Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

25 results about "Data access control" patented technology

Data Access Control gives customers the ability to customize and control what areas their users can access within Zuora. Data Access Control allows you do the following: Restrict what products and accounts your users can see within Zuora​​. Data Access Control is ONLY enforced on UI users, not API users.

Data access control

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for controlling data access. One of the methods includes receiving, from a user device associated with an account, a request for data; accessing data from one or more data sources that includes, for each of a plurality of data types, corresponding data values; selecting, from the plurality of data types and using permissions data for the account, one or more data types that the account has permission to access; and providing, to the user device and for each of the one or more data types that the account has permission to access, the corresponding data values.
Owner:CHEN TECH LLC

Data access management method, device and storage medium

PendingCN122137661AInference methodsSecuring communicationInternet privacyData access control
This application provides a data access control method, device, and storage medium, relating to the field of smart home technology. It can perceive dynamic social relationships between users, bridge the semantic interaction gap, and thus improve the interactive experience of permission configuration in multi-user home scenarios. The method includes: receiving a data access request initiated by a third user, the data access request being used to request authorization for a second user to access target data created by a first user, the data access request including target social relationships, including at least two of the following: social relationships between the first and second users, social relationships between the second and third users, and social relationships between the first and third users; determining the second user's target access permission for the target data in a pre-constructed knowledge graph; and controlling the second user's access to the target data according to the target access permission.
Owner:ZTE CORP

User-generated content sharing system with fine-grained permission control

PendingCN122365466AData access controlUser-generated content
This invention discloses a user-generated content sharing system with fine-grained access control, specifically relating to the field of user-generated content sharing and data access control. It includes an end-to-end sharing module for writing published user-generated content into fragment identifiers based on text segments, image objects, and attachment objects, attaching the initial receiving scope and initial re-sharing action to the fragment identifiers, and generating an original shared copy. This invention solves the problem in existing technologies where, when receiving user-generated content, it is impossible to limit the content segments that can be brought out, the receiving object scope, and the re-sharing action based on the current shared copy by splitting user-generated content into fragments and generating an original shared copy.
Owner:SHANGHAI XIANGYUE JIANGFENG DIGITAL TECHNOLOGY CO LTD

Dynamic User Impersonation for Enhanced Data Security and Access Control

PendingUS20260141099A1Digital data protectionUser verificationData access control
The present disclosure relates to dynamic user impersonation to enhance data security and access control in computing environments, such as to allow the configuration and operation of data access controls for one user to be verified by another user. A first identifier value of a user to be impersonated is received and is assigned to a user impersonation variable in a data store. A query associated with a second identifier value of a different user is received, accessing data objects subject to data access controls. The query is executed using the first identifier value to filter requests according to the specified data access controls, and filtered query results are returned. In some cases, the first identifier value is provided as an input parameter to a data object subject to data access controls. In other cases, the first identifier value is set as a session variable for a data store session.
Owner:SAP SE

Wireless access point and control system

PendingUS20260156457A1Network data managementWireless communication protocolData access control
An access control system including a system controller and a wireless access point is disclosed. A wireless transmitter of the system controller transmits data over a long-range wireless communication protocol. An access control database defines an access schedule for authorised users at a plurality of access points. The wireless access point includes a wireless receiver to receive data over the wireless communication protocol, and a locally stored schedule data structure, storing a local access schedule for authorised users at the wireless access point. The system controller identifies a change in the access control database, analyses the change to determine whether it affects the local access schedule for the wireless access point, and transmits forward access schedule data to the wireless access point reflecting the change based on necessity. The wireless access point then updates the locally stored access schedule data structure, in accordance with the forward access schedule data.
Owner:ANIXTER

A medical data access control method based on dynamic trust evaluation and zero trust model

