Data Routing System Using NLP Classification for Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data communication and information security technologies fail to reliably route data to authorized users, often resulting in over-sharing or under-sharing of data within organizations due to inadequate classification and access control.
Innovation Solution
A system and method that classify data items based on responsibility and sensitivity features using Natural Language Processing (NLP) algorithms, determining the appropriate access levels of users and routing data accordingly, while obfuscating sensitive information not authorized for access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current data communication and information security technologies are used, then data can be communicated among employees, databases, servers, and other entities within an organization, but data may be over-shared or under-shared due to inadequate classification and access control
Solution Approach 1:
The patent segments data into different sensitivity classes (e.g., public, internal, confidential, restricted) and routes each class through different communication paths based on the recipient's access level. This segmentation allows precise control over data distribution, preventing both over-sharing and under-sharing by matching data sensitivity with appropriate access channels.
Solution Approach 2:
The system performs preliminary classification of data sensitivity levels before communication occurs. By pre-categorizing data and establishing access rules in advance, the system ensures that only authorized recipients receive appropriate data, eliminating the need for reactive security measures and preventing information loss from improper sharing.
2Ease of operation
If data is routed to all employees within an organization, then information accessibility is improved, but security risks increase due to potential unauthorized access
Solution Approach 1:
The patent applies local quality by assigning different security attributes to different portions of data based on sensitivity. Each data element is tagged with its classification level, and access control is applied locally at the data level rather than uniformly across all data. This allows employees to easily access appropriate data while unauthorized access is blocked at the specific data level.
Solution Approach 2:
The system introduces an intermediary classification mechanism that sits between the data source and recipients. This intermediary automatically classifies data sensitivity and mediates access requests by routing data through appropriate channels, maintaining ease of access for authorized users while blocking unauthorized access without requiring manual security checks for each interaction.
3Reliability
If strict access control measures are implemented, then data security is improved, but data communication efficiency decreases due to additional verification steps
Solution Approach 1:
The system performs preliminary classification of data into sensitivity categories before communication occurs. By pre-establishing access rules and classification schemas, the system automates the verification process, allowing rapid determination of authorized recipients without manual security checks during actual communication, thus maintaining both security and efficiency.
Solution Approach 2:
The patent implements self-service security where the data itself carries classification metadata that automatically guides routing and access control decisions. The system uses the embedded sensitivity information to self-regulate access without requiring external verification for each data transmission, eliminating redundant security steps while maintaining protection.
Data Source
AI summary
A system for classifying a data item to communicate to authorized users extracts features from the data item, where the features comprise a responsibility feature and a sensitivity feature. The responsibility feature indicates a job responsibility associated with the data item. The sensitivity feature indicates a sensitivity level of the data item. The system determines, based on the responsibility feature, that the data item belongs to a particular responsibility class. The system determines, based on the sensitivity feature, that the data item belongs to a particular sensitivity class. The system determines whether a user to whom the data item is directed belongs to the particular responsibility class and sensitivity class to which the data item belongs. The system sends the data item to the user, if is it determined that the user belongs to the particular responsibility class and sensitivity class to which the data item belongs.

