Access Control Interface for External Auditor Data Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face the challenge of restricting access to internal data when sharing it with external auditors, as external entities may inadvertently or intentionally access non-relevant data, posing a risk to confidentiality and privacy.
Innovation Solution
A system and method that utilize a definition file to specify which external entity can access specific internal data through a user interface, with access restrictions enforced by an access system to prevent access to non-relevant data and systems, ensuring that auditors can only access defined portions of the internal data during scheduled audits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If external auditors are given access to internal data for auditing purposes, then the organization can comply with external oversight requirements, but the risk of unauthorized access to non-relevant confidential data increases
Solution Approach 1:
The patent segments the internal data into different categories and creates role-specific views that divide the data access into authorized portions and restricted portions. Auditors see only the data segments relevant to their audit function, while sensitive segments remain hidden. This segmentation resolves the contradiction by enabling compliance access while preventing unauthorized access to non-relevant confidential data.
Solution Approach 2:
The patent introduces an intermediary mechanism (the interface system with role-based access control) that mediates between the auditor's need to access data and the organization's need to protect confidential data. The intermediary filters and controls what data is visible to auditors, allowing them to perform audits while blocking access to sensitive information they shouldn't see.
2Ease of operation
If auditors can access and copy internal data, then they can perform thorough audits, but the confidentiality and privacy of the data is compromised
Solution Approach 1:
The patent extracts the harmful capability (data copying) from the auditor's access while preserving the useful capability (data viewing for audit purposes). The system allows auditors to view and analyze data through the interface but removes their ability to copy, download, or export the data, thus maintaining audit capability while protecting data confidentiality.
Solution Approach 2:
The patent applies preliminary anti-action by preemptively blocking the copying function before auditors can misuse it. The system is designed to prevent data extraction at the source rather than trying to control or monitor it afterward, thus maintaining both audit effectiveness and data security.
3Adaptability or versatility
If the organization provides full access to internal data systems, then auditors can review all necessary information, but the complexity of managing access security increases
Solution Approach 1:
The patent creates a universal interface system that handles multiple functions (data display, filtering, role-based access control, audit logging) through a single integrated platform. This multi-functional approach allows the system to adapt to different audit scopes and data types without requiring separate complex access management systems for each scenario.
Data Source
AI summary
A user interface receives a request from an external entity to display a particular subset of internal data of an organization relating to a particular member thereof, determines from a located file corresponding to the external entity that a member ID of the particular member is listed therein, and thereafter retrieves the internal data of the member from a database. The user interface then culls the particular subset of the internal data to be displayed from the retrieved internal data, applies located rules corresponding to the external entity to the display of such particular subset of the internal data to result in any modifications necessary in view of such located rules, and displays such particular subset of the internal data as modified to the external entity.


