Embeddable Cloud Analytics via Token-Based Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data warehouse systems are not suited for third-party use due to proprietary components, limiting the ability to embed cloud-based analytics features in third-party applications and ensuring secure access to analytics information.
Innovation Solution
A token-based mechanism is employed to provide secure access to analytics information, allowing cloud-based analytics features to be embedded in third-party applications, with a scalable, multi-tenant analytics platform that regulates access through n-dimensional cubes and policy sets, ensuring secure and controlled data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proprietary components are used in data warehouse systems, then system functionality and performance are improved, but third-party adaptability and ease of embedding are worsened
Solution Approach 1:
The patent introduces a token as an intermediary mechanism that mediates between third-party applications and the proprietary data warehouse system. The token contains encoded authorization information that allows the proprietary system to verify access rights without exposing its internal components or data structures to third parties, thus maintaining both system integrity and third-party adaptability
Solution Approach 2:
The patent segments the access control mechanism into separate components: the token generation module in the proprietary system, the token transmission channel, and the token verification module in the data warehouse system. This segmentation allows the proprietary system to maintain its functionality while providing standardized access interfaces for third-party applications
2Measurement precision
If direct access to transactional data is provided, then analytics precision and data completeness are improved, but data security and access control are worsened
Solution Approach 1:
The token serves as an intermediary that enables analytics operations on data without requiring direct access to the underlying transactional data. The token encapsulates the necessary authorization and data reference information, allowing the analytics engine to process data through controlled interfaces while maintaining security boundaries
Solution Approach 2:
The patent creates a virtual representation of data access rights through the token, which copies the essential authorization information needed for analytics operations without providing actual access to the transactional data storage structures. This allows analytics precision to be maintained while security is preserved through the use of this virtual access mechanism
3Ease of operation
If embeddable analytics are implemented, then ease of operation and third-party integration are improved, but system complexity and access control mechanisms are worsened
Solution Approach 1:
The patent extracts the complex access control logic from the core data warehouse system and places it in the token structure. This extraction simplifies the integration process for third-party applications, as they only need to implement token generation and transmission, while the complex verification and authorization logic remains encapsulated within the proprietary system's token validation mechanism
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An analytics module may be embedded into an application developed, published, or used by an entity in addition to the owner of the data under analysis. An access token may be submitted by the analytics module to a provider of hosted services. The access token may correspond to an n-dimensional cube containing data at a level of granularity permitted to the application. The access token may incorporate additional policies controlling access to the corresponding n-dimensional cube.