Declarative Policy Framework for Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data access control technologies face challenges in effectively managing complex queries and adaptive querying scenarios, as well as in understanding and addressing data privacy risks, particularly in networked devices where sensitive information is at risk of exposure.

Innovation Solution

A policy engine that implements a declarative policy framework using a common data model and shareability theory, enabling the specification of expressive data access policies in a concise manner, and automates the creation and application of robust data protection policies by interfacing with data systems to determine shareability based on ontological representations and axioms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If fully capturing a policy authority's intent in a formal specification is used, then data access control precision is improved, but policy creation complexity increases

Engineering Contradiction:
Improvepolicy specification precisionVSAvoidpolicy creation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a declarative policy language as an intermediary layer between the policy authority's intent and the formal specification. This language includes high-level constructs for defining data access policies that are automatically translated into formal logical representations, thereby maintaining precision while reducing the complexity of policy creation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates simplified copies or abstractions of the formal specification through the declarative policy language. Instead of requiring users to work directly with complex formal logic, the system provides an accessible syntactic framework that captures the essential meaning and automatically generates the formal representation.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If complex formal knowledge representation is used, then policy expression capability is improved, but user accessibility deteriorates

Engineering Contradiction:
Improvepolicy expression capabilityVSAvoiduser accessibility
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent employs a disposable syntactic framework where users interact with simple, intuitive policy statements that are automatically processed and discarded after translation to formal logic. This eliminates the need for users to maintain complex formal representations while preserving full expressive capability through automatic translation.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system replaces the mechanical process of manually constructing complex formal knowledge representations with an automated translation mechanism. The declarative policy language serves as a higher-level interface that automatically compiles into formal logic, substituting manual formalization work with automated processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If detailed policy specifications are created, then data protection reliability is improved, but policy maintenance time increases

Engineering Contradiction:
Improvedata protection reliabilityVSAvoidpolicy maintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically generating formal specifications, validation rules, and enforcement mechanisms from the declarative policy language at policy creation time. This preliminary processing ensures reliability is built-in from the start, reducing the need for time-consuming maintenance and adjustments later.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables parameter changes in policy specifications through the declarative language's structured format, which allows easy modification of policy parameters without restructuring the entire formal specification. This maintains reliability while significantly reducing the time required to update policies.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11263339B2Data access control system with a declarative policy framework
Publication Date: 2022.03.01 SRI INTERNATIONAL
  • US11263339B2 patent drawing
  • US11263339B2 patent drawing
  • US11263339B2 patent drawing

AI summary

In general, techniques for data access control are described, in which a policy engine implements and applies a declarative policy framework that can represent and reason about complex privacy policies. By using a common data model together with a formal shareability theory, this declarative policy framework enables the specification of expressive policies in a concise way without burdening the user with technical details of the underlying formalism of a data querying application or other knowledge representation scheme. The policy engine may be deployed as the policy decision point in a data access control system that also includes a policy enforcement point. The policy engine includes user interfaces for the creation, validation, and management of privacy policies. The policy engine may interface with systems that manage data requests and replies by coordinating policy engine decisions and access to databases.