Data Distribution Management via Mediator Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for a mechanism to manage and distribute data shared between organizations while ensuring compliance with regional and national laws, including data sharing agreements, traceability, and secure data placement and deletion.
Innovation Solution
A data distribution management apparatus that includes a proposal management unit for creating and registering data sharing agreements, a policy management unit for generating access control policies, and a policy enforcement unit for controlling data access and storage based on these policies, using a dedicated and shared data store system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is shared between organizations to improve service provision and competitiveness, then data utility and value are improved, but data security and compliance risks increase
Solution Approach 1:
The patent introduces a data distribution management apparatus as an intermediary system between data providers and data users. This mediator enforces access control policies, manages data sharing agreements, and ensures compliance with legal requirements, thereby enabling data sharing while maintaining security through a controlled intermediate layer
Solution Approach 2:
The patent segments data access control into multiple independent components: data sharing condition setting, access control policy registration, and policy enforcement. This segmentation allows each component to be managed and controlled separately, improving both data utility through flexible sharing conditions and data security through granular access control
2Reliability
If comprehensive data sharing agreements and access control mechanisms are implemented to ensure compliance, then data security and legal compliance are improved, but system complexity increases
Solution Approach 1:
The patent combines multiple compliance-related functions into a single integrated data distribution management apparatus. This merger includes data sharing condition management, access control policy registration, policy enforcement, and traceability mechanisms, reducing system complexity by consolidating these functions rather than implementing them as separate systems
Solution Approach 2:
The data distribution management apparatus performs multiple functions simultaneously: it acts as a data store, policy management system, access control enforcement mechanism, and compliance tracking system. This multi-functionality reduces overall system complexity by having a single system handle all compliance-related tasks
3Productivity
If data is distributed across multiple locations to improve service accessibility, then data availability and utility are improved, but control and traceability become more difficult
Solution Approach 1:
The patent implements feedback mechanisms through the policy enforcement unit that continuously monitors and records data access operations. This feedback system tracks which data is accessed, by whom, and under what conditions, maintaining traceability even as data is distributed across multiple locations and accessed by various users
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Provided is a data distribution management apparatus 1 which duplicates data stored in a dedicated data store 2 to a shared data store 3 and shares the data. The data distribution management apparatus 1 includes a proposal management unit 11 which mediates creation of an agreement on a data sharing condition including a condition limiting data to be shared and a condition limiting a user capable of referring to the data to be shared and registers the agreed-upon data sharing condition in a proposal database 15, a policy management unit 12 which registers an access control policy which is used for access control on the data to be shared in a policy DB 16 on the basis of the agreed-upon data sharing condition, and a policy enforcement unit 13 which duplicates the data to be shared from the dedicated data store 2 to the shared data store 3 on the basis of the access control policy and performs access control on the data to be shared on the basis of the access control policy in response to a data reference request for the data to be shared.