Data Access Control via Abstraction Filters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In distributed digital services, controlling access to digital data and algorithms across multiple jurisdictions is challenging due to technical limitations and legal complexities, including data protection, technology transfer restrictions, and the need to prevent misuse and misallocation, especially when data and algorithms flow across national borders.
Innovation Solution
A computer system using a Computer Aided System Engineering (CASE) tool to create autonomous connected ecosystems, with filters and a decision engine that abstracts and secures data, considering legal frameworks and contractual provisions, to ensure controlled access and optimal data processing while minimizing legal risks and optimizing processing locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data and algorithms are transferred across national borders to enable distributed processing, then processing efficiency and resource utilization are improved, but legal compliance and security control deteriorate due to jurisdictional complexities and technology transfer restrictions
Solution Approach 1:
The patent segments data into different abstraction levels (raw data, processed data, abstracted data) and applies different access controls to each level. Filters are implemented at multiple points in the data flow to ensure that only compliant data transfers occur, while still enabling efficient processing of abstracted versions that contain essential patterns without sensitive details.
Solution Approach 2:
The patent introduces abstracted data as an intermediary representation that preserves the essential structure and patterns needed for processing while removing or obscuring sensitive identifying information. This intermediary form enables cross-border processing to proceed efficiently while maintaining legal compliance, as the abstracted data no longer contains the sensitive details that would trigger jurisdictional restrictions.
2Reliability
If access control filters are implemented to prevent misuse and misallocation of data, then security and legal compliance are improved, but data accessibility and processing speed deteriorate
Solution Approach 1:
The patent implements access control filters and abstraction rules in advance, before data transfer operations occur. The system pre-configures what levels of abstraction are required for different types of data and destinations, so that during actual processing, the filters simply apply predetermined rules rather than performing complex real-time analysis, thereby maintaining high processing speeds.
Solution Approach 2:
The patent changes the parameter of data representation from detailed raw data to abstracted data with controlled information content. By transforming data into different abstraction levels with varying degrees of detail, the system enables fast access and processing of essential patterns while the filter controls prevent access to more sensitive detailed representations, thus achieving both security and speed.
3Loss of information
If raw data is processed at remote locations to generate processed data, then data utility and information value are improved, but legal risks and technology transfer violations increase
Solution Approach 1:
The patent extracts sensitive identifying information from data before transfer, creating abstracted versions that retain the structural patterns and relationships necessary for processing and analysis. This extraction removes the harmful elements (sensitive details that could violate technology transfer restrictions) while preserving the useful elements (patterns and relationships needed for processing).
Data Source
AI summary
A computer system for controlling access to digital data and algorithms, including a multitude of local systems provided at a plurality of remote locations. At least a first subset of the multitude of local systems comprises at least one data acquisition device adapted to generate and provide raw digital data. At least a second subset of the multitude of local systems comprises at least one data processing unit having a memory with a memory capacity and a processor with a computing capacity to process raw digital data to generate processed digital data to be presented to one or more of a plurality of users of the system. The system also includes a filter system, wherein at least one filter is assigned at each local system, each filter having a filter setting for restricting and prohibiting data transfer between the assigned local system and other local systems.


