Data Access Governance via Segmented Project Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data sharing systems fail to effectively manage data access and usage by linking permissions to specific projects, workspaces, applications, and outputs, leading to inadequate control over data sensitivity and compliance with regulatory concerns.

Innovation Solution

A data sharing platform that implements governance by setting permissions and limitations on data use, using tokens to protect Personally Identifiable Information (PII) and attaching metadata to define permitted uses, which are enforced through surveillance and auditing to ensure compliance with usage policies and regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional governance solutions allow permissions to be bound to a particular agent for whatever uses the agent feels necessary, then ease of operation is improved, but data sensitivity and compliance control deteriorate

Engineering Contradiction:
Improveease of data accessVSAvoiddata sensitivity breach risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments data access permissions by linking them to specific projects, workspaces, applications, and outputs rather than allowing unrestricted access. This segmentation enables fine-grained control over data usage contexts, resolving the contradiction by maintaining operational ease within defined boundaries while preventing sensitive data breaches outside authorized scopes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary surveillance and auditing system that monitors data usage activities. This intermediary layer detects and reports unauthorized data access attempts, enabling compliance control without directly restricting legitimate operations, thus resolving the contradiction between ease of operation and data sensitivity protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If data is shared between entities without respect for sensitivity of uses, then productivity is improved, but compliance with regulatory requirements deteriorates

Engineering Contradiction:
Improvedata sharing efficiencyVSAvoidregulatory compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing surveillance and auditing mechanisms before data sharing occurs. Usage policies and regulatory requirements are predefined, and the system proactively monitors data access activities against these pre-established rules, ensuring compliance without hindering productive data sharing operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs feedback mechanisms through auditing systems that continuously monitor data usage and provide feedback on compliance status. This feedback loop enables real-time detection of regulatory violations while maintaining efficient data sharing workflows, resolving the contradiction between productivity and compliance reliability.

Inventive Principle:
Principle #23Feedback

3Device complexity

If permissions are not linked to specific projects and workspaces, then device complexity is reduced, but control over data sensitivity deteriorates

Engineering Contradiction:
Improvepermission management complexityVSAvoiddata sensitivity loss
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent merges multiple control functions into an integrated platform that handles permissions, surveillance, auditing, and compliance monitoring unifiedy. This consolidation reduces overall system complexity while maintaining comprehensive control over data sensitivity through coordinated operation of integrated components rather than separate discrete systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11720701B2Systems and methods to control data access and usage
Publication Date: 2023.08.08 IXUP IP
  • US11720701B2 patent drawing
  • US11720701B2 patent drawing
  • US11720701B2 patent drawing

AI summary

Systems and methods to control data access and usage by storing a permitted use of a set of data items. The permitted use identifies: a set of computer resources to be used to operate on the set of data items; rules for operating on the data items; and a data product to be generated from the set of computer resources operating on the set of data items. A project space provides the set of computer resources to operate on the set of data items according to the permitted use, wherein the data product is to be transferred from the project space to a user device separate from the system; and a usage monitor records operations of the set of computer resources on the set of data items in the project space for compliance with the permitted use. A data air-lock mechanism implements dynamic permissions rules based on actual usages.