Dynamic Data Redaction via Security Service Module
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems fail to effectively control access to data on a fine grain level, especially when data is sourced from disparate locations, and lack the ability to aggregate data while ensuring appropriate authorization levels.
Innovation Solution
A dynamic data redaction system that evaluates policies in a distributed computing environment, using a Security Service Module (SSM) to determine access rights based on user roles and policies, and applies redaction or encryption to ensure only authorized data is provided to requestors, leveraging XML Query and XACML for data manipulation and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is aggregated from disparate sources accessible to users with given authorization levels, then data integration capability is improved, but security control over fine-grained access deteriorates
Solution Approach 1:
The patent segments security control into fine-grained permissions that can be applied to individual data elements, fields, or records rather than treating entire datasets as single units. This allows different authorization levels to be applied to different portions of aggregated data from disparate sources, maintaining security control while enabling data integration.
Solution Approach 2:
The patent introduces an intermediary security enforcement mechanism that sits between data sources and users, dynamically evaluating access requests against fine-grained policies. This intermediary layer enables data aggregation from multiple sources while maintaining security control by filtering and transforming data based on user authorization levels before presentation.
2Reliability
If label-based security is implemented within a database, then access control is improved, but applicability to web services and integration mechanisms deteriorates
Solution Approach 1:
The patent implements a universal security framework using XACML (XML Access Control Markup Language) that can be applied across multiple platforms and communication protocols including web services, databases, and integration mechanisms. This multi-functional approach allows the same fine-grained access control policies to enforce security consistently across disparate systems and communication channels.
3Ease of manufacture
If static redaction policies are applied to data, then implementation simplicity is improved, but ability to handle dynamic authorization requirements deteriorates
Solution Approach 1:
The patent implements dynamic redaction policies that can be evaluated and modified at runtime based on user context, data sensitivity, and authorization levels. The system uses XACML policies that can be dynamically assessed against user requests, allowing the same data to be presented differently to different users or the same user under different conditions, thereby handling dynamic authorization requirements while maintaining manageable complexity through standardized policy evaluation.
Data Source
AI summary
A system, method and media for dynamically redacting data based on the evaluation of one or more policies. In one embodiment, the method comprises receiving a request to access one or more resources, receiving responses from the one or more resources and assembling a result set which includes several portions of data, determining current access policies for the requestor to the one or more resources, and redacting from the result set a portion of the data that the requestor is not permitted to receive, based on the current access policies.


