CIS Query Service Discovery and Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As information sharing systems expand, managing new and changing capabilities becomes challenging, and existing mechanisms fail to educate participants fully on utilizing the full range of capabilities, leading to inefficient data sharing and access control.
Innovation Solution
A collaborative information system with a hub-and-spokes configuration, where a CIS platform with pre-defined query services authorizes access to dispersed data sources, enabling self-configuration of authorization models and automated discovery of available data sources, allowing participants to control access without requiring a common dedicated location for data storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If information sharing systems expand to include more participants and data sources, then the value and capabilities of the system increase, but managing and discovering new capabilities becomes increasingly challenging
Solution Approach 1:
The patent introduces an automated discovery service as an intermediary component that mediates between participants and the expanding system capabilities. This service automatically discovers, catalogs, and presents available data sources and query services to participants, eliminating the need for manual capability tracking and reducing management complexity as the system scales.
Solution Approach 2:
The discovery service implements a feedback mechanism where it continuously monitors the system for new data sources and query services, automatically updates its catalog, and notifies participants of new capabilities. This closed-loop feedback system ensures participants are always aware of available capabilities without manual intervention, resolving the complexity of managing expanding system capabilities.
2Productivity
If participants share more data to enable broader query services, then the value of the information system increases, but the risk of data mining and loss of control over exposed data increases
Solution Approach 1:
The patent implements pre-defined query services with explicitly defined data requirements and access controls before data sharing occurs. Participants can review and authorize specific query services that operate on their data sources, with predetermined scopes and purposes. This preliminary authorization framework enables efficient data sharing while maintaining control and reducing data mining risks.
Solution Approach 2:
The system applies different authorization and access control policies to different data sources and query services based on their specific characteristics and sensitivity. Each participant can configure granular access controls for their individual data sources, allowing broad sharing for some data while maintaining strict controls for sensitive data, thus enabling productivity while mitigating data mining risks through localized quality control.
3Adaptability or versatility
If the system provides comprehensive query services to all participants, then the usefulness of the system increases, but the complexity of authorization management and IT intervention requirements increase
Solution Approach 1:
The patent implements a self-service authorization model where participants can independently configure their own data source authorizations, review available query services, and make authorization decisions without requiring IT staff intervention. The discovery service provides self-service capability discovery and the authorization framework enables participants to autonomously manage their data sharing preferences, greatly simplifying operation while maintaining comprehensive query service availability.
Data Source
AI summary
The present disclosure includes a system and method for a service recommendation service. A method for a service recommendation service includes determining one or more queries that do not expose additional data items stored in a data source of a participant in a collaborative information system than are exposed by queries already implemented on the participant's data source. Query services that are not authorized to involve the data source, but which use the determined one or more queries are identified. The identified query services are recommended to the participant.


