Graph Security Overlays for Dynamic Node Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional database security mechanisms provide uniform protection across all data, leaving sensitive information vulnerable to unauthorized access and breaches, which can compromise the entire database.

Innovation Solution

Implementing a dynamic security system for executable graph-based models by associating security overlay nodes with each data record, adjusting security levels based on confidentiality, and enabling real-time access control to protect sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single-layer security mechanism is implemented for the entire database, then the database structure is simple and easy to manage, but a single security breach leads to the entire database getting exposed

Engineering Contradiction:
Improvesecurity mechanism structureVSAvoiddata protection reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the database into multiple isolated graph-based data structures, where each graph represents a separate security domain. Security breaches are contained within individual graphs and cannot propagate to other graphs, thus segmenting the security risk while maintaining manageable structure through modular graph operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security policies and access controls are applied to different graphs based on their specific sensitivity and requirements. Each graph can have customized security parameters, allowing high-security graphs to have stricter controls while less sensitive graphs have more accessible policies, optimizing both security and manageability.

Inventive Principle:
Principle #3Local quality

2Ease of manufacture

If uniform security protection is applied to all data records, then the security policy is simple to implement, but sensitive information remains vulnerable to unauthorized access

Engineering Contradiction:
Improvesecurity policy implementationVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent implements differentiated security policies where each graph can define its own access control rules, encryption methods, and authentication requirements based on data sensitivity. This allows simple uniform policies for less sensitive data while applying enhanced security measures to sensitive graphs without complicating the overall system implementation.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Security policies are made dynamic and adaptable, allowing graphs to adjust their security parameters based on threats, user roles, and data access patterns. The system can dynamically modify access controls and security measures for individual graphs while maintaining a straightforward base implementation framework.

Inventive Principle:
Principle #15Dynamics

3Reliability

If security overlay nodes are associated with each data record, then data protection is enhanced, but processing latency increases

Engineering Contradiction:
Improvedata protectionVSAvoidprocessing latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security validation and access control checks are performed in advance when data is written to graphs, rather than during every read operation. Access permissions are pre-validated and cached, allowing rapid data retrieval while maintaining strong security protections, thus reducing processing latency for legitimate operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Security overlay nodes are implemented as modular, independent components attached to specific graphs rather than as a monolithic security layer. This segmentation allows the system to activate only the necessary security checks for each operation, reducing overhead and processing latency while maintaining comprehensive data protection.

Inventive Principle:
Principle #1Segmentation

4Device complexity

If the entire database is exposed in case of security breach, then the security mechanism is simple to implement, but the impact of breaches is severe

Engineering Contradiction:
Improvesecurity mechanismVSAvoidbreach impact
Core Design Contradiction:
Device complexityVSObject-generated harmful factors

Solution Approach 1:

The database is segmented into multiple isolated graphs where each graph acts as an independent security boundary. A security breach in one graph is contained and cannot propagate to other graphs, automatically limiting breach impact without requiring complex additional security mechanisms. The modular graph structure provides inherent isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Graph-based data structures serve as intermediary layers between the physical database storage and access requests. These graphs enforce security boundaries and control data flow, preventing direct access to underlying data structures and containing potential breaches within the graph layer without exposing the entire database.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12518047B2Dynamic security for graph-based models
Publication Date: 2026.01.06 INFOSYS LTD
  • US12518047B2 patent drawing
  • US12518047B2 patent drawing
  • US12518047B2 patent drawing

AI summary

An overlay system including processing circuitry and storage element that stores various base nodes and various security overlay nodes, is provided. Each base node is associated with one or more security overlay nodes that control access to the information value contained in the base node. The processing circuitry receives a contextualized stimulus that indicates a requirement for associating two or more nodes. The processing circuitry identifies two base nodes required for processing the contextualized stimulus and executes an operation on the two identified base nodes to create an aggregated node. Thus, the aggregated node contains a higher information value than the two identified base nodes. Consequently, the processing circuitry dynamically associates, with the aggregated node, one or more security overlay nodes that have an equal or higher security level than the security levels of security overlay nodes associated with the two identified base nodes.