Graph-Based Access Control Inference for Cross-Departmental Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face challenges in information access and compliance due to complex structural flows and separate databases across departments, leading to obstructed information flow and the need for timely data collection across the corporation while adhering to domestic and international laws.
Innovation Solution
An information processing apparatus that compares access policies and requests using graph structures, performs inference with ontologies and time-limited rules to convert mismatched items, and generates access permissions, obligations, and policies to facilitate access control across departments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If separate databases are maintained across departments, then each department can manage its own information independently, but information flow between departments becomes obstructed and data collection across the corporation becomes inefficient
Solution Approach 1:
An information processing apparatus acts as an intermediary between separate departmental databases. The apparatus receives access requests from one department, compares them against access policies stored in the apparatus, and grants access to data in other departments' databases when policies are satisfied. This mediator enables cross-departmental information flow while preserving departmental independence and data security.
2Reliability
If complex access control policies are implemented across the corporation, then compliance with laws and regulations is improved, but the complexity of managing and comparing access requests increases
Solution Approach 1:
The patent extracts complex access control logic from individual department systems and centralizes it in a dedicated information processing apparatus. This apparatus stores access policies separately from departmental databases and handles all access control decisions centrally. By taking out the complexity management function to a specialized system, compliance is ensured while individual departments avoid the burden of managing complex policies.
Solution Approach 2:
The patent replaces manual or mechanical access control processes with an automated information processing apparatus that uses graph structure comparison and ontology-based inference. The system automatically compares access requests against policies using computational methods, substituting manual policy management with automated electronic processing. This reduces management complexity while maintaining or improving compliance assurance.
3Reliability
If manual access control review processes are used, then compliance with access policies can be verified, but the time required to process access requests increases
Solution Approach 1:
The patent replaces manual access control review with an automated information processing apparatus that uses graph structure comparison and ontology-based reasoning. The system automatically compares access requests against stored policies, performs logical inference to determine compliance, and makes access decisions without human intervention. This substitution maintains verification accuracy through systematic policy comparison while dramatically reducing processing time.
4Reliability
If centralized access control is implemented, then compliance monitoring is improved, but the complexity of the access control system increases
Solution Approach 1:
The patent segments the centralized access control system into distinct functional modules: a graph structure comparison unit that compares access requests against policies, an ontology storage unit that stores domain knowledge, and an inference engine that performs logical reasoning. This segmentation organizes the centralized system into manageable components, improving compliance monitoring capability while making the overall system complexity more tractable through modular design.
Data Source
AI summary
An information processing apparatus includes: a comparison unit that compares first access information having a graph structure indicating a predetermined access policy and second access information having a graph structure indicating an access request for access to an object by a user; and a conversion unit that performs an inference on mismatched items using an ontology of the first access information and the second access information and time-limited rules in a case where some of items in the first access information and items in the second access information do not match each other as a result of the comparison made by the comparison unit to convert such items into matching items.


