Geographic Data Platform Provisioning for Role-Based Map Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing map services face challenges in efficiently exposing and managing large datasets for geospatial data, including deployment and provisioning of map servers and data partitions, which affects computational resource usage and efficiency.
Innovation Solution
A geographic information system data platform that provisions domain accounts on map servers, controls access through user roles, and secures data partitions using entitlements, enabling efficient management and deployment of map services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If map services handle millions of data points to visualize and analyze large amounts of geospatial data, then the data processing capability and visualization quality are improved, but the computational resource usage and system complexity increase
Solution Approach 1:
The patent segments geospatial data into discrete data points that can be individually managed and processed. Map services handle millions of这些数据点 efficiently through structured data partitions and hierarchical organization, allowing the system to process large volumes of data without becoming unmanageably complex
Solution Approach 2:
The patent introduces multiple organizational dimensions for geospatial data including spatial dimensions (coordinates, boundaries), hierarchical dimensions (data partitions, folders), and access control dimensions (roles, permissions). This multi-dimensional organization allows efficient processing while maintaining system structure
2Productivity
If map servers and data partitions are deployed to handle large datasets, then the data processing capacity is improved, but the deployment and provisioning management becomes more difficult
Solution Approach 1:
The patent creates a universal provisioning system that manages map servers and data partitions through standardized interfaces and procedures. The domain account provisioning process works consistently across different map servers and data partition configurations, making deployment management easier despite increased processing capacity
Solution Approach 2:
The patent introduces a provisioning system as an intermediary between administrators and map servers. This intermediary handles the complexity of deploying and provisioning map servers and data partitions through automated processes, reducing the operational burden on users
3Adaptability or versatility
If domain accounts are provisioned to multiple map servers to process domain application requests, then the system scalability and request processing capability are improved, but the access control and security management complexity increases
Solution Approach 1:
The patent implements a universal user role configuration system that works across multiple map servers and domain accounts. The same user role definitions and access control mechanisms function consistently throughout the distributed system, enabling scalability without proportionally increasing access control complexity
Solution Approach 2:
The patent uses template-based provisioning where user role configurations and access control policies can be copied and replicated across multiple domain accounts and map servers. This allows consistent access control management to be scaled across the system without manually configuring each component
4Reliability
If data partition entitlements are used to secure access to data partitions, then the data security and access control precision are improved, but the authentication and authorization overhead increases
Solution Approach 1:
The patent performs access control validation as part of the domain application request provisioning process, before the actual data access occurs. By pre-establishing user roles, permissions, and data partition entitlements during provisioning, the system reduces authentication overhead during actual data access operations
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method implements a geographic information system data platform. The method includes provisioning a domain account, corresponding to a domain application, as one of a set of domain accounts to a map server to process a set of domain application requests from a set of domain applications including the domain application. The method further includes controlling access to the domain accounts based on a user role configuration. The method further includes mapping a domain application request from the domain application to the domain account on the map server based on a user role configuration. The method further includes securing access to a data partition within the domain account using a data partition entitlement for the request.