Graph-Based Access Control Inference for Cross-Departmental Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face challenges in information access and compliance due to complex structural flows and separate databases across departments, leading to obstructed information flow and the need for timely data collection across the corporation while adhering to domestic and international laws.

Innovation Solution

An information processing apparatus that compares access policies and requests using graph structures, performs inference with ontologies and time-limited rules to convert mismatched items, and generates access permissions, obligations, and policies to facilitate access control across departments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate databases are maintained across departments, then each department can manage its own information independently, but information flow between departments becomes obstructed and data collection across the corporation becomes inefficient

Engineering Contradiction:
Improvedepartmental independenceVSAvoidinformation flow efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

An information processing apparatus acts as an intermediary between separate departmental databases. The apparatus receives access requests from one department, compares them against access policies stored in the apparatus, and grants access to data in other departments' databases when policies are satisfied. This mediator enables cross-departmental information flow while preserving departmental independence and data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex access control policies are implemented across the corporation, then compliance with laws and regulations is improved, but the complexity of managing and comparing access requests increases

Engineering Contradiction:
Improvecompliance assuranceVSAvoidaccess control management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts complex access control logic from individual department systems and centralizes it in a dedicated information processing apparatus. This apparatus stores access policies separately from departmental databases and handles all access control decisions centrally. By taking out the complexity management function to a specialized system, compliance is ensured while individual departments avoid the burden of managing complex policies.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces manual or mechanical access control processes with an automated information processing apparatus that uses graph structure comparison and ontology-based inference. The system automatically compares access requests against policies using computational methods, substituting manual policy management with automated electronic processing. This reduces management complexity while maintaining or improving compliance assurance.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If manual access control review processes are used, then compliance with access policies can be verified, but the time required to process access requests increases

Engineering Contradiction:
Improvepolicy verification accuracyVSAvoidaccess request processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual access control review with an automated information processing apparatus that uses graph structure comparison and ontology-based reasoning. The system automatically compares access requests against stored policies, performs logical inference to determine compliance, and makes access decisions without human intervention. This substitution maintains verification accuracy through systematic policy comparison while dramatically reducing processing time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If centralized access control is implemented, then compliance monitoring is improved, but the complexity of the access control system increases

Engineering Contradiction:
Improvecompliance monitoringVSAvoidcentralized system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized access control system into distinct functional modules: a graph structure comparison unit that compares access requests against policies, an ontology storage unit that stores domain knowledge, and an inference engine that performs logical reasoning. This segmentation organizes the centralized system into manageable components, improving compliance monitoring capability while making the overall system complexity more tractable through modular design.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10380080B2Information processing apparatus, storage medium, and information processing method
Publication Date: 2019.08.13 FUJIFILM BUSINESS INNOVATION CORP
  • US10380080B2 patent drawing
  • US10380080B2 patent drawing
  • US10380080B2 patent drawing

AI summary

An information processing apparatus includes: a comparison unit that compares first access information having a graph structure indicating a predetermined access policy and second access information having a graph structure indicating an access request for access to an object by a user; and a conversion unit that performs an inference on mismatched items using an ontology of the first access information and the second access information and time-limited rules in a case where some of items in the first access information and items in the second access information do not match each other as a result of the comparison made by the comparison unit to convert such items into matching items.