Centralized Data Entitlement Management for Federated Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data entitlement management systems face challenges in synchronizing access controls across diverse data storage systems, leading to inconsistent security and increased costs due to manual updates and different authorization models in a federated data ecosystem.

Innovation Solution

A method and system for data access management that utilizes a structured metadata catalog to store user access permissions across multiple external data stores, translating user requests into native languages and generating API calls to retrieve and transmit data while maintaining centralized security administration, thereby automating CRUD transactions and replicating security settings across all data platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual updates are used to maintain data entitlements across multiple data stores, then each system can be independently managed, but synchronization complexity and costs increase significantly

Engineering Contradiction:
Improvedata entitlement management capabilityVSAvoidsynchronization complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized data entitlement management system that acts as an intermediary between multiple heterogeneous data stores. This intermediary layer translates and standardizes access control requests across different data storage systems, eliminating the need for manual synchronization while maintaining consistent security policies throughout the federated data ecosystem.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a universal data entitlement management platform that can handle multiple types of data stores (relational databases, NoSQL databases, cloud storage, on-premise systems) through a common interface. This multi-functional approach allows a single system to manage access control across diverse data technologies without requiring system-specific customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If centralized data entitlement management is implemented, then access control consistency is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control consistencyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the data entitlement management function from individual data stores by implementing a separate centralized management layer. This segmentation allows the access control logic to be consolidated in one location while data remains distributed across multiple stores, achieving consistency without requiring changes to the underlying data storage systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized entitlement management system serves as an intermediary between users and data stores, translating access control requests into system-specific commands. This intermediary layer ensures consistent security policies are applied across all data stores while abstracting the complexity of different data storage technologies from the management system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple data authorization models are supported across different systems, then adaptability to heterogeneous ecosystems is improved, but synchronization difficulty increases

Engineering Contradiction:
Improveauthorization model compatibilityVSAvoidsynchronization difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent changes the fundamental parameter of how authorization is handled by moving from distributed authorization models to a centralized model. The system translates different authorization models into a unified access control framework, making synchronization trivial by eliminating the need to coordinate between multiple independent authorization systems.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The centralized data entitlement management system acts as an intermediary that understands and translates multiple data authorization models into a common access control language. This mediator can communicate with different data stores using their native authorization mechanisms while maintaining consistent security policies across the entire federated ecosystem.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230376616A1Methods and systems for data access management and data entitlements integration
Publication Date: 2023.11.23 KOHLBERG KRAVIS ROBERTS & CO LP
  • US20230376616A1 patent drawing
  • US20230376616A1 patent drawing
  • US20230376616A1 patent drawing

AI summary

A method, system, and computer program product for data access management. A processing device stores metadata defining user access permissions for a plurality digital content files located in a plurality of external data stores. The processing device may receive a user data request for one of the plurality of digital content files, identify an external data store containing the requested digital content file, and retrieve the requested digital content file. Retrieving the requested digital content file from the identified external data store may include translating the user data request into a native language of the external data store, generating an API call, transmitting the API call to the external data store, and receiving the digital content file from the external data store. The processing device may then transmit the requested data content file to the user of the received user data request.