Combined Access Rights Lattice for Heterogeneous Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems face complexity in managing access rights for data of heterogeneous origin, where data from multiple sources is combined, making it difficult to determine appropriate access levels for users.

Innovation Solution

A system creates a combined access rights lattice that integrates access rights from various sources, allowing for granular control over data access by determining which data to provide based on specific access rights associated with each part of the combined data, and uses existing rights to reestablish access when rights change.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a system combines access rights from multiple data sources, then the ability to control access to heterogeneous data is improved, but the complexity of managing access rights increases

Engineering Contradiction:
Improveaccess control capabilityVSAvoidaccess rights management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments access rights management by creating separate access rights lattices for different data sources (internal data lattice and external data lattice), then combining them through a unified access rights lattice. This allows granular control over access to heterogeneous data while managing complexity through modular organization of access rights from different origins.

Inventive Principle:
Principle #1Segmentation

2Reliability

If granular access control is implemented for each part of combined data, then data security is improved, but the difficulty of determining appropriate access levels increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess level determination difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary access rights lattice structure that mediates between multiple data sources and users. This lattice combines access rights from internal and external data sources, providing a unified mechanism to determine appropriate access levels granularly for each part of combined data, thus maintaining security while simplifying access level determination.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access rights are strictly enforced for heterogeneous data, then data security is maintained, but the loss of access when rights change occurs

Engineering Contradiction:
Improvedata securityVSAvoiddata access loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements dynamic access rights management where the system continuously monitors changes in access rights from external data sources. When rights change, the system dynamically adjusts the combined access rights lattice and notifies relevant users, allowing access to be reestablished when appropriate, thus maintaining security while minimizing access loss.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10146955B2System and method for access control for data of heterogeneous origin
Publication Date: 2018.12.04 SALESFORCE INC
  • US10146955B2 patent drawing
  • US10146955B2 patent drawing
  • US10146955B2 patent drawing

AI summary

Systems and methods are provided for controlling access to data of heterogeneous origin. A system creates combined access rights from access rights and other access rights for combined data that includes data and other data. The system receives a request to access data that is part of the combined data. The system determines whether to provide access to at least part of the data based on access rights that are part of the combined access rights. The system provides access to at least part of the data in response to a determination to provide access to at least part of the data based on the access rights that are part of the combined access rights.