Declarative Policy Framework for Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data access control technologies face challenges in effectively managing complex queries and adaptive querying scenarios, as well as in understanding and addressing data privacy risks, particularly in networked devices where sensitive information is at risk of exposure.
Innovation Solution
A policy engine that implements a declarative policy framework using a common data model and shareability theory, enabling the specification of expressive data access policies in a concise manner, and automates the creation and application of robust data protection policies by interfacing with data systems to determine shareability based on ontological representations and axioms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If fully capturing a policy authority's intent in a formal specification is used, then data access control precision is improved, but policy creation complexity increases
Solution Approach 1:
The patent introduces a declarative policy language as an intermediary layer between the policy authority's intent and the formal specification. This language includes high-level constructs for defining data access policies that are automatically translated into formal logical representations, thereby maintaining precision while reducing the complexity of policy creation.
Solution Approach 2:
The system creates simplified copies or abstractions of the formal specification through the declarative policy language. Instead of requiring users to work directly with complex formal logic, the system provides an accessible syntactic framework that captures the essential meaning and automatically generates the formal representation.
2Adaptability or versatility
If complex formal knowledge representation is used, then policy expression capability is improved, but user accessibility deteriorates
Solution Approach 1:
The patent employs a disposable syntactic framework where users interact with simple, intuitive policy statements that are automatically processed and discarded after translation to formal logic. This eliminates the need for users to maintain complex formal representations while preserving full expressive capability through automatic translation.
Solution Approach 2:
The system replaces the mechanical process of manually constructing complex formal knowledge representations with an automated translation mechanism. The declarative policy language serves as a higher-level interface that automatically compiles into formal logic, substituting manual formalization work with automated processing.
3Reliability
If detailed policy specifications are created, then data protection reliability is improved, but policy maintenance time increases
Solution Approach 1:
The system performs preliminary actions by automatically generating formal specifications, validation rules, and enforcement mechanisms from the declarative policy language at policy creation time. This preliminary processing ensures reliability is built-in from the start, reducing the need for time-consuming maintenance and adjustments later.
Solution Approach 2:
The patent enables parameter changes in policy specifications through the declarative language's structured format, which allows easy modification of policy parameters without restructuring the entire formal specification. This maintains reliability while significantly reducing the time required to update policies.
Data Source
AI summary
In general, techniques for data access control are described, in which a policy engine implements and applies a declarative policy framework that can represent and reason about complex privacy policies. By using a common data model together with a formal shareability theory, this declarative policy framework enables the specification of expressive policies in a concise way without burdening the user with technical details of the underlying formalism of a data querying application or other knowledge representation scheme. The policy engine may be deployed as the policy decision point in a data access control system that also includes a policy enforcement point. The policy engine includes user interfaces for the creation, validation, and management of privacy policies. The policy engine may interface with systems that manage data requests and replies by coordinating policy engine decisions and access to databases.


