Data Provenance Access Control for Automatic Restriction Propagation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for defining and setting access authorizations to sensitive data on multiuser platforms are time-consuming and prone to errors, compromising data security, particularly in domains like military or defense.
Innovation Solution
A computer-implemented method for determining data access restrictions by analyzing data provenance and existing access restrictions to automatically derive and adapt access controls based on dependencies between data sets, using provenance graphs and metadata.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual methods are used to define and set access authorizations for each user, then access control can be customized for each user, but the process becomes time-consuming and prone to errors
Solution Approach 1:
The system performs preliminary actions by automatically determining access restrictions for new data based on the provenance and access restrictions of source data before manual intervention is needed. This eliminates the time-consuming manual setup process while maintaining proper access control.
Solution Approach 2:
The system enables self-service by automatically propagating access restrictions through data dependencies without requiring manual configuration. The access control system serves itself by using provenance information to automatically determine appropriate access restrictions for derived data.
2Reliability
If manual methods are used to set access restrictions, then flexibility in customization is maintained, but reliability and security are compromised due to errors and tampering
Solution Approach 1:
The system implements feedback by continuously tracking data provenance and automatically adjusting access restrictions based on the relationships between source and derived data. This ensures that access controls remain reliable and secure while adapting to changes in data dependencies.
Solution Approach 2:
The system uses data provenance as an intermediary to automatically determine access restrictions. Instead of manual configuration, the provenance information mediates between source data and derived data to establish appropriate access controls, improving reliability while reducing operational complexity.
3Productivity
If access restrictions are determined manually for each data set, then precise control is achieved, but device complexity and operational burden increase
Solution Approach 1:
The system achieves universality by using a single automated mechanism that handles access restriction determination for all data sets based on their provenance. This multi-functional approach replaces multiple manual configuration processes, improving productivity without proportionally increasing system complexity.
Data Source
AI summary
Computer implemented methods and systems for determining data access restrictions are described, the method including: determining a first access restriction to first data; determining a data provenance of second data, the determined data provenance indicating a dependency of the second data on the first data; and determining, based on the data provenance and the first access restriction, a second access restriction to the second data.


