent provided by the entity accessing that data for that purpose.
[0032] The database system 101 may have access to the governance catalog 113. Although shown as a separate component, in another example, the database system 101 may include the governance catalog 113. The governance catalog 113 may include data purpose objects 105a to 105m. For the sake of simplicity in the diagram, only one data purpose object 105a is shown (but other data purpose objects may be constructed similarly). The data purpose object 105a includes information 108 indicating one of the third-party systems 102a to 102n. The data purpose object 105a includes the name of the processing purpose 107 (access reason) for processing data in the database system 101. As shown in Figure 1, the processing purpose 107 is defined as "marketing". The data purpose object 105a further includes a subset of attributes 109 used for the data processing purpose 107. The data purpose object 105a further includes a bitmap or list 110 showing the subset of attributes 109, and the public key 111 of the third-party system. One or more data purpose objects (e.g., data purpose objects 105a to 105m) may be stored for each third-party system 102a to 102n. Each purpose stored for a third party may use bitmaps for all types of data required by that purpose. For example, a marketing purpose may require access to email addresses. The database system 101 includes a consent table 123. The consent table 123 stores the entity IDs (e.g., user IDs) that have consented to a purpose and the name of that purpose.
[0033] The database system 101 may further include procedure 125. Procedure 125 may allow client systems 102a-102n to retrieve data, for example, if the entity associated with the data has consented to access. To this end, procedure 125 may retrieve the purpose from the governance catalog 113 and verify the signature using the public key 111. Procedure 125 may then grant access to the requested view if the data in the view is a subset of the data for which access has been permitted for the purpose. Stored procedure 125 may be implemented using existing database functionality, such as an application programming interface (API), or it may be built into the database as a query function. The embodiment may be advantageously used within the scope of database-as-a-service (DBaaS) cloud technologies.
[0034] Figure 2 is a flowchart illustrating exemplary methods 200 for conditional access to data according to some embodiments of the present disclosure. For illustrative purposes, methods 200 may be described in relation to the system 100 shown in Figure 1. However, methods 200 are not limited to the system 100 shown in Figure 1. Methods 200 may, in embodiments, be performed by a database system 101.
[0035] Method 200 is initiated in operation 201, where a request for data (e.g., from database 120) is received. The request for data may be for a specific processing purpose (e.g., data processing purposes within data purpose objects 105a-105m). The request may include the name of the specific processing purpose. The request may further indicate a selected view of database views 121a-121n. The views may be selected, for example, by the requester, or randomly (e.g., by the database system). Thus, the request indicates which data to access as shown in the selected view, and further indicates the purpose for which the data is accessed (e.g., the request includes the name of the purpose). The request may be received, for example, as an API call to stored procedure 125. Stored procedure 125 may be executed in this manner, and the execution of procedure 125 may include operations 203-211.
[0036] For the sake of simplicity, let's assume, as an example, that the database contains data describing a product. The database may include a set of attributes such as product, client age, purchase date, number of units purchased, mass, and size. The database views may be, for example, two database views DV1 and DV2, where database view DV1 has a subset of attributes for product, client age, and purchase date, and database view DV2 has a subset of attributes for mass, client age, and purchase date. A request for the received data may be used to perform statistical analysis to determine which age groups are interested in which products. A received request may refer to one of the two database views DV1 and DV2.
[0037] Upon receiving a request, the database system 101 may, in operation 203, retrieve data purpose objects 105a-105m that indicate a specific processing purpose. The name of the specific processing purpose may be compared with the entries for processing purpose 107 stored in the data processing objects 105a-105m, or a data processing object containing the name of the specific purpose may be retrieved from the governance catalog 113. If the requested specific processing purpose is not stored (for example, not part of the data processing objects 105a-105m), the request may be dismissed, and therefore access to the data may be denied.
[0038] In operation 205, the database system 101 compares a subset of attributes represented by the selected view with a subset of attributes shown in the retrieved data target object. For example, the bitmap (list) 130 of the selected view may be compared with the bitmap (list) 110 of the retrieved data target object to determine whether the subset of attributes represented by the selected view is a subset of the subset of attributes shown in the retrieved data target object.
