Central Data Access Governance for Cross-Platform Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data access control systems are tightly coupled with specific data platforms, fail to scale to new platforms, and present compatibility issues, with complex processes that hinder efficient access management across diverse ecosystems.

Innovation Solution

A centralized data governance and access control system that receives information about data of interest, generates access requests, automatically forwards approval requests to access control entities, creates policies based on responses, and provides access while handling communication with data owners and governance officers, supporting multiple storage technologies through plugins.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing data access control systems are tightly coupled with specific data platforms, then data security and access management can be maintained within those platforms, but the systems fail to scale to new data platforms and present compatibility issues

Engineering Contradiction:
Improvedata securityVSAvoidplatform compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a data access governance service as an intermediary layer between users and multiple data platforms. This service receives access requests, determines appropriate data owners, forwards requests through proper channels, and manages approval workflows centrally, enabling secure access across diverse platforms without tight coupling to any single platform's access control mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The data access governance service provides universal access control functionality across multiple data platforms and ecosystems. It handles various types of data assets, manages different approval workflows, and works with multiple storage technologies through plugins, making the system adaptable to diverse platforms while maintaining consistent security policies

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If existing data access control systems are used, then data security can be maintained within their ecosystems, but the access processes become complex and cumbersome for users

Engineering Contradiction:
Improvedata securityVSAvoidaccess request process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service data access by allowing users to directly submit access requests through the data access governance service without needing to manually identify data owners or navigate complex platform-specific approval processes. The service automatically routes requests to appropriate data owners and manages the entire approval workflow, simplifying the user experience while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent merges multiple access control functions into a single unified data access governance service. It combines request submission, data owner identification, approval workflow management, and policy enforcement into one centralized system, eliminating the need for users to interact with multiple separate systems and complex procedures

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If manual data access request processes are used, then data owners can be contacted for approval, but identifying data owners and managing access becomes time-consuming and complex

Engineering Contradiction:
Improveaccess controlVSAvoidaccess request processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-identifying and storing information about data owners and their contact information in the data catalog. When access requests are submitted, the governance service can immediately retrieve this pre-prepared information and forward requests to the correct data owners without requiring users to manually search or contact the right personnel, significantly reducing processing time

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12579285B2Central data governance and access control for enterprise data
Publication Date: 2026.03.17 RAKUTEN SYMPHONY INC
  • US12579285B2 patent drawing
  • US12579285B2 patent drawing
  • US12579285B2 patent drawing

AI summary

A data platform provides central data governance and access control for enterprise data. Information identifying data of interest at a storage system is received from users. An Access Request for the data of interest at the storage system is generated. The Access Request is forward to a Data Access Layer of a Data Governance and access Control Layer. An Approval Request is automatically forwarded by the Data Access Layer to one or more access control entities. The Data Access Layer receives an Approval Response from the one or more access control entities. A policy for accessing the data of interest at the storage system is created. The policy is used to provide access to the data of interest at the storage system. The Data Access Layer is also able to provide cross-platform access to different storage sources.