Business-Aware Data Access Control for Dynamic Security Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data access control methods in enterprises are static and inflexible, failing to adapt to the dynamic nature of business data needs and security requirements, leading to inadequate control and potential data breaches.

Innovation Solution

A method and apparatus that utilize a data access security model to determine a data query processing policy based on business data access capability and security attributes, enabling flexible control by employing anonymization, data passthrough, or data isolation policies to manage access requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static single data access control is implemented, then system simplicity is maintained, but adaptability to dynamic business needs deteriorates

Engineering Contradiction:
Improveadaptability to business needsVSAvoidaccess control system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic data access control by introducing time periods, business scenarios, and user roles that can change over time. The access control policy is no longer static but adapts dynamically based on the user's current context, the specific business scenario, and the time period, allowing the system to respond flexibly to changing business needs while maintaining manageable complexity through structured policy definitions.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If flexible data access control is implemented, then adaptability to business needs is improved, but system complexity increases

Engineering Contradiction:
Improveflexibility of data access controlVSAvoidcontrol system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the data access control system into distinct components: user roles, business scenarios, time periods, and data sensitivity levels. Each dimension is independently defined and combined through the data access security model, allowing flexible policy creation without proportionally increasing overall system complexity. The segmentation enables modular policy management where each component can be configured and maintained separately.

Inventive Principle:
Principle #1Segmentation

3Reliability

If data access control is strengthened, then data security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidease of data access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service data access control where users automatically receive appropriate access permissions based on their user role, the business scenario they are engaged in, and the current time period. The data access security model automatically evaluates access requests against the configured policies without requiring manual approval or complex user actions. This maintains strong security controls while preserving ease of operation for legitimate business needs.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4283507B1Method and apparatus for data access control
Publication Date: 2026.04.08 DOUYIN VISION CO LTD
  • EP4283507B1 patent drawingFigure 1
  • EP4283507B1 patent drawingFigure 2
  • EP4283507B1 patent drawingFigure 3~4

AI summary

According to examples of the present disclosure, there is provided a method and device for controlling data access. The method comprises: receiving a data query request characterizing that a first user requests target data; obtaining a business data access capability attribute corresponding to the first user and obtaining a business security attribute corresponding to the target data; wherein the business data access capability attribute is used to characterize capability of accessing data in a business environment in the charge of a user based on a business attribute of the user; determining a data query processing policy corresponding to the data query request by invoking a data access security model based on the business data access capability attribute of the first user and the business security attribute of the target data; and processing the target data by invoking the data query processing policy and generating a response message for feedback.