[0039] Following the simplified example above, a subset of attributes of the retrieved data processing object associated with the specific purpose of the request—client age, purchase date, number of units purchased, and product—may be compared to a subset of attributes of database view DV1 (if the selected view is DV1), such as product, client age, and purchase date, or to a subset of attributes of database view DV2 (if the selected view is DV2), such as mass, client age, and purchase date. For example, if the selected view is DV2, the check fails because the subset of attributes, mass, age, and purchase date, are not part of the subset of attributes of the retrieved data processing object (they only overlap). For example, if the selected view is DV1, the check succeeds because the subset of attributes, age, purchase date, and product, are part of the subset of attributes of the retrieved data processing object.
[0040] In operation 207, if it is determined that the subset of attributes represented by the selected view is a subset of the subset of attributes shown in the retrieved data-purpose object, then in operation 209, values for the subset of attributes represented by the selected view for the entity associated with the particular processing purpose are provided. For example, each record in database 120 may be processed to determine the entity associated with the record, and the determined entity may be compared with entities listed in the consent table to check whether the determined entity has authorized or consented to use its data for the particular processing purpose received, and if it has authorized or consented, values for the subset of attributes 109 for each record may be provided.
[0041] In operation 207, if the subset of attributes represented by the selected view is not a subset of the subset of attributes shown in the retrieved data target object, then in operation 211, access to the data is denied (for example, the request is dismissed).
[0042] In this embodiment, operations 201 to 211 may be performed automatically for each received request.
[0043] The actions described above may be completed in any order, and are not limited to the order described. Furthermore, some or all of the actions described above may be completed, or none of them may be completed, while still remaining within the spirit and scope of this disclosure.
[0044] Figure 3 shows a set of information regarding processing purposes and user agreements according to an embodiment of the present disclosure.
[0045] One or more third-party systems may request (310) a new processing purpose. In response to the request, the requested processing purpose may be stored (312) in the governance catalog 113 (for example, as a data purpose object). After storing the data purpose object, an entity (for example, an individual or a company) may consent (314) to the given purpose of the stored data purpose object. A consenting entity may be added (316) to the consent table 123 for the given purpose. An entity may also revoke its consent (318) from the purpose. To this end, the consenting entity ID may be removed (320) from the consent table 123 for the given purpose. Operations 310 to 320 may enable the transmission of information about purposes and consents used by the database system 101 for conditional access to data. For example, a third-party system may request (322) access to data for a given purpose. In response, stored procedure 125 may be executed (324). The execution of a stored procedure may include identifying a stored data-purpose object that corresponds to a given purpose (326).
[0046] Figure 4 is a flowchart of an exemplary method 400 for conditional access to data according to embodiments of the present disclosure. For illustrative purposes, method 400 may be described in relation to system 100 shown in Figure 1. However, method 400 is not limited to system 100 shown in Figure 1. In embodiments, method 400 may be performed by a database system 101.
[0047] Method 400 is initiated in operation 401, when a data access request is received by a third-party system. The request may include a purpose name, database views 121a-121n, and a signature. In operation 403, the database system 101 retrieves data purpose objects 105a-105m for the entered purpose name from the governance catalog 113.
[0048] In operation 405, the validity of the received signature is verified using the public key of the retrieved data-purpose object to ensure that the requesting third party is the owner of the data-purpose object. In operation 407, if the signature is not verified, access is denied in operation 409 because the third party does not own the retrieved data-purpose object.
[0049] If the signature is validated in operation 407, operation 411 determines whether the bitmap 130 of the requested view is a subset of the target bitmap 110. This indicates that all data in the view is included by the purpose. If, in operation 413, it is determined that the bitmap 130 of the requested view is not a subset of the target bitmap 110, then access is denied in operation 415 because the view contains data that is not subject to consent for this purpose.
[0050] In operation 413, if it is determined that the bitmap 130 of the requested view is a subset of the target bitmap 110, in operation 417, the consent table is joined with the view so that it contains only the data of users who have consented to the requested purpose. The joined data is then returned (for example, presented on a graphical user interface (GUI)). This is shown in operation 419.
[0051] Figure 5A is a flowchart illustrating an exemplary method 500 for conditional access to data according to an embodiment of the present disclosure. For illustrative purposes, the method 500 described in Figure 5A may be implemented in the system shown in Figure 5B.
