Consensus-Based Database Access Control for Multi-Owner Data Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In big data and data science projects, combining data sets from multiple owners is challenging due to distrust and administrative complexity, leading to unconstrained access issues and lack of control over data usage, which compromises privacy and compliance.

Innovation Solution

A consensus-based access control system that filters and projects only necessary data subsets, using a consensus engine to obtain approvals from data owners and an immutable lineage tracker for auditing, ensuring secure and compliant data processing and publishing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data analysts are granted full access to combine data sets from multiple owners, then data processing capability is improved, but control over data usage is lost and privacy compliance is compromised

Engineering Contradiction:
Improvedata processing capabilityVSAvoidprivacy compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments data access control into fine-grained permissions at the column, table, and database levels. Instead of granting blanket access, the system divides access rights into specific units that can be independently controlled and tracked, allowing analysts to access only the minimum necessary data portions while maintaining compliance oversight.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control system that sits between data analysts and data sets. This intermediary layer enforces policies, tracks usage, and manages approvals without preventing necessary data processing. The system mediates between the need for data access and the need for compliance control through automated policy enforcement and audit trails.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional approval chains are used for data access, then privacy control is improved, but administrative complexity increases

Engineering Contradiction:
Improveprivacy controlVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal access control framework that handles multiple functions through a single system. The same infrastructure manages approvals, enforces policies, tracks usage, and generates audits across all data sets and analysts. This multi-functional approach consolidates what would otherwise be separate administrative processes into one unified system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service capabilities where analysts can submit their own data access requests and track their own usage. The system automatically enforces policies and generates compliance reports without requiring manual intervention from administrators for every access request. This reduces administrative burden while maintaining control.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If data analysts freely manipulate accessed data, then data analysis flexibility is improved, but trust and control mechanisms are weakened

Engineering Contradiction:
Improvedata analysis flexibilityVSAvoidtrust and control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements continuous feedback mechanisms through audit trails that track every data access and manipulation operation. The system monitors data usage in real-time and provides feedback to administrators about compliance status. This feedback loop maintains trust by ensuring that even flexible data manipulation operates within controlled and observable boundaries.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent establishes preliminary controls by defining access policies and usage rules before data analysts begin their work. Approval chains and policy frameworks are set up in advance, creating a controlled environment within which analysts can freely manipulate data. The preliminary structure ensures that flexibility operates within predetermined safe boundaries.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11520917B2Database system consensus-based access control
Publication Date: 2022.12.06 AT&T INTELLECTUAL PROPERTY I L P
  • US11520917B2 patent drawing
  • US11520917B2 patent drawing
  • US11520917B2 patent drawing

AI summary

A processing system may obtain an operations set associated with database sources of a database system from a client entity, the operations set including a statement, the statement including a query, identify data sets from the operations set, transmit, a request to a first owner to permit access to a first data set, and a request to a second owner to permit access to a second data set, and receive approvals from the first and second owners. The processing system may retrieve a first portion of data stored in the first data set and a second portion of data stored in the second data set in accordance with the approvals, execute the operations set in accordance with the first portion of data and the second portion of data to generate a result set, and provide the client entity access to the result set.