Graph Access Management via Completeness Conditions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional privacy-preserving data mining techniques are limited in the types of operations they allow on data and incur high processing overhead, while also restricting access to various portions of access-restricted data.

Innovation Solution

An access management method that determines whether complete access information is available for a node in a graph by combining pre-acquired access information, allowing access when the completeness condition is met and restricting access otherwise, enabling multiple devices to share a concealed graph and manage access control effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional privacy preserving data mining techniques are used to protect data privacy, then data confidentiality is improved, but processing overhead increases and operation types are limited

Engineering Contradiction:
Improvedata confidentialityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the access control system into multiple sharing servers, each responsible for specific portions of the concealed graph. This distribution reduces the processing burden on individual servers while maintaining overall data confidentiality through coordinated access management across the segmented system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an access management system that acts as an intermediary between users and the concealed graph data. This mediator manages access requests by verifying completeness conditions and coordinating with multiple sharing servers, reducing direct processing overhead on the data storage system while preserving confidentiality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional privacy preserving data mining techniques are used to protect data privacy, then data confidentiality is improved, but the types of operations on data are limited

Engineering Contradiction:
Improvedata confidentialityVSAvoidoperation types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal access management framework that can handle multiple types of operations (read, write, delete, etc.) on concealed graph data across multiple sharing servers. This multi-functional system maintains data confidentiality while enabling diverse operations that conventional PPDM techniques cannot support.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs dynamic access control where the system adaptively determines whether completeness conditions are met based on the specific operation type and data portion requested. This dynamic approach allows flexible operation types while maintaining confidentiality by adjusting access permissions in real-time based on operational requirements.

Inventive Principle:
Principle #15Dynamics

3Reliability

If access control is implemented on the entire concealed graph in each sharing server, then data security is improved, but processing load increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the concealed graph into portions distributed across multiple sharing servers, with each server implementing access control only for its specific portion. This segmentation reduces the processing load on individual servers while maintaining overall data security through coordinated access management across the distributed system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges the access control functions across multiple sharing servers into a coordinated system. Each server handles access control for its portion of the graph, and the system combines these local access control decisions to provide comprehensive security without requiring any single server to process the entire graph, thus reducing individual processing loads.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3435271B1Access management method, information processing device, program, and recording medium
Publication Date: 2021.10.06 ASSEMBLOGUE INC
  • EP3435271B1 patent drawingFigure 1
  • EP3435271B1 patent drawingFigure 2
  • EP3435271B1 patent drawingFigure 3

AI summary

To appropriately access various portions of a concealed graph while suppressing a processing load. Provided is an access management method in which a computer including a control unit performs access management of a graph comprising nodes and directed links between the nodes. The control unit determines, in response to an attempt to access a node N, whether a completeness condition, which indicates that complete access information that is access information with which it is possible to access the node N can be obtained, is satisfied, by combining pieces of access information which have been acquired before accessing the node N. The control unit permits access to the node N from a node M when the completeness condition is satisfied. The control unit suspends access to the node N from the node M when the completeness condition is not satisfied.