Global Namespace Data Access Control Platform
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data access management techniques are ineffective in controlling access to data across multiple geo-locations and cloud services, failing to protect data outside centralized locations and unable to track private data throughout its lifecycle, leading to vulnerabilities and compliance issues.
Innovation Solution
A data control platform that implements access controls independently of data location, using a global namespace to manage access policies, data record location descriptors, and compliance policies, ensuring secure data access and governance across distributed data platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional centralized access controls are used to manage data access, then access control implementation is simplified, but data protection is lost when data moves outside the centralized location
Solution Approach 1:
The patent segments the access control mechanism from the data storage location. Instead of having access controls tied to a single centralized location, the system divides access control into portable policy components that can travel with data across multiple locations and transformations, enabling protection without requiring centralized control at each data point
Solution Approach 2:
The patent introduces an intermediary access control system that sits between the data and various access points. This intermediary layer enforces access policies regardless of where the data is located or what transformations it has undergone, acting as a mediator that maintains security without requiring direct control over the underlying data storage
2Adaptability or versatility
If data is allowed to move freely across multiple locations and transformations, then data utility and accessibility are improved, but tracking and protecting private data becomes difficult
Solution Approach 1:
The patent applies local quality by attaching specific access control metadata and policy tags to individual data elements as they move through transformations. This allows the system to track and protect only the private portions of data that require protection, while allowing other data to move freely, thus maintaining data utility while enabling targeted tracking
Solution Approach 2:
The patent implements feedback mechanisms that continuously monitor data movements and transformations. The system provides feedback about data location and transformation state to the access control engine, which then adjusts access decisions accordingly, enabling continuous tracking without blocking data flow
3Reliability
If access controls are implemented at every data location and transformation point, then data protection is maintained, but system complexity increases significantly
Solution Approach 1:
The patent creates a universal access control framework that handles multiple locations, storage systems, and transformation types through a single unified policy enforcement mechanism. This universal system reduces complexity by eliminating the need for separate access control implementations at each data point while maintaining comprehensive protection
Data Source
AI summary
A method in one embodiment comprises receiving a plurality of requests for data records from a plurality of clients. The data is in a plurality of data systems of a global namespace, and the plurality of data systems are in a plurality of locations. The method also comprises determining whether a given client is allowed access to one or more of the data records based on one or more of a plurality of data access policies, retrieving the data records from at least one of the data systems based on a determination that the given client is allowed access to the data records, and providing the data records to the given client. Retrieving the data records comprises determining a location for the data records, and generating a channel to the location through which the data records are retrieved.