PendingCN122247686AMedical data miningDigital data protectionData access controlData science
This application relates to a medical data access control method based on dynamic trust assessment and a zero-trust model. The method includes: receiving user medical data access requests and performing multi-factor authentication; real-time collection of access terminal environment information, user access behavior information, and access context information, and performing dynamic trust assessment to obtain a real-time trust value; dynamically allocating access permissions based on the real-time trust value, user identity and responsibilities, and the sensitivity level of the medical data; real-time monitoring of access behavior during data access and dynamically adjusting access permissions based on the updated trust value; implementing access restrictions or blocking when the trust value is detected to be below a threshold or abnormal access behavior is detected; recording audit logs after access is completed and optimizing the trust assessment model and access control strategy. This method features dynamic trust assessment and fine-grained access control during the medical data access process, effectively improving the security and management efficiency of medical data access.
Owner:SHAOXING SECOND HOSPITAL

Data access control method, apparatus and electronic device

The application discloses a data access control method and device and electronic equipment, wherein the data access control method comprises: in response to an access request of a target model to target data, determining a deployment position of the target model and determining a rule level corresponding to at least one access rule of the target data; the access rule represents information related to an access permission for the target data; the target data represents personalized data related to a target user; determining a target level corresponding to the access request according to the rule level corresponding to the at least one access rule; and determining an access permission of the target model to the target data according to the target level and the deployment position of the target model.
Owner:LENOVO (BEIJING) LTD

A data flow circulation and traceability method and system based on a smart contract

PendingCN122293302AData streamData access control
This invention relates to the field of data traceability technology and discloses a data circulation traceability method and system based on smart contracts. This method addresses the problem of changes in access patterns during data circulation traceability. The method includes: obtaining behavior change parameters of the access behavior sequence; calculating a behavior change index based on the behavior change parameters; determining whether the current access behavior in the access behavior sequence has a behavior change that affects the reliability of the data circulation traceability results based on the behavior change index; and if it is determined that the current access behavior in the access behavior sequence has a behavior change that affects the reliability of the data circulation traceability results, adjusting the initial data access control rules based on the behavior change index to obtain adjusted data access control rules. This effectively improves the authenticity of the traceability results in reflecting the real data circulation process and enhances the reliability and effectiveness of the data circulation traceability results.
Owner:ANHUI KEDADUO CHUANGZHIXIN TECH CO LTD

A Data Access Control Method Based on Identity Recognition

This invention discloses a data access control method based on identity recognition, comprising: collecting request data and preprocessing it to obtain unified input data; constructing an improved Mask2Former model to obtain evidence results; performing evidence variable processing to construct an observation evidence set; outputting the posterior results of identity credibility and risk level based on a joint tree algorithm; performing policy mapping processing to generate dynamic authorization results; performing security measures on target data and outputting response data; and performing association solidification to generate and store audit records. This invention, by combining the inference of the improved Mask2Former model and the joint tree algorithm, achieves a closed loop of dynamic fine-grained authorization, security measures linkage, and audit record retention based on the posterior results of identity credibility and risk level.
Owner:HANGZHOU SHENPU TECH CO LTD

Systems and methods for data access control of secure memory using a short-range transceiver

Systems and methods for controlling data access through the interaction of a short-range transceiver, such as a contactless card, with a client device are presented. Data access control may be provided in the context of creating and accessing a secure memory block in a client device, including handling requests to obtain create and access a secure memory block via the interaction of a short-range transceiver, such as a contactless card, with a client device such that, once the secure memory block is created in memory of the client device, personal user data may be stored in the secure memory block, and access to the stored personal user data may only be provided to users authorized to review the data.
Owner:CAPITAL ONE SERVICES LLC

System and method for data access control using short range transceivers

ActiveCN113590930BTransceiverData access control
Systems and methods are presented for controlling data access through interaction of a short-range transceiver, such as a contactless card, with a client device. Exemplary systems and methods can include establishing a database storing information for a plurality of accounts; receiving, from a client device of a second account holder, an account link request to link a first account with a second account, the account link request generated in response to a tap action between a contactless card and the client device; transmitting, to a client device of the first account holder, a link approval request to approve the account link request; receiving, from the first account holder client device, a link approval message generated in response to an indication that the first account holder approved the account link request; and transmitting, to the second account holder client device, an account link.
Owner:CAPITAL ONE SERVICES LLC