[0052] Figure 5B shows an exemplary database system 501 and governance catalog 513. The governance catalog 513 stores two data objective objects 505a and 505b. Data objective object 505a represents an objective named "Marketing," and data objective object 505b represents an objective named "Fraud Analysis." Each of data objective objects 505a and 505b may contain information similar to that described for the data objective objects in Figure 1.
[0053] The database system 501 includes a database view 521, a consent table 523, and a stored procedure 525. In operation 531 of method 500, the database system 501 receives a request to access data. The request includes a list of inputs required by the stored procedure 525, which are the purpose name, the selected view, and the signature. In response, the database system 501 executes the stored procedure 525 using the inputs in operation 533 of method 500. The execution of procedure 525 may perform operations 203 to 211 in Figure 2, for example, to grant or deny access to the requested data. As shown by the exemplary pseudocode in Figure 5B, the procedure may retrieve the purpose from the governance catalog 513 and verify the signature using the public key. The procedure may then grant access to the requested view if the data in the view is a subset of the data that the purpose has been granted access to.
[0054] For example, for marketing purposes, a credit company might request data from database system 101 to find out which products user ID "15" "Jane Doe" purchased. Database system 101 might allow this request because the bitmap of the accessed view is a subset of the access that Jane has granted to the credit company for a given purpose.
[0055] In another example, a fraudulent company might request data from database system 101 for marketing purposes to find out which products user ID "15" "Jane Doe" purchased. Since there is no "marketing" purpose for this company, database system 101 cannot permit this request.
[0056] In another example, for marketing purposes, a credit company might request data from database system 101 to find out which products user ID "16" "John Doe" purchased. Database system 101 cannot grant this request because user 16 (John) has not consented to data access.
[0057] In another example, for the purpose of fraudulent analysis, a fraudulent company might request data from database system 101 to find out which products user ID "15" "Jane Doe" purchased. Database system 101 cannot allow this request because the bitmap of the product view is not a subset intended for "fraudulent analysis" purposes.
[0058] Referring now to Figure 6, a high-level block diagram of an exemplary computer system 601 is shown, which may be used in various devices described herein (e.g., database system 101 and client system 102a) according to embodiments of the present disclosure, and which may be used to implement one or more of the methods, tools, and modules described herein, as well as any related functions (e.g., using one or more processor circuits or computer processors of a computer). In some embodiments, the main components of the computer system 601 may include one or more CPUs 602 (also referred to herein as processors), memory 604, terminal interface 612, storage interface 614, I / O (input / output) device interface 616, and network interface 618, all of which may be communicatively connected directly or indirectly for intercomponent communication via memory bus 603, I / O bus 608, and I / O bus interface unit 610.
[0059] The computer system 601 may include one or more general-purpose programmable central processing units (CPUs) 602A, 602B, 602C, and 602D, which are generally referred to herein as CPUs 602. In some embodiments, the computer system 601 may include multiple processors, which are typical of relatively large systems, while in other embodiments, the computer system 601 may alternatively be a single CPU system. Each CPU 602 may execute instructions stored in the memory subsystem 604 and may include one or more levels of onboard cache.
[0060] Memory 604 may include computer system-readable media in the form of volatile memory such as random access memory (RAM) 622 or cache memory 624. Computer system 601 may further include other removable / non-removable, volatile / non-volatile computer system storage media. As just one example, storage system 626 may be provided for reading from and writing to non-removable non-volatile magnetic media such as “hard drives”. Although not shown, magnetic disk drives for reading from and writing to removable non-volatile magnetic disks (e.g., “floppy disks”) or optical disk drives for reading from or writing to removable non-volatile optical disks such as CD-ROMs, DVD-ROMs, or other optical media may be provided. In addition, memory 604 may include flash memory, such as flash memory stick drives or flash drives. Memory devices may be connected to memory bus 603 by one or more data medium interfaces. The memory 604 may include at least one program product having a set of program modules (e.g., at least one) configured to perform functions of various embodiments.
[0061] One or more programs / utilities 628, each having at least one set of program modules 630, may be stored in memory 604. A program / utility 628 may include a hypervisor (also called a virtual machine monitor), one or more operating systems, one or more application programs, other program modules, and program data. Each of the operating systems, one or more application programs, other program modules, and program data, or any combination thereof, may include an embodiment of a networking environment. A program / utility 628 or program module 630, or both, generally performs functions or methodologies of various embodiments.
