Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

284 results about "Data access control" patented technology

Data Access Control gives customers the ability to customize and control what areas their users can access within Zuora. Data Access Control allows you do the following: Restrict what products and accounts your users can see within Zuora​​. Data Access Control is ONLY enforced on UI users, not API users.

Private AI question and answer method, system and device and medium

The invention discloses a privatized AI question and answer method, system and device and a medium, and relates to the technical field of artificial intelligence, and the method comprises the steps: collecting a file archive data set, and constructing a local digital knowledge base; selecting an AI semantic large model architecture; performing annotation enhancement on a local digital knowledge base by using an AI semantic large model architecture, and constructing a knowledge base AI question and answer model; performing permission marking on the local digital knowledge base based on a user access control rule, and establishing a knowledge base retrieval mechanism; and integrating and fusing the knowledge base retrieval mechanism and the knowledge base AI question-answering model to generate a retrieval enhanced AI question-answering model, performing semantic question-answering retrieval on the request question information, and outputting a user request question-answering result. The technical problem that in the prior art, data security, intelligent question answering and information retrieval efficiency are insufficient is solved, and the technical effect of improving intelligence and data access control of the question answering system is achieved.
Owner:SUIZHONG POWER GENERATION CO LTD

Linux access control system based on attributes

The invention provides a Linux access control system based on attributes, and relates to the technical field of data access control. The system comprises a system monitor module, a data interaction module and a decision unit. The system monitor module collects attributes from a kernel and a user space and writes the attributes into the data interaction module; the access decision unit compiles the access control strategy into an eBPF program and mounts the eBPF program to a corresponding hook; executing the kernel to the hook, and triggering an eBPF program; an eBPF program queries a Flow rule; matching the attribute with the Flow rule, and if the matching is successful, executing a corresponding action; if all the Flow rules fail to match, executing a default action; the system can be expanded during operation, and can be loaded or unloaded based on dynamic loading characteristics and strategies of the eBPF program and the eBPF program during operation of the system, so that the problem that a kernel needs to be compiled in a traditional LSM scheme is solved; the method does not intrude the kernel, is completely based on an eBPF program, does not modify a kernel source code, and can guarantee the stability and compatibility.
Owner:SICHUAN UNIV

Highway-oriented full-process digital collaborative management system and method

The invention discloses a road-oriented full-process digital collaborative management system and method, particularly relates to the technical field of road data management, and is used for solving the problem of abnormal multi-role collaborative conflict recognition. According to the method, dynamic linkage management of task states and role behaviors in the whole highway design process is achieved by building the task-driven atlas and the multi-role scheduling model, and the dynamic linkage management of the task states and the role behaviors in the whole highway design process is achieved by extracting access behaviors, task records and data version states, calculating role collaborative offset and recognizing and controlling the write-in permission of task conflict nodes. A priority factor is constructed based on a stage index, data dependence and a time urgency degree, a nonlinear model is adopted to generate scores, automatic reconstruction of a scheduling sequence and data ownership is driven, role permission and a collaborative view are synchronously updated, a data access control closed loop based on task state evolution is formed, and a three-dimensional responsibility chain is constructed by whole-process behavior traces. The traceable management of collaborative operation is realized, and the intelligence of collaborative scheduling and the accuracy of data management are improved.
Owner:JIANGXI HIGHWAY RES & DESIGN INST CO LTD

Multi-level dynamic data access control method and device based on credential environment

The invention provides a multi-level dynamic data access control method and device based on a credential environment, and the method comprises the steps: obtaining a data access request initiated by a user and associated environment state information, carrying out the multi-factor authentication processing of a user identity, and combining the pre-stored user role attribute information and responsibility division data, thereby achieving the multi-level dynamic data access control. Generating an initial permission set of the user for the data resource identifier; extracting historical access behavior records of the user in the credential environment to generate historical access behavior characteristics, extracting real-time state characteristics in combination with the environment state information, performing association analysis on the historical access behavior characteristics and the real-time state characteristics, and generating a risk assessment result of the user access behavior; and adjusting access permission configuration of the user to the data resource identifier, generating a permission control instruction, and executing permission control operation of accessing the data resource identifier by the user. According to the method, the accuracy, the dynamic adaptability, the safety and the reliability of data access control in the credential environment are improved.
Owner:GONGCHENG MANAGEMENT CONSULTING

Multi-level data encryption storage and access control method based on cloud computing

