Data Stream Identity Segmentation for Entity Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack the capability to associate data streams with entity-specific data segments and apply distinct authorization requirements to overlapping segments, failing to manage identities effectively across multiple entities involved in data streams.

Innovation Solution

Assigning unique identifiers to individual data sets within a data stream, allowing for granular management of lifecycle and access control, and using identity servers to analyze ownership, filter, and control access to specific data portions based on entity-specific policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data streams are treated as single unified entities, then management simplicity is maintained, but entity-specific access control and authorization cannot be applied to different segments

Engineering Contradiction:
Improvedata stream management simplicityVSAvoidentity-specific access control capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent divides data streams into discrete data segments that can be individually identified and managed. Each segment is associated with specific entities through unique identifiers, enabling granular access control while maintaining overall stream management capability. This segmentation allows different entities to access specific portions of data according to their authorization policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces data segment identifiers as intermediary elements that mediate between the data stream and access control mechanisms. These identifiers act as references that link specific data segments to entities and their authorization policies, enabling the system to manage access control without requiring complex modifications to the data stream structure itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple entities are associated with different portions of data streams, then access control precision is improved, but system complexity increases due to overlapping segments and multiple policies

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

By segmenting the data stream into discrete portions with unique identifiers, the system can precisely track which segments belong to which entities. This segmentation approach simplifies the management of overlapping segments by treating each segment independently, reducing the complexity of managing multiple policies across a unified stream.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access control policies to different data segments based on their specific characteristics and associated entities. Each segment can have its own authorization requirements and access control settings, allowing the system to manage complexity at the local segment level rather than attempting to manage all segments uniformly across the entire stream.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If data segments are broken down into non-contiguous portions, then entity-specific identification is improved, but data integrity and continuity may be compromised

Engineering Contradiction:
Improveentity-specific identification accuracyVSAvoiddata continuity
Core Design Contradiction:
Measurement precisionVSStability of the object's composition

Solution Approach 1:

The patent segments data into non-contiguous portions while maintaining logical associations through unique identifiers. This segmentation allows the same entity to be identified across dispersed segments without requiring the data to be continuous, as the identifier serves as a persistent reference that maintains entity identity regardless of segment position or continuity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11646875B2Data stream identity
Publication Date: 2023.05.09 CLOUDENTITY INC
  • US11646875B2 patent drawing
  • US11646875B2 patent drawing
  • US11646875B2 patent drawing

AI summary

Systems and methods for managing data stream identity are provided. Ownership information regarding a data stream may be analyzed to identify at least one owner. The data stream may be filtered to identify at least one portion that is associated with the identified owner. A unique identifier may be assigned to the identified portion. The identified portion may be stored in memory in association with the assigned unique identifier and information regarding the identified owner. Access to the identified portion may be controlled based on settings set by the identified owner.