Attribute-Based Data Access Control for Industrial Operational Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to provide secure and compliant access to industrial operational data, especially when shared among multiple parties, as they lack effective mechanisms to manage data access based on risk levels, ownership, contractual obligations, and geographical restrictions.

Innovation Solution

A data access control system that employs attribute-based access control (ABAC) to classify data restrictions, determine access constraints, and generate clearance entitlements, ensuring secure and compliant data sharing by matching user accounts with data objects based on geopolitical, ownership, and contractual attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is shared among multiple parties in a common database, then data accessibility and collaboration are improved, but security risks and unauthorized access increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different access rights and clearance levels to different users based on their specific attributes (e.g., organizational affiliation, clearance status, data needs). Instead of uniform access control, the system evaluates each user's local characteristics against data restrictions to grant or deny access, thereby maintaining high accessibility for authorized users while protecting sensitive data from unauthorized access.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the access control parameters dynamically based on user attributes and data characteristics. The access control mechanism evaluates parameters such as user clearance level, organizational membership, and data classification to determine access rights. This parameter-based approach allows the system to adapt access decisions in real-time, enabling versatile data sharing while maintaining security through continuous parameter evaluation.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If access control mechanisms are strengthened to prevent unauthorized access, then security is improved, but system complexity and operational difficulty increase

Engineering Contradiction:
Improveaccess securityVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control system implements self-service by automatically evaluating user attributes and data restrictions without requiring manual intervention. The system autonomously determines access rights by comparing user clearance levels, organizational affiliations, and data classification levels, eliminating the need for complex manual access review processes while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces complex mechanical access control mechanisms with an automated attribute-based evaluation system. Instead of relying on cumbersome manual approval processes or complex policy management interfaces, the system uses computational logic to automatically assess user attributes against data restrictions, simplifying the overall system architecture while enhancing security through consistent, rule-based decision-making.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If data access is restricted based on risk levels and attributes, then data protection is improved, but access speed and efficiency decrease

Engineering Contradiction:
Improvedata protectionVSAvoidaccess efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system performs preliminary action by pre-evaluating and storing user attributes, clearance levels, and data restrictions before access is requested. User profiles and authorization data are prepared in advance, allowing the access control system to make rapid decisions when access requests are made, rather than performing complex evaluations in real-time, thus maintaining both security and efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating simplified access control decisions based on pre-established attribute mappings and clearance levels. Instead of performing complex security evaluations for each access request, the system references pre-computed attribute relationships and clearance databases to quickly determine access rights, thereby reducing processing time while maintaining robust data protection through comprehensive attribute-based restrictions.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20240143774A1Attribute based data access control
Publication Date: 2024.05.02 BAKER HUGHES CO
  • US20240143774A1 patent drawing
  • US20240143774A1 patent drawing
  • US20240143774A1 patent drawing

AI summary

Methods, systems, and computer-readable storage media for compliant access to data from a database using an attribute based access control. A method may include receiving a query requiring an access to data. The data is classified to determine restrictions based on a level of risk related to the access to the data. Data access constraints are determined based on the restrictions of the data. Data access clearance is generated based on the data access constraints. A data access control result is provided based on the data access clearance.