Flexible Data Access Control with Runtime Logging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data access control systems are inflexible and often lag behind changing business requirements, necessitating frequent redefinitions of access control models, which are hindered by administrative bureaucracy.
Innovation Solution
A system and method for flexible data access control that includes a data access controller, a run-time data access modifier, and a data access request logger, allowing for dynamic presentation of authorized data while maintaining records of requests and explanations, enabling access to previously restricted data items based on predefined criteria.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a predefined access control model is applied to data, then data security and access control are maintained, but the system cannot adapt to changing business requirements in a timely manner
Solution Approach 1:
The system performs preliminary actions by logging access requests and explanations before formal model redefinition occurs. The run-time data access modifier captures requestor identity, requested data items, and explanations in advance, creating a ready-to-process record that can be quickly reviewed and approved without waiting for bureaucratic redefinition cycles.
Solution Approach 2:
The patent introduces an intermediary mechanism (the run-time data access modifier and logging system) between the strict access control model and business requirements. This intermediary captures and processes access requests, allowing flexible adaptation while maintaining the integrity of the predefined access control model through structured record-keeping and approval workflows.
2Adaptability or versatility
If access control model redefinition is performed frequently to meet changing requirements, then adaptability improves, but administrative bureaucracy increases and efficiency decreases
Solution Approach 1:
The system extracts the time-consuming elements of access control management (logging, record-keeping, explanation collection) from the main access control model. By separating these administrative functions into a dedicated logging and modification system, the core access control model remains stable while adaptive changes are handled efficiently through the extracted subsystem.
Solution Approach 2:
The run-time data access modifier enables a form of self-service by automatically logging requests, capturing explanations, and maintaining records without requiring immediate administrative intervention. The system serves itself by preprocessing and organizing access requests, reducing the administrative burden and improving overall productivity.
3Ease of operation
If restricted data items are made accessible based on runtime requests, then data access flexibility improves, but data security control may be weakened
Solution Approach 1:
The system implements feedback mechanisms by logging all access requests, explanations, and approvals. This creates an audit trail that provides continuous feedback on access patterns, allowing the system to maintain security integrity while enabling flexible access. The feedback loop ensures that any deviations from the predefined model are tracked, reviewed, and can be corrected if necessary.
Solution Approach 2:
The system performs preliminary security checks and logging before granting access to restricted data items. By capturing requestor identity, requested data, and explanations in advance, the system ensures that security controls are maintained while enabling flexible access decisions based on preprocessed information rather than ad-hoc judgments.
Data Source
AI summary
A method for presenting data, the method including presenting via a first computer output device an indicator indicating a data item whose value is prevented, in accordance with predefined access control criteria, from being presented via the first computer output device, receiving from a requestor a request to present the data item value, maintaining a record of an identity of the requestor together with a description of the requested data item, and presenting via a second computer output device the data item value.