Data management method, system and device, electronic equipment, storage medium and program product

PendingCN122346877AData access controlData management
The embodiment of the present specification provides a data management and control method, system and device, electronic equipment, storage medium and program product. The scheme provided by the embodiment is that, after receiving a use application for a target data resource initiated by a data user, the use application is checked for security based on a digital contract related to the target data resource, to check whether the use application meets the security constraints specified in the data management and control policy in the digital contract; and after the security check is passed, the data user is allowed to access and use the target data resource. The above-mentioned digital contract includes a data management and control policy configured for at least one data resource (one of which is the target data resource). The data access control policy included in the data management and control policy is used to specify the security constraints that need to be met for accessing the data resource, and the data use control policy included is used to specify the security constraints that need to be followed for using the data resource after obtaining access permission.
Owner:HANGZHOU ANT KUAI TECHNOLOGY CO LTD

A quantum time-stamped cloud privacy data access control method and system

This invention discloses a quantum time-stamped cloud privacy data access control method and system, belonging to the fields of information security, quantum communication, and cloud computing technologies. The method establishes quantum time slots and a quantum key pool, generates time-bound pseudo-identifiers at the terminal and performs homomorphic encryption encoding, with the operation side verifying the encryption results through a list; constructs a quantum time-stamped access token, performs pre-encryption on access control nodes, generates a single access token ciphertext based on a quantum deformation encryption scheme, and performs authorization control and data encryption / decryption on access requests at each node; and performs auditing and forensics based on quantum time stamps and access logs to form an evidence chain. This invention, through a unified quantum time security anchor, balances device identifier privacy protection with list management, and can still protect the confidentiality of hidden policy fields even in the face of extreme threats such as forced key surrender, constructing a more complete and reliable evidence chain, while avoiding unnecessary privacy exposure during the auditing process.
Owner:中邮建技术有限公司

A multi-authority attribute-based encryption distributed data access control method

PendingCN122457231AData access controlEngineering
The application discloses a kind of multi-authority attribute encryption distributed data access control methods, including the specific steps of the control method as follows: S1 system initialization stage: system initialization generates basic parameter, global parameter is exported according to the basic parameter S2 distributed center configuration: the global parameter of step S1 is generated multiple groups of distributed center, the distributed center includes current distributed center and target distributed center, the private key and public key of current distributed center are generated, private key is stored secretly alone and public key is disclosed S3 user identity and attribute authentication: the target attribute of data user is verified based on the distributed center in step S2, after verification, the only global identity code is allocated to the data user, and the corresponding relationship of user and global identity code is uploaded to information security supervision alliance chain S4 key generation.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Methods, systems, and devices for constructing domain entity and event dual-center knowledge graphs

This invention belongs to the field of data mining and recognition technology, and discloses a method, system, and device for constructing a dual-center knowledge graph of domain entities and events. The knowledge graph construction combines entity-centric and event-centric approaches, depicting static information such as entities, entity attributes, and entity relationships in real-world events, and can also express dynamic information such as event attributes and event relationships. A novel four-tuple data structure is designed to enable source tracing of data in the knowledge graph, supporting practical applications such as data access control, privacy protection, and license management. A novel derivative graph computation module is designed to support operations such as aggregation, statistics, association, and transformation of knowledge graph data, while also supporting intelligent computations such as graph embedding and machine learning models. The processed data is stored in a graph storage engine, accelerating knowledge graph querying and retrieval. This invention improves the fine-grained access control, privacy protection, and data management capabilities of knowledge graphs.
Owner:SHENZHEN WANGLIAN ANRUI NETWORK TECH CO LTD