The invention is applied to the technical field of data storage, and particularly discloses a multilevel data encryption storage and access control method based on cloud computing, which comprises the following steps of: 1, data classification and multilevel encryption; step 2, constructing a layered secret key; step 3, data access control; and 4, constructing and dynamically updating the data access authority. According to the multi-level data encryption storage and access control method based on cloud computing, encryption grade division is performed on data according to the data confidentiality degree, and algorithm encryption with different intensities is performed on the data according to different encryption grades, so that encryption can be performed for different types of data, and compared with traditional single algorithm encryption, the encryption efficiency is improved. According to the technical scheme, the adaptability of data encryption can be improved, meanwhile, three levels of key structures are arranged to be matched with one another, the main key protects the middle key, the middle key isolates direct association of the main key, the working key and the data, and the exposure risk of the main key is reduced.
Owner:SHANGHAI TECHN INST OF ELECTRONICS & INFORMATION

Attribute-based encrypted medical data sharing method based on dynamic NFT

The invention discloses a dynamic NFT-based attribute-based encrypted medical data sharing method, which comprises the following steps that: firstly, a user submits identity authentication information to a trusted digital identity platform, and applies for an attribute certificate from an institution to which the user belongs; secondly, the key management system completes system initialization and generates a master key and a public key, the medical data owner generates an attribute-based encrypted ciphertext according to the access strategy and casts a dynamic NFT according to the smart contract, and when the medical data demander conforms to the access strategy, the medical data owner issues a sub-NFT of the dynamic NFT to the medical data demander through the smart contract; and then the medical data demander applies for a master key from the key management system and decrypts the ciphertext. And finally, the medical data owner changes the access strategy and re-judges whether the medical data demander conforms to the access strategy. According to the invention, the data access control does not depend on a fixed strategy any more, and the controllability and security of the data access control are enhanced.
Owner:HANGZHOU DIANZI UNIV

Zero-trust data access control method and system and storage medium

The invention discloses a zero-trust data access control method and system and a storage medium, and the method comprises the steps: carrying out the identity authentication of a user logging in a client, and obtaining the current terminal equipment information of the client, the current network information and the historical access information of the user after the authentication succeeds, the trust level of the authorization request and the current access permission matched with the trust level are obtained; acquiring a real-time access action of a user and real-time terminal equipment information and real-time network information of a client to perform threat detection on the authorization request, and adjusting the current access permission so as to generate a real-time access strategy corresponding to the client according to the adjusted real-time access permission; and acquiring a data access request uploaded by the client according to the real-time access strategy, acquiring access data required by the client according to the access request, and sending the encrypted access data to the client, thereby improving the security of data access.
Owner:GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD

Block chain-based trusted data space cross-domain access control method, system and device, and medium

The invention relates to the technical field of data cross-domain access control, in particular to a block chain-based trusted data space cross-domain access control method, system and device and a medium, comprising: receiving a data access request, and analyzing a target data identifier, a target heterogeneous system identifier and access scene information; obtaining the data attribute of the target data according to the target data identifier, generating a dynamic access strategy in combination with the access scene information, and deploying the dynamic access strategy into the block chain; mapping the dynamic access strategy into an equivalent access control rule, and converting the data access request into target compatible request data; verifying zero-knowledge proof provided by the user based on an equivalent access control rule and a user public key; after the verification is passed, routing the target compatible request data to the target heterogeneous system; and the target heterogeneous system generates original response data, converts the original response data into user-side compatible response data and returns the user-side compatible response data to the user. According to the invention, cross-system efficient cooperation is realized, and the real-time adaptability and privacy enhancement security of access control can be improved.
Owner:INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD

Network data security protection method and system based on multi-dimensional right control

The invention relates to the related technical field of zero-trust networks, in particular to a network data security protection method and system based on multi-protection right control, and the method comprises the steps: connecting a terminal and a protection center, setting a primary authorization mechanism, starting hierarchical authorization of a right group, evaluating the risk in real time, interrupting the access if the risk does not accord with the threshold, and carrying out the threat sharing. The technical problems that the authority is allocated only according to a fixed role, the enterprise business scene change and the user actual demand change cannot be adapted, the access of the user to the isolated data area resource is lack of fine-grained control, the situation of excessive authority granting or insufficient authority granting is easy to occur, and the data leakage risk is increased are solved; according to the invention, dynamic hierarchical management of the authority is realized by constructing a primary authorization authentication mechanism and a hierarchical authorization authentication mechanism, the authority is minimized to a single service instance, and fine-grained partitioning is carried out on resources, so that data access control is more accurate, illegal data access and attack diffusion are effectively blocked, and data access efficiency is improved. And the safety of the isolated data area is ensured.
Owner:SHICHUAN DIGITAL TECH (SHENZHEN) CO LTD

