Graph-Based Industrial Data Access Control by Scope and Role

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to efficiently manage and control access to complex data in industrial plants, particularly in large-scale chemical plants, where vast amounts of data from sensors and actuators require secure and context-sensitive access control.

Innovation Solution

A graph database model is used to represent and store data and relationships within an industrial plant, with scopes and authorization providers determining access rights based on roles, enabling secure and context-sensitive data access through a graph structure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional access control systems are used to manage data in industrial plants, then implementation is simple, but the system cannot efficiently handle complex data relationships and context-sensitive access requirements

Engineering Contradiction:
Improvecontext-sensitive data accessVSAvoidaccess control system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a graph database as an intermediary layer between the access control system and the complex industrial plant data. This graph database models data relationships using nodes, edges, and properties, enabling context-sensitive access control without requiring the access control system itself to become overly complex. The graph structure serves as a mediator that naturally represents complex relationships while maintaining manageable access control logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the fundamental parameters of how data is structured and accessed by transitioning from traditional flat database schemas to a graph-based model with nodes, edges, and properties. This parameter change enables the system to handle complex data relationships and context-sensitive access requirements by representing data in a way that naturally captures relationships and contexts.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If comprehensive data access is allowed in industrial plants, then data usability is improved, but security risks increase

Engineering Contradiction:
Improvedata access easeVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different access rights and scopes to different nodes, edges, and properties within the graph database. Instead of applying uniform access control across all data, the system allows fine-grained, location-specific access permissions based on the particular data element and its context within the graph structure, enabling both ease of operation and security.

Inventive Principle:
Principle #3Local quality

3Loss of information

If data is stored in a graph database with detailed relationships, then data context and relationships are preserved, but data management complexity increases

Engineering Contradiction:
Improvedata relationship informationVSAvoiddata management system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies universality by using the graph database structure to serve multiple functions simultaneously: storing data, representing relationships, enabling context-sensitive access control, and supporting various query patterns. The same graph structure that preserves data relationships also naturally supports the access control mechanism, reducing the need for separate complex management systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250384154A1Method and system for controlling access to data in an industrial plant or in a database associated to the industrial plant
Publication Date: 2025.12.18 BASF SE
  • US20250384154A1 patent drawing
  • US20250384154A1 patent drawing
  • US20250384154A1 patent drawing

AI summary

A method for controlling access to data in at least one an industrial plant or in a data base associated to the at least one industrial plant is provided. Elements of the industrial plant are mapped to elements of a graph structure. Scopes (S10-S30) associated to elements (11-18) of the graph structure are defined. At least one authorization provider (31-33) is associated to one of the scopes (S10-S30). A request for data from a requesting entity for data from at least one a target entity is received via an application programming inter-face (API). It is determining to which scope (S10-S30) the requested data is related to. Authorization to the request from the requesting entity for the data from the target entity is provided by the at least one authorization provider (31-33) associated to the scope (S10-S20) to which the request is related to. The requesting entity is granted access to the requested data based on the authorized request.