Data Provenance Access Control for Automatic Restriction Propagation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for defining and setting access authorizations to sensitive data on multiuser platforms are time-consuming and prone to errors, compromising data security, particularly in domains like military or defense.

Innovation Solution

A computer-implemented method for determining data access restrictions by analyzing data provenance and existing access restrictions to automatically derive and adapt access controls based on dependencies between data sets, using provenance graphs and metadata.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual methods are used to define and set access authorizations for each user, then access control can be customized for each user, but the process becomes time-consuming and prone to errors

Engineering Contradiction:
Improveaccess authorization setupVSAvoidtime for setting access restrictions
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically determining access restrictions for new data based on the provenance and access restrictions of source data before manual intervention is needed. This eliminates the time-consuming manual setup process while maintaining proper access control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by automatically propagating access restrictions through data dependencies without requiring manual configuration. The access control system serves itself by using provenance information to automatically determine appropriate access restrictions for derived data.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual methods are used to set access restrictions, then flexibility in customization is maintained, but reliability and security are compromised due to errors and tampering

Engineering Contradiction:
Improvedata securityVSAvoidaccess restriction management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements feedback by continuously tracking data provenance and automatically adjusting access restrictions based on the relationships between source and derived data. This ensures that access controls remain reliable and secure while adapting to changes in data dependencies.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system uses data provenance as an intermediary to automatically determine access restrictions. Instead of manual configuration, the provenance information mediates between source data and derived data to establish appropriate access controls, improving reliability while reducing operational complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If access restrictions are determined manually for each data set, then precise control is achieved, but device complexity and operational burden increase

Engineering Contradiction:
Improveaccess control efficiencyVSAvoidaccess restriction management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system achieves universality by using a single automated mechanism that handles access restriction determination for all data sets based on their provenance. This multi-functional approach replaces multiple manual configuration processes, improving productivity without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250258941A1Method and devices for determining data access restrictions
Publication Date: 2025.08.14 HELSING GMBH
  • US20250258941A1 patent drawing
  • US20250258941A1 patent drawing
  • US20250258941A1 patent drawing

AI summary

Computer implemented methods and systems for determining data access restrictions are described, the method including: determining a first access restriction to first data; determining a data provenance of second data, the determined data provenance indicating a dependency of the second data on the first data; and determining, based on the data provenance and the first access restriction, a second access restriction to the second data.