[0062] In Figure 6, the memory bus 603 is shown as a single bus structure providing a direct communication path between the CPU 602, memory 604, and I / O bus interface 610. However, in some embodiments, the memory bus 603 may include multiple different buses or communication paths, which may be arranged in any of various forms, such as hierarchical point-to-point links, star or web configurations, multi-layer buses, parallel and redundant paths, or any other suitable type of configuration. Furthermore, the I / O bus interface 610 and I / O bus 608 are shown as single units, respectively, and the computer system 601 may include multiple I / O bus interface units 610, multiple I / O buses 608, or both in some embodiments. Additionally, multiple I / O interface units are shown to isolate the I / O bus 608 from various communication paths to various I / O devices, although in other embodiments, some or all of the I / O devices may be directly connected to one or more system I / O buses.
[0063] In some embodiments, the computer system 601 may be a multi-user mainframe computer system, a single-user system, or a server computer or similar device that has little or no direct user interface but receives requests from other computer systems (clients). Furthermore, in some embodiments, the computer system 601 may be implemented as a desktop computer, a portable computer, a laptop or notebook computer, a tablet computer, a pocket computer, a telephone, a smartphone, a network switch or router, or any other suitable type of electronic device.
[0064] It should be noted that Figure 6 is intended to show typical main components of an exemplary computer system 601. In some embodiments, however, individual components may have greater or less complexity than those shown in Figure 6, and there may be components other than or in addition to those shown in Figure 6, and the number, types, and configuration of such components may vary.
[0065] While this disclosure includes a detailed description of cloud computing, it should be understood that the embodiments of the teachings set forth herein are not limited to cloud computing environments. Rather, embodiments of this disclosure can be implemented in conjunction with any other type of computing environment that is currently known or may be developed in the future.
[0066] Cloud computing is a service delivery model that enables convenient on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that are rapidly supplied and released with minimal administrative effort or interaction with service providers. This cloud model may include at least five characteristics, at least three service models, and at least four deployment models.
[0067] The characteristics are as follows:
[0068] On-demand self-service: Cloud consumers can unilaterally access computing capabilities such as server time and network storage as needed, automatically and without requiring human interaction with service providers.
[0069] Broad network access: Capabilities are available over the network and accessed through standard mechanisms that facilitate use by heterogeneous thin-client or thick-client platforms (e.g., mobile phones, laptops, and PDAs).
[0070] Resource sharing: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically allocated and reallocated as needed. Location independence has implications in that consumers generally do not have control or knowledge of the exact location of the resources provided, but may be able to specify the location at a higher level of abstraction (e.g., country, state, or data center).
[0071] Rapid Scalability: Capabilities can be supplied quickly and flexibly to scale out instantly, sometimes automatically, and released quickly to scale in instantly. To consumers, the available capabilities for supply often appear unlimited and can be purchased at any quantity at any time.
[0072] Measurable Services: Cloud systems automatically control and optimize resource usage by leveraging measurable capabilities at a level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both service providers and consumers.
[0073] The service model is as follows:
[0074] Software as a Service (SaaS): The capability offered to consumers is the use of a provider's applications running on cloud infrastructure. These applications are accessible from various client devices through thin-client interfaces such as web browsers (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, storage, or even individual application capabilities, with the exception of potentially limited user-specific application configuration settings.
[0075] Platform as a Service (PaaS): The capability offered to consumers is the deployment of consumer-created or acquired applications, written using programming languages and tools supported by the provider, onto cloud infrastructure. Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but they have control over the deployed applications and, where possible, the application hosting environment configuration.
[0076] Infrastructure as a Service (IaaS): The capabilities offered to consumers are the provision of processing, storage, networking, and other basic computing resources that enable consumers to deploy and run any software, including operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but they do have control over the operating system, storage, and deployed applications, and, where possible, limited control over select networking components (e.g., host firewalls).
[0077] The deployment model is as follows:
[0078] Private Cloud: Cloud infrastructure is operated exclusively for a specific organization. The cloud infrastructure may be managed by that organization or a third party, and may reside on or off-premises.
[0079] Community Cloud: Cloud infrastructure is shared by multiple organizations to support a specific community with shared concerns (e.g., missions, security requirements, policies, and compliance considerations). Cloud infrastructure may be managed by an organization or a third party and may reside on-premises or off-premises.