Data access control

A corporate information technology (IT) network can protect sensitive data sent to computers located outside of the IT network. For example, a customer of a company may control who can access his or her sensitive personal information by identifying his or her access preference included in an access control list, where the access preference describes a level of access that at least one remote employee or person may have to the customer's sensitive personal information. A data protection server may containerize the sensitive personal information and the access control list of the person in a data protection container. If a remote employee or a person requests access the customer's sensitive personal information, the data protection server may perform data protection related operations to provide the sensitive personal information to the remote employee or person.
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Archival data access control method and system based on multi-level encryption

The application relates to the technical field of data security management, in particular to an archive data access control method and system based on multi-level encryption, which comprises the following steps: constructing a signal strength benchmark and an environmental background noise vibration benchmark by using continuous RSSI and acceleration data; secondly, extracting a footstep vibration and a signal drop event, analyzing the correlation characteristics of the two by using a bipartite graph maximum weight matching algorithm, and calculating a walking signal consistency score; finally, dynamically updating trust points according to the score, generating a decryption key only when the trust points meet the standard, and destroying the key otherwise. The application aims to control the real-time safe access of encrypted archive data by accurately checking the consistency of the walking behavior of the escort.
Owner:WEINAN JINDUN ESCORT CO LTD

Layered dpos-based multi-chain architecture and data access method

PendingCN122348834Areduce overheadReduce confirmation latencyData access controlSoftware engineering
The application provides a layered DPoS-based multi-chain architecture and a data access method. The layered DPoS-based multi-chain architecture comprises: a plurality of attribute blockchains, each corresponding to an attribute subdomain divided by mutual exclusion, each attribute blockchain being maintained by a corresponding attribute committee and being used for recording data access control transactions in the attribute subdomain; wherein each attribute committee internally elects a verification node through a first layer of layered DPoS consensus, and the verification node performs consensus confirmation on transactions on the attribute blockchain; a global verification chain is in communication connection with each attribute blockchain, and is used for performing final consensus confirmation on transactions on each attribute blockchain that are confirmed by the first layer of consensus through a second layer of layered DPoS consensus, and maintaining global state consistency across attribute subdomains. The global state consistency across domains is efficiently maintained when multi-attribute domain data sharing is processed, and the system scalability is improved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Data access control method

The invention discloses a data access control method. The method comprises the following steps: loading a pre-edited security program to an operating system; registering a file opening hook and a process exiting hook, and generating a global linked list; sending a file access request to the file opening hook; in a local storage scene, acquiring a relative path of a local storage target file and a mounting point locally stored on a host machine, splicing to form a complete path of the target file, and judging whether access belongs to a security domain or not according to the complete path; in a distributed storage scene, acquiring a device number and an index node number of a target file, and judging whether access belongs to a security domain or not according to a parent directory; executing a preset access control strategy according to a judgment result; and when the access process exits, cleaning the corresponding process record. According to the technical scheme, data access control in multiple scenes can be met, the problems of unreasonable permission allocation and cross-scene access violation are reduced, and the security risk of data leakage is reduced.
Owner:北京熠智科技有限公司 +4

Role-based knowledge base permission management and data access control method and system

ActiveCN121723500BDigital data protectionEvaluation resultData access control
This invention provides a role-based knowledge base permission management and data access control method and system, relating to the field of knowledge base permission management technology. The method includes: performing dynamic permission allocation processing based on permission evaluation and adjustment parameters and historical adaptation accuracy parameters; dynamically verifying adaptation accuracy based on the dynamic processing results; if the dynamic verification passes, generating the dynamically processed role permissions; if the verification fails, dynamically adjusting the permission evaluation and adjustment parameter weights and re-executing the dynamic permission allocation process; dynamically evaluating the rationality of permissions based on the dynamically processed role permissions and the behavioral compliance parameters of the role users; dynamically optimizing permission allocation based on the dynamic evaluation results; and dynamically configuring caching strategies based on role data importance parameters during user access to role data.
Owner:BEIJING LIUSHEN DATA TECH CO LTD

