Cloud Access Controller Mediating Data Interoperability and Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based software platforms face challenges in coordinating data interchange formats, ensuring data privacy and security, and controlling access to user data, particularly in ensuring that one user cannot access or modify another user's data while allowing applications to access and manipulate data for multiple users.
Innovation Solution
Implementing an access controller that mediates data access, using a schema catalog for uniform data exchange, and employing a publish-subscribe messaging pattern to manage permissions and data access based on user roles and schemas, ensuring that data is accessed and modified according to defined permissions and compliance requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud-based software platforms provide broad data access to applications, then data interoperability and functionality are improved, but data security and user privacy deteriorate
Solution Approach 1:
The patent introduces an access controller as an intermediary component that sits between data stores and applications. This controller mediates all data access requests by evaluating authorization policies, thereby enabling broad data interoperability while maintaining security through centralized control. The access controller acts as the mediator that resolves the contradiction by allowing data sharing only to authorized entities.
Solution Approach 2:
The patent segments data access control into multiple layers: user-level authorization, application-level authorization, and data-level authorization. This segmentation allows fine-grained control over data access, enabling the system to provide data to applications while maintaining security through hierarchical policy evaluation at different levels.
2Object-affected harmful factors
If the system implements comprehensive access control policies, then data privacy and security are improved, but system complexity and operational overhead worsen
Solution Approach 1:
The access controller is designed as a universal authorization service that handles multiple types of access control scenarios (user-level, application-level, data-level) through a single unified architecture. This multi-functionality reduces overall system complexity by consolidating control logic rather than requiring separate control mechanisms for each access scenario.
Solution Approach 2:
The system implements self-service authorization where applications and users can manage their own access permissions through policy definitions. The access controller automatically evaluates policies and makes authorization decisions without requiring manual intervention, thereby reducing operational overhead while maintaining comprehensive privacy protection.
3Adaptability or versatility
If the system allows applications to access data for multiple users, then service versatility is improved, but data isolation and security worsen
Solution Approach 1:
The patent implements local quality control by allowing different access permissions for different users and applications. Each user and application can have customized access policies that define their specific data access rights. This enables service versatility where applications can access data for multiple users while maintaining data isolation through user-specific permission evaluations.
Solution Approach 2:
The access control system is dynamic, allowing authorization policies to be changed in real-time based on user roles, application permissions, and data sensitivity. This dynamic policy evaluation enables the system to adapt access rights on-demand, providing service versatility while maintaining security through flexible, context-aware authorization decisions.
Data Source
AI summary
Aspects of the present disclosure relate to systems and methods for managing access to data in a cloud-based software platform. A first cloud-based software application generates first data associated with a user account on the cloud-based software platform. A second cloud-based software application may also be connected to the user account and request access to the first data generated by the first application. The user account sets a collection of access permissions on the first data, where the second cloud-based software application is granted access to the first data subject to the collection of access permissions.