[0080] Public Cloud: Cloud infrastructure is made available to the general public or large industry groups and is owned by organizations that sell cloud services.
[0081] Hybrid Cloud: Cloud infrastructure remains a unique entity, but it is a composite of two or more clouds (private, community, or public) joined together by standardized or proprietary technologies (e.g., cloud bursting for load balancing between clouds) that enable data and application portability.
[0082] Cloud computing environments are service-oriented, centered on statelessness, low coupling, modularity, and semantic interoperability. At the heart of cloud computing is the infrastructure, including a network of interconnected nodes.
[0083] Referring here to Figure 7, an exemplary cloud computing environment 50 is shown. As illustrated, the cloud computing environment 50 includes one or more cloud computing nodes 10 that can communicate with local computing devices used by cloud consumers, such as personal digital assistants (PDAs) or mobile phones 54A (e.g., client system 102a), desktop computers 54B, laptop computers 54C, or automotive computer systems 54N, or a combination thereof. The nodes 10 can communicate with each other. They can be grouped physically or virtually within one or more networks, such as a private cloud, community cloud, public cloud, or hybrid cloud, or a combination thereof, as described above (not shown). This makes it possible for the cloud computing environment 50 to offer infrastructure, platforms, or software, or a combination thereof, as a service that does not require cloud consumers to maintain resources on their local computing devices. The types of computing devices 54A to 54N shown in Figure 7 are intended to be illustrative only, and it should be understood that the computing node 10 and the cloud computing environment 50 may communicate with any type of computerized device via any type of network or network-addressable connection or both (e.g., using a web browser).
[0084] Referring now to Figure 8, a set of functional abstraction layers provided by the cloud computing environment 50 (Figure 7) is shown. The components, layers, and functionalities shown in Figure 8 are intended to be illustrative only, and embodiments of this disclosure are not limited thereto. As illustrated, the following layers and corresponding functionalities are provided:
[0085] The hardware and software layer 60 includes hardware and software components. Examples of hardware components include a mainframe 61, a RISC (Reduced Instruction Set Computer) architecture-based server 62, a server 63, a blade server 64, a storage device 65, and network and networking components 66. In some embodiments, the software components include network application server software 67 and database software 68.
[0086] The virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities are provided: virtual servers 71, virtual storage 72, virtual networks 73 including virtual private networks, virtual applications and operating systems 74, and virtual clients 75.
[0087] For example, the management layer 80 may provide the functions described below. Resource supply 81 provides dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment. Measurement and pricing 82 provides cost tracking when resources are used within the cloud computing environment and charges or invoices are issued for the consumption of these resources. For example, these resources may include application software licenses. Security provides identity verification for cloud consumers and tasks, as well as protection for data and other resources. The user portal 83 provides consumers and system administrators with access to the cloud computing environment. Service level management 84 provides cloud computing resource allocation and management to ensure that the required service levels are met. Service level agreement (SLA) planning and execution 85 provides pre-positioning and procurement of cloud computing resources where future requirements are anticipated in accordance with the SLA.
[0088] The workload layer 90 provides examples of functions that utilize the cloud computing environment. Examples of workloads and functions provided from this layer include mapping and navigation 91, software development and lifecycle management 92, virtual classroom education delivery 93, data analysis processing 94, transaction processing 95, and conditional data access management 96.
[0089] As will be described in more detail herein, some or all of the operations of some embodiments of the methods described herein may be performed in an alternative order, or not performed at all. Furthermore, multiple operations may occur simultaneously or as internal parts of a larger process.
[0090] This disclosure may be a system, method, or computer program product, or a combination thereof. A computer program product may include a computer-readable storage medium (or more mediums) having computer-readable program instructions thereon for causing a processor to perform an aspect of this disclosure.
[0091] A computer-readable storage medium may be a tangible device capable of holding and storing instructions for use by an instruction execution device. A computer-readable storage medium may, but is not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of those described above. A non-exhaustive list of more specific examples of computer-readable storage media includes portable computer diskettes, hard disks, random-access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random-access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disks (DVDs), memory sticks, floppy(R) disks, mechanically encoded devices such as punch cards or grooved raised structures on which instructions are recorded, and any suitable combination of those described above. The computer-readable storage media used herein should not be interpreted as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmitting media (e.g., light pulses passing through optical fiber cables), or electrical signals transmitted through wires.
