Dynamic Data Redaction via Security Service Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems fail to effectively control access to data on a fine grain level, especially when data is sourced from disparate locations, and lack the ability to aggregate data while ensuring appropriate authorization levels.

Innovation Solution

A dynamic data redaction system that evaluates policies in a distributed computing environment, using a Security Service Module (SSM) to determine access rights based on user roles and policies, and applies redaction or encryption to ensure only authorized data is provided to requestors, leveraging XML Query and XACML for data manipulation and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is aggregated from disparate sources accessible to users with given authorization levels, then data integration capability is improved, but security control over fine-grained access deteriorates

Engineering Contradiction:
Improvedata integration capabilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments security control into fine-grained permissions that can be applied to individual data elements, fields, or records rather than treating entire datasets as single units. This allows different authorization levels to be applied to different portions of aggregated data from disparate sources, maintaining security control while enabling data integration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security enforcement mechanism that sits between data sources and users, dynamically evaluating access requests against fine-grained policies. This intermediary layer enables data aggregation from multiple sources while maintaining security control by filtering and transforming data based on user authorization levels before presentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If label-based security is implemented within a database, then access control is improved, but applicability to web services and integration mechanisms deteriorates

Engineering Contradiction:
Improveaccess controlVSAvoidapplicability to web services
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal security framework using XACML (XML Access Control Markup Language) that can be applied across multiple platforms and communication protocols including web services, databases, and integration mechanisms. This multi-functional approach allows the same fine-grained access control policies to enforce security consistently across disparate systems and communication channels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If static redaction policies are applied to data, then implementation simplicity is improved, but ability to handle dynamic authorization requirements deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidhandling dynamic authorization
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic redaction policies that can be evaluated and modified at runtime based on user context, data sensitivity, and authorization levels. The system uses XACML policies that can be dynamically assessed against user requests, allowing the same data to be presented differently to different users or the same user under different conditions, thereby handling dynamic authorization requirements while maintaining manageable complexity through standardized policy evaluation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7748027B2System and method for dynamic data redaction
Publication Date: 2010.06.29 ORACLE INT CORP
  • US7748027B2 patent drawing
  • US7748027B2 patent drawing
  • US7748027B2 patent drawing

AI summary

A system, method and media for dynamically redacting data based on the evaluation of one or more policies. In one embodiment, the method comprises receiving a request to access one or more resources, receiving responses from the one or more resources and assembling a result set which includes several portions of data, determining current access policies for the requestor to the one or more resources, and redacting from the result set a portion of the data that the requestor is not permitted to receive, based on the current access policies.