Federal learning-based emergency rescue data privacy protection and collaborative analysis system

The invention discloses an emergency rescue data privacy protection and collaborative analysis system based on federated learning, and belongs to the technical field of emergency rescue data privacy protection and collaborative analysis. A dynamic trust evaluation module; the federated learning privacy protection engine module is used for realizing cross-domain data collaborative training by adopting a secure multi-party computing model; and the block chain intelligent contract module is used for deploying a data access control strategy and a credible auditing rule. According to the method, a global trusted environment is established through an end-side cloud three-level trust chain, the reliability of equipment is quantified through dynamic trust evaluation, data collaboration of privacy protection is realized through federated learning, an auditing strategy is automatically executed through an intelligent contract, an efficient encryption technology for guaranteeing safety and effectively reducing resource consumption is adopted, and the urban emergency data safety problem is solved.
Owner:INST OF URBAN SAFETY & ENVIRONMENTAL SCI BEIJING ACAD OF SCI & TECH

Medical data abnormal access identification method and system

The invention relates to the technical field of medical data security, in particular to a medical data abnormal access identification method and system. Firstly, a user ID and an access log are collected to provide a behavior analysis basis, then a new user is endowed with initial credibility based on historical credibility of a group to which the new user belongs and jumps to permission setting, and an old user carries out vectorization on current and historical access data and calculates a fitting degree; constructing a three-dimensional evaluation vector in combination with data importance, access duration and fitness, calculating initial credibility by using a density function, finally matching a dynamic update model according to a fitness range, mapping the credibility into an intelligent contract control interval, automatically intercepting a hyper-permission request, and realizing fine-grained real-time permission control and abnormal access accurate interception. The technical problems that a traditional medical data access control technology lacks a fine-grained trust evaluation mechanism, is difficult to dynamically adapt to the complexity of an access behavior, and is easy to cause abnormal access recognition lag are solved.
Owner:山东省立第三医院 +1

Data access control method and device

The invention discloses a data access control method and device, and relates to the technical field of cloud computing. The method comprises the steps that an access control strategy for a target data resource is acquired, the access control strategy of the target data resource indicates a target data table, and then in response to an operation request for the target data resource triggered by a user, a resource identifier of the target data resource and a user identifier of the user in the operation request are extracted. Querying a target data table based on the operation request to obtain target permission data having a mapping relationship with the user identifier in the target data table, and if the target permission data comprises the resource identifier, passing the authentication; and if the target permission data does not comprise the resource identifier, the authentication is not passed. According to the method, access control with data as granularity is realized, whether the access authority exists or not is determined by inquiring whether the target authority data comprises the resource identifier or not, and the maintainability of an authentication system and the access control efficiency are improved.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Data access control method and system based on zero knowledge proof

The invention provides a data access control method and system based on zero-knowledge proof, and relates to the technical field of data access control. According to the method, a root key of a unique hardware identity is generated through a physical unclonable function of a data request equipment chip, and meanwhile, real-time running state data of equipment is collected; the two are subjected to cryptographic binding to form an equipment credible state voucher; secondly, detecting capacitance field disturbance when data holding equipment approaches through a capacitive proximity sensor array, and generating an interactive response mode; then, the equipment credible state certificate and the interactive response mode serve as private input to generate a composite zero-knowledge proof, and identity authenticity and physical proximity are proved to data holding equipment at the same time on the premise that sensitive information is not leaked; and after the data holding device passes verification, the data access permission is authorized immediately, and a temporary encryption communication channel is established, so that the reliability and instantaneity of security authentication between IoT devices can be improved.
Owner:NANJING YISHENG SAFETY TECH RES INST CO LTD +1

Distributed access control method, system and equipment based on multi-factor authentication

