Policy-Based Genomic Data Sharing Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current genomic data sharing systems face challenges in facilitating controlled and collaborative access to genomic digital data among software-as-a-service tenants due to technical, security, and legal constraints, leading to fragmented data ecosystems that hinder global collaboration and integration.

Innovation Solution

A cloud-based platform implementing policy-based access control, where access to genomic digital data is managed through role identifiers linked to policy documents, enabling automated and controlled access by generating signed access tokens based on attributes and conditions, allowing secure and controlled sharing among tenants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional data sharing methods are used, then data accessibility is improved, but security and control are worsened

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity and control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a policy-based access control system as an intermediary between data owners and data requesters. The system uses policy documents that define access conditions and role identifiers to mediate the access decision process, enabling secure and controlled data sharing without direct trust between parties

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical access control mechanisms with a policy-based evaluation system. Instead of relying on static permission lists or authentication tokens, the system dynamically evaluates access requests against policy documents that contain conditions and role identifiers, providing more flexible and secure access control

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual access control processes are used, then security is improved, but administrative burden is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a self-service access control system where the policy evaluation engine automatically processes access requests by evaluating them against stored policy documents. The system autonomously determines access decisions based on role identifiers and policy conditions, eliminating the need for manual administrative intervention in access control decisions

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent pre-configures policy documents and role identifiers before access requests are made. By establishing access policies in advance and storing them in the policy store, the system enables rapid automated evaluation of access requests without requiring real-time administrative decisions, thus reducing administrative burden while maintaining security

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If flexible access control is implemented, then adaptability is improved, but system complexity is worsened

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the access control system into distinct components: policy documents, role identifiers, and a policy evaluation engine. This segmentation allows each component to handle specific aspects of access control independently, making the overall system more manageable and easier to implement while providing flexible access control capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal policy-based access control framework that can handle multiple access control scenarios through a single unified system. The policy evaluation engine can process various types of access requests, evaluate different policy conditions, and manage multiple role identifiers, providing flexible access control without requiring separate systems for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12058129B2Policy-based genomic data sharing for software-as-a-service tenants
Publication Date: 2024.08.06 ILLUMINA INC
  • US12058129B2 patent drawing
  • US12058129B2 patent drawing
  • US12058129B2 patent drawing

AI summary

Policy-based genomic digital data sharing facilitates a variety of sharing scenarios, including public access, tenant-to-tenant sharing, workgroup sharing, and access by external service providers. Genomic digital data can be published to the platform and controlled by access tokens that are generated based on access policies. The policies can support conditions that are evaluated at execution time and effectively place control of access to information in hands of the owning tenant. Sharing conditions can be easily specified to support various use cases, relieving administrators from excessive access control configuration.