Hosted Data Access Platform for Controlled Sensitive-Data Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in balancing the need to allow various types of system operators and users to access sensitive data while maintaining confidentiality by limiting access to such information, often leading to unauthorized dissemination of sensitive data.
Innovation Solution
A hosted access platform on a server that controls data access and processing, using access category indicators and definitions to manage access requests, allowing legitimate use while retaining control over data dissemination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If direct access to sensitive data is allowed for various system operators and users, then data accessibility and operational efficiency are improved, but data confidentiality and security deteriorate due to unauthorized dissemination
Solution Approach 1:
The patent introduces an intermediation server that acts as a mediator between users and sensitive data. This server hosts data access functions and enforces access restrictions without requiring users to have direct access to the underlying data source. The intermediation server evaluates access requests against stored access definitions and restrictions, thereby enabling controlled data accessibility while preventing unauthorized dissemination.
2Object-affected harmful factors
If access restrictions are imposed on sensitive data to maintain confidentiality, then data security is improved, but data accessibility and operational efficiency deteriorate
Solution Approach 1:
The patent implements preliminary action by pre-defining access restrictions and access definitions before any data access occurs. Access definitions include record identification criteria, access category indicators, and associated restrictions that are stored in advance on the intermediation server. When users request data access, the system simply evaluates their requests against these pre-established rules, maintaining security without impeding operational efficiency.
3Reliability
If comprehensive access control mechanisms are implemented to prevent unauthorized data access, then data security is improved, but system complexity increases
Solution Approach 1:
The patent applies segmentation by dividing access control into distinct modular components: access definitions (including record identification criteria, access category indicators, and restrictions), mapping data (linking access type indicators to access category indicators), and hosted data access functions. This modular structure allows the system to enforce comprehensive security controls while maintaining manageable system complexity through organized, reusable access control templates.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method includes: establishing, at a server, a connection with a data source storing a plurality of records; storing, at the server, mapping data defining a set of access category indicators, and for each access category indicator, a plurality of corresponding access type indicators; storing, at the server, an access definition including (i) a record identification criterion, (ii) one of the access category indicators, and (iii) an access restriction associated with the access category indicator; receiving, from a client device, a request to access a portion of the plurality of records, the request including one of the access type indicators; determining, from the mapping data, that the access type indicator corresponds to the access category indicator of the access definition; and in response to determining that the portion of the plurality of records satisfies the record identification criterion, responding to the request according to the access restriction.