The invention discloses a distributed access control method, system and equipment based on multi-factor authentication, and relates to the related field of data access control, and the method comprises the steps: responding to a real-time access request, determining a first access user, and judging whether the access is the first access; if not, the first decentralized identity system is connected to determine the bound multi-factor authentication mode and the lowest permission principle under the zero-trust architecture; connecting the access log database to collect a historical access record of the first access user, performing trust risk assessment, and generating a trust risk index; judging whether the trust risk index meets the trust requirement under the zero-trust architecture or not, executing screening of the lowest permission principle and the multi-factor authentication mode, and generating a target authentication scheme; and performing access authority authentication on the first access user. The technical problems that existing access control is insufficient in safety and unauthorized access is difficult to effectively prevent are solved, and the technical effects of improving the safety of access control and effectively preventing unauthorized access are achieved.
Owner:LINGSHU TECH CO LTD

Ontology-based data space dynamic access control method, equipment and medium

The invention discloses an ontology-based data space dynamic access control method and device, and a medium. The method comprises the following steps: constructing a data dictionary connector and a basic connector; establishing a semantic mapping relationship between the global ontology and the local ontology to obtain first access mapping; establishing data field mapping between the data source and the local ontology to obtain second access mapping; performing policy relationship construction on the second access mapping to establish a policy relationship between the data source and the local ontology; obtaining a data request, and determining an accessible field corresponding to the identity of the requester through data access control based on the data request and the first access mapping; carrying out strategy relation analysis on the accessible field to obtain an access query statement; and according to the access query statement, obtaining fine-grained access data through virtual mapping knowledge domain mapping. According to the method, the technical problem that a centralized access control strategy is difficult to respond to the authority change demand in multi-organization cooperation in time is solved.
Owner:LINYI UNIVERSITY

Data security protection method and system for large model training

The invention discloses a data security protection method and system for large model training. The core of the method is that a data safe box trusted application (TA application) is deployed in a trusted execution environment (TEE) and cooperatively works with a user-defined virtual file system driver at a host machine side, so that an end-to-end secret state data access control link is constructed. Before encryption protection of sensitive data, a measurement value (including code hash, configuration parameters and a runtime state) of a current TEE instance is submitted to a remote verification service through a data safe box TA application, and the verification service only sends the measurement value (including code hash, configuration parameters and a runtime state) of the current TEE instance to the remote verification service after confirming that the TEE environment meets a preset security policy (such as a kernel version, a software version and configuration parameter compliance). And generating a secret key encrypted by a custom virtual file system on a host machine side through derivation. And malicious copying of a system memory and a storage medium is prevented, so that the traditional attack defense capability is effectively improved.
Owner:PANOVASIC TECHNOLOGY CO LTD

Fault switching method and device, electronic equipment and storage medium

The invention discloses a failover method and device, electronic equipment and a storage medium, and relates to the technical field of distributed storage, and the failover method comprises the following steps: determining a first disk resource group corresponding to a first storage node and a second disk resource group corresponding to a second storage node; and establishing a double-control relationship between the first disk resource group and the second disk resource group. And after the establishment of the double-control relationship is completed, carrying out fault switching on different disk resource groups under the double-control relationship based on the first mechanism and the second mechanism. The technical problem that in a distributed storage system, efficient and safe disk resource management and data access control of a fault controller cannot be effectively achieved under a double-controller architecture is solved, and the technical effects of improving rapidness, smoothness and automatic back-switching of fault switching and remarkably improving the high availability of the distributed storage system are achieved.
Owner:JINAN INSPUR DATA TECH CO LTD

Server data access control method and device, equipment and storage medium

The invention relates to the technical field of server data access control, and discloses a server data access control method, device and equipment and a storage medium. Distributed server deployment information is queried by estimating bidding document item service requirements of each sub-service area; solving a server data access control strategy by taking the overall processing delay condition of the server executing the corresponding service user bidding document item, the server hardware load and the server resource scheduling limitation as a constraint condition set and taking the server access experience of the service user in the target server access control time period as an optimization target; and resource scheduling and service user matching of the distributed server in each access control period are realized by using a control strategy, so that bidding document project service is executed. According to the method, the rationality of server data access control planning is improved by considering regional differences, time peak differences and strong regional relevance of bidding document application services in different industry categories and hardware resource limitations of distributed servers.
Owner:CHENGDU POLYTECHNIC +1

Power data access control method and device based on multi-level encryption strategy

