Approval Server Access Control for Trusted Sensitive Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data access control systems fail to consider the confidence level of data providers in determining data provision based on the purpose of use and protection level, especially for sensitive information.
Innovation Solution
An approval server controls data access by calculating a confidence level based on the data user's policy and the data owner's policy, allowing anonymization to ensure data protection levels are met.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data providers provide sensitive data to data users, then data value and service capability are improved, but data security and privacy protection deteriorate
Solution Approach 1:
The patent introduces an approval server as an intermediary between data providers and data users. The approval server calculates confidence levels based on multiple factors including data protection level, use purpose, and user attributes, then mediates the data access decision. This intermediary mechanism enables data sharing while maintaining security through automated confidence assessment.
Solution Approach 2:
The patent changes the parameter of data protection by introducing dynamic confidence level calculation. Instead of fixed access control, the system adjusts the effective protection level based on calculated confidence scores that consider data sensitivity, user attributes, and use purposes. This allows flexible data sharing where protection level adapts to the specific access request.
2Object-affected harmful factors
If data access control is based on risk index calculation, then data security is improved, but the ability to determine confidence in data providers deteriorates
Solution Approach 1:
The patent segments the confidence assessment into multiple independent components: data protection level, use purpose, and user attributes. Each component is evaluated separately and then integrated to form a comprehensive confidence level. This segmentation allows the system to capture nuanced confidence information that a single risk index cannot represent.
Solution Approach 2:
The patent transitions from a one-dimensional risk index to a multi-dimensional confidence assessment framework. By adding dimensions such as data protection level, use purpose classification, and user attribute profiles, the system creates a richer information space that captures confidence in multiple aspects of data access.
3Object-affected harmful factors
If data providers strictly protect sensitive information, then data security is improved, but data circulation and service capability deteriorate
Solution Approach 1:
The patent introduces dynamic access control where the effective security level adjusts based on the calculated confidence level. Instead of static protection, the system dynamically permits or denies access based on real-time assessment of data protection level, use purpose, and user attributes. This dynamic mechanism enables data circulation when confidence is high while maintaining security when confidence is low.
Data Source
AI summary
In a data circulation control method, an approval server including a processor and a memory controls access to data between a provision party computer providing the data and a use party computer using data. The method includes: a purpose accomplishment status notifying step in which the use party computer notifies the approval server of a use status of the previously approved data; a use application step in which the use party computer makes application to the approval server for a use policy including protection level information related to a security measure when the data is used and a use purpose of the data; and an access control step in which the approval server controls access of the use party computer to the data of the provision party computer based on the use status of the data, the protection level information, and the use purpose of the data.


