Entity-Relationship Access Rule System for Database Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems for entity-relationship databases are inflexible, complex, and difficult for non-technical users to manage, often requiring separate configuration updates and leading to misconfiguration and increased audit complexity, especially in dynamic business environments like CRM systems.
Innovation Solution
The Entity-relationship Access Rule (ERAR) system embeds security access rules within the entity-relationship database model, allowing access rules to be specified and stored as entities and relationships, enabling permissions to be granted based on business rules that non-technical users can understand and manage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control systems (RBAC, MAC, DAC) are used to secure entity-relationship databases, then security control is established, but the system becomes inflexible and difficult to adapt to changing business needs
Solution Approach 1:
The patent merges access control rules directly into the entity-relationship database model by storing access rules as entities and relationships within the same database system. This integration allows security controls to automatically adapt when business data structures change, eliminating the need for separate configuration updates while maintaining reliable security enforcement.
Solution Approach 2:
The patent implements dynamic access control by storing access rules as configurable entities within the database model, allowing these rules to be modified, added, or removed alongside business requirements without requiring system reconfiguration. This enables the security system to dynamically adapt to changing business needs while maintaining control integrity.
2Ease of operation
If separate configuration files are maintained for access control, then security settings can be managed, but the complexity increases and configuration must be kept up-to-date manually
Solution Approach 1:
The patent eliminates separate configuration files by merging access control rules directly into the entity-relationship database model. Access rules are stored as entities and relationships within the same database, automatically synchronized with business data structures, thereby reducing configuration management complexity while maintaining ease of operation through unified data management.
Solution Approach 2:
The system enables self-service access control management by allowing business users to define and modify access rules using the same entity-relationship model they use for business data. This eliminates the need for separate configuration management processes and reduces complexity by allowing the system to manage its own security configuration through standard database operations.
3Reliability
If access control is defined with respect to entity types, then security can be implemented, but the amount of access control configuration increases with the number of entity types
Solution Approach 1:
The patent implements universal access control by defining access rules at the entity level rather than requiring separate type-specific configurations. The entity-relationship model allows a single access rule definition to apply across multiple entity types through inheritance and relationship mechanisms, reducing configuration volume while maintaining reliable security implementation across the entire database system.
Solution Approach 2:
The patent segments access control configuration into reusable entity templates and relationships within the entity-relationship model. By structuring access rules as modular entities that can be inherited and composed, the system reduces the volume of configuration required while maintaining comprehensive security coverage across diverse entity types through hierarchical and relational structures.
4Adaptability or versatility
If complex entity-relationship structures are modeled, then business objects can be represented accurately, but security configuration becomes more complex and exposes unnecessary complexity to non-technical users
Solution Approach 1:
The patent introduces the entity-relationship model itself as an intermediary layer between complex business structures and security configuration. By storing access rules as entities and relationships within this model, the system shields non-technical users from underlying complexity while accurately representing complex business objects, as security management occurs at the familiar entity level rather than exposing intricate structural details.
Solution Approach 2:
The patent applies homogeneity by using the same entity-relationship model structure for both business data representation and security rule definition. This unified approach allows non-technical users to manage security with the same intuitive tools and concepts they use for business operations, hiding underlying complexity while maintaining accurate business object representation through consistent modeling practices.
Data Source
AI summary
A computer implemented method of securing information stored in an entity relationship database system comprising at least one entity relationship database, the information stored in the entity relationship database system being stored according to an entity relationship model, the method comprising the steps of: specifying access rules limiting access to the entity relationship database system; storing the access rules in the entity relationship database system according to the entity relationship model; permitting an accessor to create an entity in the entity relationship database system if a “create-check” process dependent upon at least one of the one or more stored access rules grants permission; and permitting the accessor to read or modify or delete an entity stored in the entity relationship database system if a “non-create-check” process dependent upon at least one of the one or more stored access rules grants permission.