The invention provides a power data access control method and device based on a multi-level encryption strategy. The method comprises the following steps: establishing a platform root key, a role key derived based on a role identifier and a homomorphic encryption public and private key pair bound with a sensitive field in an encryption engine, and mapping the keys to a corresponding power data field; performing first-layer encryption on the to-be-stored power data block by using the platform root key, performing second-layer encryption on the field set belonging to the corresponding role access level by using the role key, and performing third-layer encryption on the sensitive field by using the homomorphic encryption public key; distributing the data key set to a computing node, and enabling the computing node to execute decryption or secret state calculation on the encrypted power data to obtain target data; and re-encrypting the target data by using the role key, and providing the re-encrypted target data to the requester carrying the role identifier. According to the method and the device, data security access of fine-grained permission isolation and online secret state calculation can be considered.
Owner:INNER MONGOLIA ELECTRIC POWER (GRP) CO LTD DIGITAL RES BRANCH

Data access control method and device, storage medium and electronic equipment

The invention discloses a data access control method and device, a storage medium and electronic equipment, and relates to the field of computers.The data access control method comprises the steps that a target reading request is received, and the target reading request is used for requesting to read data corresponding to target time from a storage space in a memory according to target address information; in response to the target reading request, positioning a target cache region corresponding to the target address information in a cache space in a memory; and extracting the target data of the target snapshot version corresponding to the target time from the reference snapshot version and the reference data which are stored in the target cache region and have the corresponding relationship, thereby solving the technical problems of relatively low data access efficiency and the like caused by the fact that historical snapshot data reading needs to depend on a rear-end disk. The technical effects of cache acceleration of historical snapshot data reading and improvement of data access efficiency are achieved.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Data distributed secure storage system and method based on computer science and technology

The invention relates to the technical field of data distributed storage, in particular to a data distributed secure storage system and method based on computer science and technology. The system comprises a data fragmentation and strategy binding module, a strategy declaration evidence storage and state tracking module, a strategy execution voucher generation module and a voucher verification and data assembly module. The system carries out fragmentation processing on original service data through a dynamic fragmentation algorithm to generate encrypted data fragments and a strategy binding statement; storing the strategy binding declaration to a distributed account book and maintaining a strategy state table; generating a policy execution voucher including an access qualification proof, a digital signature response, a policy hash value and a timestamp based on the system real-time state and the access request; and the distributed storage node implements decentralized data access control by verifying the policy execution credential. According to the method, the single-point fault and strategy tampering risk of centralized authority management are effectively solved, and a reliable data security sharing scheme is provided for a supply chain financial service scene.
Owner:刘震

Dynamic distributed data access control

Dynamic data access control may be provided by granting an access request for accessed data that is governed by an access policy. A hash tree may be generated for the accessed data. The hash tree may be stored in conjunction with the access policy, and the access policy may be related to uploaded data, based on the hash tree.
Owner:BMC SOFTWARE INC

Data access control method based on zero-trust architecture

The invention discloses a data access control method based on a zero-trust architecture, relates to the technical field of network security, and solves the problems that multi-factor identity authentication is difficult to be combined with a deep learning model for identity verification and whether access permission is granted or not is difficult to judge according to the trust probability of a user. The access authority is difficult to dynamically allocate in combination with roles and attributes of users and a zero-trust architecture; a micro-isolation technology is difficult to carry out logic isolation, and data resources are difficult to encrypt in real time; and finally, the data access authority is difficult to recover automatically. According to the method, the minimum permission principle, continuous monitoring and dynamic access control in the zero-trust architecture are combined, so that the accurate verification of the user identity, the real-time evaluation of the trust degree and the dynamic adjustment of the access permission are realized. And meanwhile, the attack range is limited by utilizing a micro-isolation technology, the data is encrypted in real time, and the authority is automatically recovered after the access is finished.
Owner:NAVAL UNIV OF ENG PLA +1

Data access control

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for controlling data access. One of the methods includes receiving, from a user device associated with an account, a request for data; accessing data from one or more data sources that includes, for each of a plurality of data types, corresponding data values; selecting, from the plurality of data types and using permissions data for the account, one or more data types that the account has permission to access; and providing, to the user device and for each of the one or more data types that the account has permission to access, the corresponding data values.
Owner:CHEN TECH LLC

