Cross Domain Discovery System with Segmented Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely sharing and accessing confidential information across different domains while ensuring appropriate access restrictions, as they lack efficient mechanisms for managing diverse access levels and encryption keys.
Innovation Solution
A cross-domain discovery system that uses an object service component to store entities with varying restriction levels, a search service component to match keywords with authorized access, and a policy service component to manage encryption keys, ensuring secure access and retrieval of information based on user credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple entities with different access restriction levels are stored in a single domain, then information sharing capability is improved, but security risk increases due to potential unauthorized access
Solution Approach 1:
The patent divides information into multiple entities with different access restriction levels (e.g., public, private, confidential) within a single domain. Each entity is independently accessible to users with appropriate clearance levels, enabling selective information sharing while maintaining security through segmentation of access rights.
Solution Approach 2:
The patent introduces a search service component as an intermediary that mediates between users and information entities. This intermediary evaluates user credentials against access restriction levels and facilitates authorized access without requiring direct trust between all users and all information, thus reducing security risk while maintaining sharing capability.
2Device complexity
If encryption keys are managed centrally, then key management simplicity is improved, but system vulnerability increases due to single point of failure
Solution Approach 1:
The patent segments encryption key management by assigning unique encryption keys to different access restriction levels. Each key is managed separately and can be independently controlled, eliminating the single point of failure vulnerability associated with centralized key management while maintaining simplicity through structured organization.
Solution Approach 2:
The patent applies local quality to key management by giving different security properties to different keys based on their associated access restriction levels. Higher clearance levels have stronger encryption keys with stricter access controls, allowing customized security measures for different information types without compromising overall system simplicity.
3Object-affected harmful factors
If access restrictions are enforced for each entity, then information security is improved, but search and retrieval efficiency deteriorates
Solution Approach 1:
The patent performs preliminary action by pre-evaluating and storing access restriction metadata with each entity during the indexing phase. The search service component uses this pre-stored metadata to quickly determine user eligibility without performing complex real-time security checks during search operations, thus maintaining both security and efficiency.
Solution Approach 2:
The patent implements feedback mechanisms where the search service component continuously monitors user credentials and access requests, providing real-time feedback on authorization status. This feedback loop allows efficient search operations by immediately filtering out unauthorized access attempts without requiring exhaustive security verification for each query.
Data Source
AI summary
Aspects of the disclosure provide methods and systems for cross domain discovery. According to the disclosure, an object can include multiple entities defined by an originator. The multiple entities have different scopes corresponding to different access restrictions. Further, the originator defines keywords for each of the multiple entities. A system for cross domain discovery stores the multiple entities in an object service component, and stores the keywords and access restrictions in a search service component. The search service component conducts a search based on the keywords and access restrictions in response to a search request from a user. An entity is provided to the user based on the user's credential and the searching.


