Dynamic Data Access Evaluation for System of Systems Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprises like the Department of Homeland Security face challenges in conducting mission-oriented analysis at the system of systems level due to limitations in tools and the absence of a doctrinal framework, leading to duplicated efforts and higher costs from uncoordinated efforts across different projects.

Innovation Solution

A System of Systems Operational Analytics (SoSOA) tool is implemented, which provides a virtual environment for collaborative operational analyses, enabling decision-makers to access varied data sources and high-powered analytic capabilities, and includes a dynamic access evaluation process for controlled data access, using metadata coefficients to determine data access eligibility based on task and user attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a system of systems operational analytics tool is implemented to enable collaborative operational analyses and access to varied data sources, then analytic capabilities are enhanced and operational efficiency is improved, but device complexity and data access control mechanisms become more complex

Engineering Contradiction:
Improveanalytic capabilitiesVSAvoiddata access control mechanisms
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The data access control mechanism is segmented into multiple independent modules: a metadata coefficient collection module that gathers data attributes, a dynamic access evaluation module that performs real-time assessment, and a data broker module that manages data requests. This segmentation allows each module to handle specific tasks independently, reducing overall system complexity while maintaining comprehensive control capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A dynamic access evaluation module is introduced as an intermediary between users and restricted data sources. This mediator automatically evaluates data requests by collecting metadata coefficients, comparing them against access policies, and making authorization decisions without requiring manual intervention from data owners, thereby simplifying the access control process while enhancing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dynamic access evaluation is performed based on metadata coefficients and task-user attributes, then data access control is improved and security is enhanced, but processing time and computational resources increase

Engineering Contradiction:
Improvedata access controlVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Metadata coefficients for data elements are pre-calculated and stored in a data dictionary before access requests occur. When a user requests data, the system retrieves pre-computed metadata coefficients and compares them against access policies without performing complex real-time analysis, significantly reducing processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The dynamic access evaluation module autonomously performs metadata coefficient collection, comparison, and access decision-making without requiring manual intervention from data owners or security administrators. The system self-evaluates each data request against stored policies and coefficients, enabling rapid automated decisions that reduce processing time while maintaining reliable access control.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If restricted access data is made accessible through automated evaluation, then ease of operation is improved and user convenience is enhanced, but security risks and potential data exposure increase

Engineering Contradiction:
Improvedata access convenienceVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements a feedback mechanism where the dynamic access evaluation module continuously monitors data access patterns, evaluates metadata coefficients against access policies, and adjusts authorization decisions in real-time. This feedback loop ensures that convenient automated access is granted only when security requirements are satisfied, preventing data exposure while maintaining user convenience.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes the parameter of data access from static permission settings to dynamic parameter-based evaluation. Access decisions are made based on variable parameters including user attributes, data metadata coefficients, and access context, allowing the system to automatically adjust access levels based on real-time conditions while maintaining security constraints.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If comprehensive metadata coefficients are collected and evaluated for each data element, then access control precision is improved and security is enhanced, but device complexity and processing requirements increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The comprehensive metadata coefficient collection process is segmented into standardized categories (sensitivity, privacy, combinability, security) with predefined coefficients for each data element type. This segmentation allows the system to collect and evaluate precise access control parameters without requiring complex custom analysis for each data element, reducing system architecture complexity while maintaining high precision.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11126551B1Data access for system of systems operational analytics
Publication Date: 2021.09.21 THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SEC OF HOMELAND SECURITY
  • US11126551B1 patent drawing
  • US11126551B1 patent drawing
  • US11126551B1 patent drawing

AI summary

Systems and methods are described, and an example system includes logic that implements a user interface and that accepts an indicator of data, and upon identifying the data is restricted access, receives via the interface attributes of tasks, and of the user, and determines a task-user attribute matrix based on the user input. The logic sends a data-coefficient request to access modules, receives a reply message that includes sensitivity metadata coefficient, a privacy metadata coefficient, a combinability metadata coefficient, and a security metadata coefficient. The logic constructs, using a content of the reply message, a metadata coefficient matrix. The logic applies a dynamic access evaluation that is based on the task-user attribute matrix and the metadata coefficient matrix and, upon a positive evaluation, accesses the restricted-access data and provides the accessed data to a data cache. Optionally, the data cache feeds a system of system operational analytics.