Policy-Based Genomic Data Sharing Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current genomic data sharing systems face challenges in facilitating controlled and collaborative access to genomic digital data among software-as-a-service tenants due to technical, security, and legal constraints, leading to fragmented data ecosystems that hinder global collaboration and integration.
Innovation Solution
A cloud-based platform implementing policy-based access control, where access to genomic digital data is managed through role identifiers linked to policy documents, enabling automated and controlled access by generating signed access tokens based on attributes and conditions, allowing secure and controlled sharing among tenants.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional data sharing methods are used, then data accessibility is improved, but security and control are worsened
Solution Approach 1:
The patent introduces a policy-based access control system as an intermediary between data owners and data requesters. The system uses policy documents that define access conditions and role identifiers to mediate the access decision process, enabling secure and controlled data sharing without direct trust between parties
Solution Approach 2:
The patent replaces traditional mechanical access control mechanisms with a policy-based evaluation system. Instead of relying on static permission lists or authentication tokens, the system dynamically evaluates access requests against policy documents that contain conditions and role identifiers, providing more flexible and secure access control
2Reliability
If manual access control processes are used, then security is improved, but administrative burden is worsened
Solution Approach 1:
The patent implements a self-service access control system where the policy evaluation engine automatically processes access requests by evaluating them against stored policy documents. The system autonomously determines access decisions based on role identifiers and policy conditions, eliminating the need for manual administrative intervention in access control decisions
Solution Approach 2:
The patent pre-configures policy documents and role identifiers before access requests are made. By establishing access policies in advance and storing them in the policy store, the system enables rapid automated evaluation of access requests without requiring real-time administrative decisions, thus reducing administrative burden while maintaining security
3Adaptability or versatility
If flexible access control is implemented, then adaptability is improved, but system complexity is worsened
Solution Approach 1:
The patent segments the access control system into distinct components: policy documents, role identifiers, and a policy evaluation engine. This segmentation allows each component to handle specific aspects of access control independently, making the overall system more manageable and easier to implement while providing flexible access control capabilities
Solution Approach 2:
The patent creates a universal policy-based access control framework that can handle multiple access control scenarios through a single unified system. The policy evaluation engine can process various types of access requests, evaluate different policy conditions, and manage multiple role identifiers, providing flexible access control without requiring separate systems for each function
Data Source
AI summary
Policy-based genomic digital data sharing facilitates a variety of sharing scenarios, including public access, tenant-to-tenant sharing, workgroup sharing, and access by external service providers. Genomic digital data can be published to the platform and controlled by access tokens that are generated based on access policies. The policies can support conditions that are evaluated at execution time and effectively place control of access to information in hands of the owning tenant. Sharing conditions can be easily specified to support various use cases, relieving administrators from excessive access control configuration.


