Data Access Governance via Segmented Project Permissions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data sharing systems fail to effectively manage data access and usage by linking permissions to specific projects, workspaces, applications, and outputs, leading to inadequate control over data sensitivity and compliance with regulatory concerns.
Innovation Solution
A data sharing platform that implements governance by setting permissions and limitations on data use, using tokens to protect Personally Identifiable Information (PII) and attaching metadata to define permitted uses, which are enforced through surveillance and auditing to ensure compliance with usage policies and regulations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional governance solutions allow permissions to be bound to a particular agent for whatever uses the agent feels necessary, then ease of operation is improved, but data sensitivity and compliance control deteriorate
Solution Approach 1:
The patent segments data access permissions by linking them to specific projects, workspaces, applications, and outputs rather than allowing unrestricted access. This segmentation enables fine-grained control over data usage contexts, resolving the contradiction by maintaining operational ease within defined boundaries while preventing sensitive data breaches outside authorized scopes.
Solution Approach 2:
The patent introduces an intermediary surveillance and auditing system that monitors data usage activities. This intermediary layer detects and reports unauthorized data access attempts, enabling compliance control without directly restricting legitimate operations, thus resolving the contradiction between ease of operation and data sensitivity protection.
2Productivity
If data is shared between entities without respect for sensitivity of uses, then productivity is improved, but compliance with regulatory requirements deteriorates
Solution Approach 1:
The patent implements preliminary action by establishing surveillance and auditing mechanisms before data sharing occurs. Usage policies and regulatory requirements are predefined, and the system proactively monitors data access activities against these pre-established rules, ensuring compliance without hindering productive data sharing operations.
Solution Approach 2:
The patent employs feedback mechanisms through auditing systems that continuously monitor data usage and provide feedback on compliance status. This feedback loop enables real-time detection of regulatory violations while maintaining efficient data sharing workflows, resolving the contradiction between productivity and compliance reliability.
3Device complexity
If permissions are not linked to specific projects and workspaces, then device complexity is reduced, but control over data sensitivity deteriorates
Solution Approach 1:
The patent merges multiple control functions into an integrated platform that handles permissions, surveillance, auditing, and compliance monitoring unifiedy. This consolidation reduces overall system complexity while maintaining comprehensive control over data sensitivity through coordinated operation of integrated components rather than separate discrete systems.
Data Source
AI summary
Systems and methods to control data access and usage by storing a permitted use of a set of data items. The permitted use identifies: a set of computer resources to be used to operate on the set of data items; rules for operating on the data items; and a data product to be generated from the set of computer resources operating on the set of data items. A project space provides the set of computer resources to operate on the set of data items according to the permitted use, wherein the data product is to be transferred from the project space to a user device separate from the system; and a usage monitor records operations of the set of computer resources on the set of data items in the project space for compliance with the permitted use. A data air-lock mechanism implements dynamic permissions rules based on actual usages.