[0092] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing / processing device, or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface within each computing / processing device receives computer-readable program instructions from the network and transfers the computer-readable program instructions for storage on a computer-readable storage medium within each computing / processing device.
[0093] The computer-readable program instructions for performing the operations of the Disclosure may be either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk(R) and C++, and conventional procedural programming languages such as the C programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be to an external computer (for example, via the Internet using an Internet service provider). In some embodiments, electronic circuits including, for example, a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer-readable program instructions by individualizing the electronic circuit using state information of computer-readable program instructions in order to perform aspects of the present disclosure.
[0094] Aspects of this disclosure are described herein by reference to flowcharts or block diagrams, or both, of methods, apparatus (systems), and computer program products as provided in the embodiments of the disclosure. Each block in a flowchart or block diagram, or both, and any combination of blocks in a flowchart or block diagram, should be understood to be implemented by computer-readable program instructions.
[0095] These computer-readable program instructions may be provided to a general-purpose computer, a dedicated computer, or a processor of another programmable data processing device to create a machine, such that instructions executed by the processor of a computer or other programmable data processing device generate means to perform functions / operations specified in one or more blocks of a flowchart or block diagram, or both. Alternatively, these computer-readable program instructions may be stored on a computer-readable storage medium so that the storage medium containing the instructions includes a product containing instructions that perform modes of functions / operations specified in one or more blocks of a flowchart or block diagram, or both, and can instruct a computer, a programmable data processing device, or other device, or a combination thereof, to function in a particular manner.
[0096] Furthermore, computer-readable program instructions may be loaded onto a computer, other programmable device, or other device to create a computer execution process in which instructions executed on the computer, other programmable device, or other device perform functions / operations specified in one or more blocks of a flowchart or block diagram, or both, thereby causing the computer, other programmable device, or other device to execute a series of operational steps.
[0097] The flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible embodiments of the systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or part of an instruction containing one or more executable instructions for performing a specified logical function. In some alternative embodiments, the functions described within a block may occur in an order other than that shown in the drawings. For example, two consecutively shown blocks may actually be executed simultaneously, substantially simultaneously, partially or entirely in overlapping time, to be realized as a single step, or blocks may be executed in reverse order depending on the functionality involved. It should also be noted that each block in a block diagram or flowchart, or both, and any combination of blocks in a block diagram or flowchart, or both, is performed by a dedicated hardware-based system that performs a specified function or operation, or a combination of dedicated hardware and computer instructions.
[0098] The technical terms used herein are for the sole purpose of describing specific embodiments and are not intended to limit the various embodiments. As used herein, the singular forms “a,” “an,” and “the” are intended to include the plural forms as well, unless the context specifically indicates otherwise. It should be further understood that the terms “includes” or “contains,” when used herein, indicate the presence of a described feature, integer, step, operation, element, or component, or combination thereof, and do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, or sets thereof, or combination thereof. In the preceding detailed descriptions of exemplary embodiments of the various embodiments, references have been made to the accompanying drawings (similar numbers indicating similar elements). The accompanying drawings form part of this specification and illustrate, as examples, specific exemplary embodiments in which the various embodiments are carried out. These embodiments have been described in sufficient detail to enable those skilled in the art to carry out the embodiments; however, other embodiments may be used, and logical, mechanical, electrical, and other modifications may be made without departing from the scope of the various embodiments. In the preceding description, many specific details were provided to give a complete understanding of the various embodiments. However, various embodiments may be carried out without these specific details. In other examples, well-known circuits, structures, and techniques are not shown in detail so as not to obscure the embodiments.
[0099] Different examples of the term “embodiment” as used herein do not necessarily refer to the same embodiment, but may refer to the same embodiment. Any data and data structures shown or described herein are merely examples, and in other embodiments, different amounts of data, types of data, fields, number and types of fields, field names, number and types of rows, records, entries, or data organization may be used. In addition, any data may be combined with logic so that individual data structures are not necessary. Therefore, the above detailed descriptions should not be taken as limiting.
[0100] The descriptions of the various embodiments of this disclosure are presented for illustrative purposes only and are not intended to be exhaustive or limit the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein has been selected to best describe the principles of the embodiments, their practical applications, or the technical improvements to the technology available on the market, or to make the embodiments disclosed herein understandable to others skilled in the art.
