Data Category Visibility for Secure On-Demand Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional database systems face performance issues when dealing with complex data relationships and concurrent access by multiple users, leading to slow query processing and inefficient data retrieval.
Innovation Solution
Implementing data category visibility (DCV) mechanisms based on user profiles and permission sets to control access, using DCV Generating Code to combine visibility settings and cache data efficiently, and maintaining a unified design database to ensure secure and efficient data retrieval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional database systems process queries with complex data relationships and concurrent user access, then data retrieval accuracy is maintained, but query processing speed decreases
Solution Approach 1:
The patent segments data access control into distinct categories (public, private, organizational, unclassified) with specific visibility rules for different user roles. This segmentation allows the database to efficiently determine data accessibility without processing all complex relationships uniformly, thereby maintaining accuracy while improving query speed through targeted filtering mechanisms.
Solution Approach 2:
The system pre-establishes data category visibility (DCV) rules and permission sets before queries are executed. By preliminarily defining which data categories are visible to which user roles, the database can quickly retrieve only the necessary data during query processing, avoiding the need to process all data relationships in detail and thus improving query processing speed while maintaining retrieval accuracy.
2Adaptability or versatility
If multiple users concurrently access the database system, then system utility increases, but query processing performance deteriorates
Solution Approach 1:
The patent applies local quality by assigning specific data visibility characteristics to different user roles and data categories. Instead of treating all users uniformly, the system tailors data access rights to specific user groups (e.g., administrators see all data, users see only their data), allowing concurrent access without performance degradation since each user's query can be processed independently with optimized visibility rules.
Solution Approach 2:
The system introduces data category visibility (DCV) as an intermediary layer between users and the database data. This DCV mechanism acts as a mediator that translates user roles into specific data accessibility rules, enabling multiple users to concurrently access the system without interfering with each other's query processing performance, thus maintaining both system utility and query processing performance.
3Reliability
If comprehensive data access control is implemented, then security improves, but system complexity increases
Solution Approach 1:
The patent segments the complex access control problem into manageable data categories (public, private, organizational, unclassified) with clearly defined visibility rules for each category. This segmentation simplifies the overall access control mechanism by providing straightforward rules (e.g., private data is visible only to the owner) rather than complex unified policies, thereby maintaining strong security while reducing system complexity.
Solution Approach 2:
The data category visibility framework provides universal rules that apply across different data types and user roles. The same DCV mechanism handles various access scenarios (user-to-data, role-to-data, organization-to-data) through a unified framework, reducing the need for separate access control mechanisms for each scenario and thus maintaining security without proportionally increasing system complexity.
Data Source
AI summary
Data category visibility are defined at the permission set and profile levels so that users who may not be assigned a role can have the data filtered by data category access rules. In an embodiment, data is filtered based on products or projects so that the products or project can be used as a data category group, once the product or project as been assigned to the user, the user may be granted access, via a data category visibility in a permission set, regardless of the user's role or position in the user hierarchy.


