Asset Governor for Analytics Platform Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current analytics platforms lack effective systems and methods for controlling access to and use of assets, such as data sets and tools, which are essential for secure and governed data analytics operations.

Innovation Solution

The implementation of an asset governor that utilizes metadata and policies to manage access, associating attributes with assets and users to enforce access controls, and integrates with a registration framework for asset management, enabling secure and governed access across multiple dimensions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an asset governor with attribute-based access control is implemented, then security and governed access to assets is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an asset governor as an intermediary component that mediates between users and assets. The asset governor evaluates access requests by comparing user attributes with asset attributes against defined policies, thereby providing centralized security control without requiring complex security logic to be embedded throughout the entire analytics platform

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control system is segmented into distinct components: asset governor, policies, attributes, and evaluation logic. This segmentation allows each component to be developed, maintained, and modified independently, reducing overall system complexity while maintaining comprehensive security control

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If attribute-based access control with multiple policies is implemented, then access control precision is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess control precisionVSAvoidease of use
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system enables self-service through automated attribute evaluation and policy enforcement. When users access assets, the asset governor automatically evaluates their credentials against relevant policies without requiring manual security checks or complex user-side decision-making, maintaining precision while simplifying user interaction

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If comprehensive metadata management is implemented, then adaptability of asset management is improved, but device complexity increases

Engineering Contradiction:
Improveasset management adaptabilityVSAvoidmetadata management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The asset governor serves multiple functions: it manages metadata, evaluates access requests, enforces policies, and controls asset usage. This multi-functionality reduces the need for separate specialized systems for each function, thereby improving adaptability while managing complexity through a unified platform

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10990689B1Data governance through policies and attributes
Publication Date: 2021.04.27 EMC IP HLDG CO LLC
  • US10990689B1 patent drawing
  • US10990689B1 patent drawing
  • US10990689B1 patent drawing

AI summary

Systems and methods for governing access to or use of assets in an analytics platform. Access to assets is controlled with policies that reference attributes. A context of an access request is defined by collecting attributes associated with an access request. The context is then evaluated in light of attributes referenced by the policy applicable to the asset or with a class of the asset. The access request is granted, denied, or partially granted based on whether the attributes defined by the context of the access request comport with the policy.