[0101] While this disclosure describes specific embodiments, modifications and alterations thereto will be obvious to those skilled in the art. Therefore, the following claims are intended to be construed as encompassing all such modifications and alterations as being in the true spirit and scope of this disclosure.
[0102] Herein, several embodiments are provided to further clarify the various aspects of this disclosure.
[0103] Example 1: A computer implementation method for conditional access to data in a database system, wherein the database system includes records, each record includes a set of attributes, the database system further includes database views, each database view represents a subset of the set of attributes, and the method stores data-purpose objects, each data-purpose object indicating a subset of attributes from the set of attributes and a processing purpose for processing the subset of attributes; associates each data-purpose purpose with one or more entities that have authorized access to the subset of attributes for the data-purpose purpose; receives a request for data about a specific processing purpose of the data-purpose purpose and a selected view of the database view; retrieves a data-purpose object indicating a specific processing purpose; compares a subset of attributes represented by the selected view with a subset of attributes shown in the retrieved data-purpose object; and, in response to determining that a subset of attributes represented by the selected view is a subset of the subset of attributes shown in the retrieved data-purpose object, provides the values of the subset of attributes represented in the selected view for the entities associated with the specific processing purpose.
[0104] Example 2: A limitation of Example 1, wherein a data object includes a first bitmap that maps bits to a set of attributes in order, the first bitmap being configured to show a subset of attributes, and a database view includes a second bitmap that maps bits to a set of attributes in the order described above, the second bitmap being configured to show a subset of attributes of the database view, and comparison is performed using the first and second bitmaps.
[0105] Example 3: A limitation of either Example 1 or 2, wherein the data object further includes a public key, the received request further indicates a signature, and the method further includes verifying the signature using the public key of the retrieved data object, the comparison being performed only if the validity of the signature is confirmed.
[0106] Example 4. Any limitation of Examples 1-3, comprising generating an agreement table such that each entry in the agreement table includes the entity identifier (ID) of the entity and the associated processing purpose, and providing the values of the subset of attributes includes only the values of the subset of attributes for the entity associated with a particular processing purpose.
[0107] Example 5. Any limitation of Examples 1-4, wherein the data target object includes a first list containing a subset of attributes, and the database view includes a second list containing a subset of attributes of the database view, and the comparison is performed using the first and second lists.
[0108] Example 6. A provision of any of Examples 1-5, further comprising providing a procedure configured to receive a specific processing purpose and a selected view as input, and to perform searching, comparing, and providing; and executing the procedure via an Application Programming Interface (API), wherein the receipt of requests is performed by a function of the API that calls the procedure.
[0109] Example 7. Any limitation of Examples 1-6, further comprising receiving a request from a third-party system to register a processing purpose in the third-party system, and generating a data purpose object, wherein each data purpose object further indicates the respective third-party system.
[0110] Example 8. A system comprising one or more processors and one or more computer-readable storage media that store a collection of program instructions, when executed by one or more processors, configured to cause the processors to perform the method according to any of Examples 1-7.
[0111] Example 9. A computer program product comprising one or more computer-readable storage media and program instructions stored together on one or more computer-readable storage media, wherein the program instructions include instructions configured to cause one or more processors to execute the method according to any one of Examples 1-7.
Claims
1. A computer information processing method for conditional access to data in a database system, wherein the database system includes records, each record includes a set of attributes, the database system includes database views, each database view represents a subset of the set of attributes, and the method The storage of data purpose objects, wherein each data purpose object indicates a subset of attributes from the set of attributes and a processing purpose for processing the subset of attributes, Associating each processing purpose with one or more entities that have authorized access to a subset of the attributes of the processing purpose, Receiving requests for data (including information indicating the selected view) for a specific processing purpose and for a selected view of the database view held in the database system, Searching for a data object that indicates the aforementioned specific processing purpose, Comparing the subset of attributes represented by the selected view with the subset of attributes shown in the retrieved data object, In response to determining that the subset of attributes represented by the selected view is a subset of the subset of attributes shown in the retrieved data-purpose object, the values of the subset of attributes represented in the selected view for the entity associated with the particular processing purpose are provided. Methods that include...
