Graph-Based Industrial Data Access Control by Scope and Role
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems struggle to efficiently manage and control access to complex data in industrial plants, particularly in large-scale chemical plants, where vast amounts of data from sensors and actuators require secure and context-sensitive access control.
Innovation Solution
A graph database model is used to represent and store data and relationships within an industrial plant, with scopes and authorization providers determining access rights based on roles, enabling secure and context-sensitive data access through a graph structure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional access control systems are used to manage data in industrial plants, then implementation is simple, but the system cannot efficiently handle complex data relationships and context-sensitive access requirements
Solution Approach 1:
The patent introduces a graph database as an intermediary layer between the access control system and the complex industrial plant data. This graph database models data relationships using nodes, edges, and properties, enabling context-sensitive access control without requiring the access control system itself to become overly complex. The graph structure serves as a mediator that naturally represents complex relationships while maintaining manageable access control logic.
Solution Approach 2:
The patent changes the fundamental parameters of how data is structured and accessed by transitioning from traditional flat database schemas to a graph-based model with nodes, edges, and properties. This parameter change enables the system to handle complex data relationships and context-sensitive access requirements by representing data in a way that naturally captures relationships and contexts.
2Ease of operation
If comprehensive data access is allowed in industrial plants, then data usability is improved, but security risks increase
Solution Approach 1:
The patent applies local quality by assigning different access rights and scopes to different nodes, edges, and properties within the graph database. Instead of applying uniform access control across all data, the system allows fine-grained, location-specific access permissions based on the particular data element and its context within the graph structure, enabling both ease of operation and security.
3Loss of information
If data is stored in a graph database with detailed relationships, then data context and relationships are preserved, but data management complexity increases
Solution Approach 1:
The patent applies universality by using the graph database structure to serve multiple functions simultaneously: storing data, representing relationships, enabling context-sensitive access control, and supporting various query patterns. The same graph structure that preserves data relationships also naturally supports the access control mechanism, reducing the need for separate complex management systems.
Data Source
AI summary
A method for controlling access to data in at least one an industrial plant or in a data base associated to the at least one industrial plant is provided. Elements of the industrial plant are mapped to elements of a graph structure. Scopes (S10-S30) associated to elements (11-18) of the graph structure are defined. At least one authorization provider (31-33) is associated to one of the scopes (S10-S30). A request for data from a requesting entity for data from at least one a target entity is received via an application programming inter-face (API). It is determining to which scope (S10-S30) the requested data is related to. Authorization to the request from the requesting entity for the data from the target entity is provided by the at least one authorization provider (31-33) associated to the scope (S10-S20) to which the request is related to. The requesting entity is granted access to the requested data based on the authorized request.