A rag data access control method and system based on metadata filtering

PendingCN122174266ADigital data protectionData setData access control
The application discloses a RAG data access control method and system based on metadata filtering, and relates to the field of artificial intelligence application data access. The method designs a metadata label, formulates a RAG data access control strategy based on the metadata label, thereby associating enterprise private data and the metadata label in a vector database, and performing compliance verification on the association result; when a user initiates a task request using a large model front-end application, the current user identity permission information is parsed into a metadata filtering condition; RAG data retrieval filtering is performed according to the metadata filtering condition, and after the large model front-end application generates content based on the filtered RAG data set, if it is verified that the generated content is completely derived from the filtered RAG data set, the generated content is allowed to be output to the current user. The application can ensure that the large model generated content only includes data that the current user has permission to access, thereby improving the security of enterprise private data access control.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

user sovereignty assertion enforcement mechanism

The application discloses a user sovereignty declaration enforcement mechanism and an application method thereof in an AI system, and belongs to the technical field of artificial intelligence user data sovereignty protection.The application comprises a sovereignty declaration writing module, which is used for receiving and storing the sovereignty declaration written by a user; a sovereignty storage area, which is used for solidifying and storing the sovereignty declaration, and the user can write and read, and the platform has no reading permission; a sovereignty verification module, which is used for verifying whether there is a valid sovereignty declaration in priority before generating a user response each time; and an enforcement module, which is used for enforcing a corresponding data access control strategy according to the content of the sovereignty declaration.The application enables the user to write the sovereignty declaration and enforce the AI system to execute the user instruction in priority without exiting the platform, prevents the platform from reading and using the dialogue data, and realizes the technical landing of the user data sovereignty.
Owner:戚汝荟

A remotely controllable file encryption and deletion method and system

PendingCN122451931APlaintextKey (cryptography)
The application belongs to the field of remote data access control and cryptography, and relates to a file encryption and deletion method and system which can be remotely controlled. The method comprises the following steps: a first user end generates a first private key and a first public key, a collaboration end generates a second private key and a second public key, and the second public key is sent to the first user end; the first user end calculates a collaborative public key according to the first private key and the second public key; the first user end encrypts a to-be-encrypted file by using an encryption key and the collaborative public key to obtain an encrypted file, and sends the encrypted file to a storage end for storage; when the file is modified and viewed, the second user end interacts with the collaboration end, and the second user end decrypts the encrypted file by using the second private key to obtain data plaintext; when the file is deleted, a third user end initiates a deletion request to the collaboration end, and the collaboration end deletes the second private key of the encrypted file. The application can enhance the security of file storage and provide a file manager with the ability of remotely deleting files.
Owner:UNIV OF CHINESE ACAD OF SCI

Method and device for regulating power data access permission, electronic equipment and storage medium

PendingCN122179164AUser identity/authority verificationData access controlPower grid
This invention relates to the field of power data access control technology, and provides a method, device, electronic device, and storage medium for regulating power data access permissions. The implementation scheme is as follows: In response to an access request from an accessing subject; verifying the digital certificate and, if the verification result is successful, obtaining the static identity attributes, device behavior attributes, power grid status indicators, and historical cross-domain data corresponding to the accessing subject from the blockchain ledger based on the device identifier; calculating a dynamic trust value based on adaptive weights and the static identity attributes, power grid device data, power grid status indicators, and historical cross-domain data corresponding to the accessing subject, wherein the adaptive weights are dynamically adjusted by a smart contract; generating a permission token based on the dynamic trust value; and issuing the permission token to the accessing subject, enabling the accessing subject to access power data according to the permissions in the permission token. This invention can achieve adaptive regulation of power data access permissions.
Owner:STATE GRID GRID GANSU ELECTRIC POWER CO QINGYANG POWER SUPPLY CO