Medical data access control method based on block chain

The invention relates to the technical field of medical data access control, in particular to a medical data access control method based on a block chain. The method comprises the following steps: S1, a health bureau is used as a management and operation main body of a block chain system; according to the method, the access information entropy is calculated for the data volume accessed by the user, the risk of the access request is dynamically calculated, and then the trust degree is calculated through risk assessment, so that sufficient risk verification and trust degree confirmation are ensured for each data access; the decentralization, transparency and data tampering resistance of the system are further improved, so that the access control of the medical data is safer and more reliable; compared with the prior art, the risk can be evaluated and controlled more accurately, higher adaptability is achieved, complex medical data sharing requirements and potential security threats can be effectively dealt with, and the access throughput and delay of the medical data are also remarkably improved.
Owner:LIMING VOCATIONAL UNIV +1

Geographic edge node data access control

A method, computer program product, and computer system are provided for geographic edge node data access control. The method carried out at an edge node includes: obtaining a regulation control template for controlling access to data on an edge node for a new regulation region; and adjusting active regulation controls of a set of operation parameters of the edge node based on the regulation control template for the new regulation region. The method also includes: inferring an impact of the adjustment of active regulation controls, wherein the impact is a variation of the operation parameters of the edge node; and, when an impact is negative, further adjusting active regulation controls based on alterative rules in the regulation control template. The method verifies a validity of the adjustment of active regulation controls for the set of operation parameters of the edge node.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Decentralized data access control method for cross-domain cooperation of unmanned aerial vehicle

The invention discloses a decentralized data access control method for cross-domain cooperation of an unmanned aerial vehicle, the method is based on a block chain network, an access control module based on a smart contract is deployed on the block chain network, an access control algorithm ScaBAC (Smart-Enabled Access Control) is embedded in the module, and the access control module is connected with the block chain network through the block chain network. An attribute-based decentralized access control algorithm driven by a smart contract comprises the working steps of data permission expression, data access execution and data permission transmission and obtainment, the method of the invention well quantifies the permission attribute of unmanned aerial vehicle data in a decentralized environment, supports flexible authorization in a dynamic task, and improves the reliability of the unmanned aerial vehicle data. And efficient cooperation of on-chain automatic decision and off-chain data verification is realized through the smart contract, and controllability and traceability of the unmanned aerial vehicle data circulation process are ensured. According to the method, real-time permission updating in a multi-unmanned aerial vehicle cooperative task can be well supported, and fine-grained permission expression is achieved.
Owner:ZHEJIANG UNIV OF TECH

Data access control method and device, computer equipment and storage medium

The invention discloses a data access control method and device, computer equipment and a storage medium. The data access control method comprises the following steps: carrying out initialized storage on to-be-stored data; when a data access request is received, a read-write request is sent to the ORAM binary tree, so that after the memory controller receives the request, whether a target data block exists in a buffer area Sash or not is searched, and a search result is received; if the search result is that the target data block does not exist, determining a real physical memory position of the target data block through a position mapping table, and re-mapping a path label of the target data block to a new random path; reading a path, stored in the ORAM binary tree, of the target data block, and storing the to-be-stored data to a buffer area Sash by adopting all data blocks contained in an RS decoding path; and updating the buffer Sash, and processing the target data block according to the read-write request. By adopting the method and the device, the safety and the integrity of the ORAM system in the data access process are improved.
Owner:湖南工商大学

Mechanism for dynamic authorization

Example embodiments of the present disclosure relate to dynamic authorization. According to embodiments of the present disclosure, a solution for dynamic access control to data is proposed. On receiving data registration from a data source, a first device checks the data types to be produced by the data source and adds policies for the data or updates existing policies for the data according to its property. It also serves as access control decision point to determine consumers' access rights based on centrally managed policies. Authorization for data access is granted / denied according to local attributes / policies. In this way, it achieves a dynamic, context-aware and risk-intelligent access control to different kind of data from various data sources (i.e., service producers).
Owner:NOKIA TECHNOLOGIES OY

Advanced semantic caching with CDN for rag-based LLM applications

A Content Distribution Network (CDN) may implemented as a front door to a RAG-based LLM for the purpose of semantically caching LLM responses to natural language prompts. More specifically, the CDN may also cache document citation(s) and / or user tag(s) along with the LLM response for purposes of ensuring that access permission constraints of the RAG are observed when providing cached LLM response as direct responses to semantically similar natural language prompts. Additionally, the CDN may be configured to modify and / or purge cached data from the CDN's cached memory database based on instructions received from a data access control (DAC) entity of the organization or enterprise client. This may ensure that the CDN observes any changes to the access permission constraints that might be made by the DAC entity.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC