Hierarchical Data Segmentation for Fine-Grained Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data protection methods lack fine-grained access control for unstructured data, leading to potential exposure of sensitive information and compliance risks, especially in environments where sensitive data is mixed with non-sensitive data without special protection.
Innovation Solution
Implementing techniques for enterprise-level data protection with variable data granularity and data disclosure control using hierarchical summarization, topical structuring, and traversal audit, which involve transforming unstructured data into sections and subsections, appending audit and retrieval agent code, and logging user access to enforce accountability and reduce exposure of sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control is implemented at the file level or data table level, then data protection is provided, but fine-grained access control for unstructured data with mixed sensitive and non-sensitive information is not achieved
Solution Approach 1:
The patent segments unstructured data into structured components by dividing documents into sections and subsections based on topical analysis. This segmentation enables fine-grained access control at the section level rather than requiring control at the entire file level, thus improving data protection reliability while managing complexity through automated topical segmentation.
Solution Approach 2:
The patent applies local quality by assigning different security attributes to different sections and subsections of documents based on their sensitivity and topical content. This allows sensitive portions of unstructured data to receive enhanced protection while non-sensitive portions remain accessible, achieving fine-grained access control without uniformly complicating the entire system.
2Ease of operation
If sensitive data is mixed with non-sensitive data without special protection, then data accessibility is maintained, but exposure of sensitive information and compliance risks increase
Solution Approach 1:
The patent segments mixed sensitive and non-sensitive data within unstructured documents by performing topical analysis to divide content into distinct sections. This segmentation allows the system to maintain ease of operation for non-sensitive portions while applying special protection to sensitive sections, thus reducing sensitive information exposure without compromising overall data accessibility.
Solution Approach 2:
The patent applies local quality by differentiating security treatments for different portions of unstructured data based on sensitivity classification. Sensitive sections receive enhanced protection measures while non-sensitive sections remain easily accessible, resolving the contradiction between data accessibility and sensitive information exposure through location-specific security attributes.
3Reliability
If hierarchical summarization and topical structuring are implemented, then data disclosure control is improved, but processing complexity and time increase
Solution Approach 1:
The patent applies preliminary action by performing topical analysis and hierarchical summarization of unstructured data in advance, before access control decisions are needed. This preprocessing creates a structured framework of sections and subsections with assigned security attributes, enabling faster access control decisions later while improving data disclosure control through proactive organization.
Solution Approach 2:
The patent implements self-service by using automated topical analysis algorithms that independently structure unstructured data without requiring manual intervention. The system automatically performs hierarchical summarization and assigns security attributes to sections, reducing processing time while maintaining reliable data disclosure control through consistent automated classification.
4Measurement precision
If audit and retrieval agent code is appended to sections and subsections, then accountability and auditing precision are enhanced, but system complexity and processing overhead increase
Solution Approach 1:
The patent segments the auditing function by appending audit and retrieval agent code to specific sections and subsections rather than implementing a monolithic auditing system. This segmentation enables precise tracking of access to individual sections, enhancing auditing precision while managing system complexity through modular, distributed audit agents that operate independently at the section level.
Data Source
AI summary
Access is obtained to a plurality of intermediately transformed electronic documents (with a plurality of sections and subsections) which have been transformed, by topical analysis and text summarization techniques, from a plurality of original electronic documents comprising at least some unstructured electronic documents. Audit and retrieval agent code is appended to the sections and subsections to create a plurality of finally transformed electronic documents. Users are allowed to access the finally transformed electronic documents. The users are provided with accountability reminders contemporaneous with the access. The access of the users to the sections and subsections of the finally transformed electronic documents is logged. An audit report is provided based on the logging. Also provided is a cloud service for enterprise-level sensitive data protection with variable data granularity, using one or more one guest virtual machine images.