2. The method according to claim 1, wherein the data object includes a first bitmap that maps bits to the set of attributes in order, the first bitmap being configured to show a subset of the attributes, the database view includes a second bitmap that maps bits to the set of attributes in order, the second bitmap being configured to show a subset of the attributes of the database view, and the comparison is performed using the first bitmap and the second bitmap.
3. The data object further includes a public key, the received request further includes a signature, and the method The method according to claim 1, further comprising verifying the signature using the public key of the retrieved data target object, wherein the comparison is performed only if the validity of the signature is confirmed.
4. The method according to claim 1, comprising generating an agreement table, wherein each entry in the agreement table includes the entity identifier (ID) of the entity corresponding to the associated processing purpose and the associated processing purpose, and joining the agreement table with the selected view, wherein providing the values of the subset of attributes includes only the values of the subset of attributes for the entity associated with the particular processing purpose.
5. The method according to claim 1, wherein the data object includes a first list containing a subset of the attributes, the database view includes a second list containing a subset of the attributes of the database view, and the comparison is performed using the first list and the second list.
6. Providing a procedure, wherein the procedure is configured to receive the specific processing purpose and the selected view as input, and to perform the searching, the comparing, and the provision of values for a subset of the attributes represented in the selected view, The method according to claim 1, further comprising executing the procedure via an application programming interface (API), wherein the reception of the request is performed by a function of the API that calls the procedure.
7. It is a system, One or more processors, One or more computer-readable storage media that store a collection of program instructions, which, when executed by the one or more processors, cause the one or more processors to perform a method for conditional access to data in a database system, wherein the database system includes records, each record includes a set of attributes, the database system includes database views, each database view represents a subset of the set of attributes, and the method is The storage of data-purpose objects in one or more computer-readable storage media, wherein each data-purpose object indicates a subset of attributes from the set of attributes and a processing purpose for processing the subset of attributes, Associating each processing purpose with one or more entities that have authorized access to a subset of the attributes of the processing purpose, To receive requests for data for a specific processing purpose and for a selected view of the database view held in the database system (including information indicating the selected view), Searching for a data object that indicates the aforementioned specific processing purpose, Comparing the subset of attributes represented by the selected view with the subset of attributes shown in the retrieved data object, and One or more computer-readable storage media, including providing values for the subset of attributes represented in the selected view for an entity associated with a particular processing purpose, in response to determining that the subset of attributes represented in the selected view is a subset of the subset of attributes shown in the retrieved data-purpose object; A system equipped with these features.
8. The system according to claim 7, wherein the data object includes a first bitmap that maps bits to the set of attributes in order, the first bitmap being configured to show a subset of the attributes, the database view includes a second bitmap that maps bits to the set of attributes in order, the second bitmap being configured to show a subset of the attributes of the database view, and the comparison is performed using the first bitmap and the second bitmap.
9. The data object further includes a public key, the received request further includes a signature, and the method The system according to claim 7, further comprising verifying the signature using the public key of the retrieved data target object, wherein the comparison is performed only if the validity of the signature is confirmed.
10. The system according to claim 7, comprising generating an agreement table such that each processing purpose is associated with one or more entities that have authorized access to a subset of the attributes of the processing purpose, and joining the agreement table with the selected view such that each entry in the agreement table includes the entity identifier (ID) of the entity corresponding to the associated processing purpose and the associated processing purpose, and providing values for the subset of attributes includes only the values for the subset of attributes for the entity associated with the particular processing purpose.
11. The system according to claim 7, wherein the data object includes a first list containing a subset of the attributes, the database view includes a second list containing a subset of the attributes of the database view, and the comparison is performed using the first list and the second list.
12. The method performed by the one or more processors is Providing a procedure, wherein the procedure is configured to receive the specific processing purpose and the selected view as input, and to perform the searching, the comparing, and the provision of values for a subset of the attributes represented in the selected view, The system according to claim 7, further comprising executing the procedure via an application programming interface (API), wherein the reception of the request is performed by a function of the API that calls the procedure.
13. The system according to claim 7, wherein the data object is stored remotely from the database system.
14. A computer program that causes a computer to perform the method described in any one of claims 1 to 6.
15. A storage medium storing the computer program described in claim 14 in one or more computer-readable storage media.
Citation Information
Patent Citations
Access control system
JP2006155074A
Predicted data use obligation match using data differentiators
US20210294853A1