Data Entity Security Metadata for Consistent Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Inconsistent security controls across multiple applications and users compromise the security of data stored in databases as the number of applications and users increases.

Innovation Solution

Implementing data interlocutors that transform data into data entities with embedded security metadata, ensuring all transactions occur through these interlocutors to enforce consistent security and access controls at the data level.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security controls are implemented at the application layer, then each application can have customized security policies, but the inconsistency in security controls increases as the number of applications increases

Engineering Contradiction:
Improvecustomized security policiesVSAvoidsecurity consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces data entities as intermediary objects between applications and the database. These data entities contain embedded security metadata that acts as a mediator, translating application access requests into consistent security decisions. The data entity serves as the intermediary that ensures all applications adhere to the same security rules defined in the metadata, thereby maintaining security consistency while allowing application-level customization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves security controls from the application layer to the data layer by embedding security metadata within data entities. This dimensional shift from application-centric security to data-centric security creates a new layer of abstraction where security policies are defined independently of applications. The security metadata in the data entity provides authorization information that transcends individual application contexts, ensuring consistent enforcement across all applications.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If the number of applications and users increases, then data accessibility and functionality improve, but the risk of security compromise increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments security controls into discrete security metadata attributes embedded within each data entity. Each data entity carries its own security metadata containing authorization information, creating granular, fine-grained security segments. This segmentation allows individual data elements to have specific security requirements independent of the application or user accessing them, thereby maintaining security integrity as the system scales to support more applications and users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The data entities provide self-service security enforcement by containing embedded security metadata that automatically guides access decisions. The security metadata within each data entity enables the system to autonomously determine authorization without requiring complex external security checks for each access request. This self-service mechanism reduces security risks by ensuring consistent security enforcement regardless of the number of applications or users accessing the data.

Inventive Principle:
Principle #25Self-service

3Reliability

If data entities with embedded security metadata are implemented, then security consistency is improved, but the complexity of data transformation increases

Engineering Contradiction:
Improvesecurity consistencyVSAvoiddata transformation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security metadata directly into the data entity structure, combining data and security information into a single unified object. This merging eliminates the need for separate security management systems and simplifies the overall architecture by integrating security controls within the data representation itself. The consolidated data entity with embedded security metadata reduces transformation complexity compared to maintaining separate security layers.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The data entity serves multiple functions simultaneously: it stores data values, contains security metadata for authorization, and enables consistent security enforcement across all applications. This multi-functionality reduces the need for separate security infrastructure and simplifies the system by having a single object type handle both data storage and security enforcement, thereby reducing overall transformation complexity despite the added security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12367224B2Transforming data into data entities
Publication Date: 2025.07.22 CAPITAL ONE SERVICES LLC
  • US12367224B2 patent drawing
  • US12367224B2 patent drawing
  • US12367224B2 patent drawing

AI summary

In some implementations, a data management system may obtain, via a data interlocutor, a set of data intended for inclusion in a database, wherein the set of data is associated with at least one data type, wherein the set of data comprises at least one data value. The data management system may generate, via the data interlocutor, a set of data entities based on the set of data and a set of security metadata associated with the set of data, wherein the set of data entities comprises a data entity associated with a data value of the at least one data value, the data entity comprising transaction authorization information associated with the data value. The data management system may output, via the data interlocutor, the set of data entities for inclusion in the database.