Cognitive Security Tokens for Context-Aware Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication platforms often provide full access to users, leading to potential illegitimate or negligent data misuse, as users or agents can access all information and resources, and user tokens can be hijacked for unauthorized control.
Innovation Solution
Implementing a system that monitors and cognitively analyzes user inputs to determine data requirements, generates data access rules, and uses a virtual database assembler to provide rule-based access, ensuring that users can only access data relevant to the context of their interaction, with two levels of data access security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If full access to all user information and resources is provided to call/contact center agents, then agents can perform all necessary actions, but the possibility of illegitimate or negligent data misuse increases
Solution Approach 1:
The patent applies local quality by providing different access rights to different agents based on their specific roles and requirements. Each agent receives customized access permissions tailored to their function rather than universal access, allowing versatile operation within safe boundaries. The system dynamically adjusts what data each agent can access based on their specific task context.
Solution Approach 2:
The patent segments user data into multiple isolated views, where each agent sees only the portion of data necessary for their specific function. This segmentation prevents any single agent from accessing the complete user profile, thereby reducing data misuse risk while maintaining operational versatility through role-specific data access.
2Adaptability or versatility
If an all-inclusive user token is provided for accessing application functionality, then users can access all resources, but the token can be hijacked for unauthorized control
Solution Approach 1:
The patent segments the user token into multiple specialized tokens, each granting access to specific functions or data types. Instead of providing one all-inclusive token that can be hijacked for complete system control, the system issues fragmented tokens with limited scopes. Even if one token is compromised, the attacker gains only partial access rather than full system control.
Solution Approach 2:
The patent applies local quality by making each token specialized for specific purposes rather than universally applicable. Each token contains permissions tailored to particular application functions or data categories, ensuring that even if a token is stolen, its limited scope restricts the damage potential while maintaining full user versatility through the combination of multiple tokens.
3Loss of information
If users can access all their information, then complete data availability is provided, but the need-to-know security requirement is violated
Solution Approach 1:
The patent segments the user's complete information into multiple isolated data views, each accessible under specific conditions. Users can access all their information overall, but at any given moment, only the segmented portion relevant to their current context is available. This maintains data availability while enforcing need-to-know security through contextual segmentation.
Solution Approach 2:
The patent makes data access dynamic by adjusting which segmented data views are available based on the user's current context, task, and authentication state. The system dynamically determines what portion of user data should be accessible at any moment, providing complete data availability over time while maintaining security through context-dependent access restrictions.
Data Source
AI summary
Secure access to data within a communications platform is provided on a need-to-know basis. Inputs provided at the communication platform are intercepted and cognitively analyzed to determine context of the interaction and related data requirements. In response, data access rules are generated and/or retrieved and applied at an access gateway. As data requests as received from the called party from within the communications platform, the data access rules are applied to the request to determine if a match exists and, if so, data access rules-based access is provided to the data. In response to determining the context of the interaction, a context access token is generated and communicated to a virtual database assembler, which assembles a virtual database that only contains data responsive to the context of the interaction.


