Knowledge Graph Access Control via Structural Radius
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing user access to knowledge graphs is challenging due to the complexity of traditional solutions like relational database management systems and the management intensity of maintaining multiple knowledge graphs or access control lists, especially for dynamically changing data structures.
Innovation Solution
A method and system that control user access to a target node in a knowledge graph by defining knowledge graph structure limitations, such as step size or radius, based on the number of edges and node types, dynamically determining access conditions, and granting access accordingly, without relying on access control lists.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If access control lists (ACL) are used to manage user access to knowledge graph nodes, then access control precision is improved, but device complexity and management burden increase
Solution Approach 1:
The system enables self-service access control by automatically determining access rights based on the knowledge graph structure itself. The number of edges connecting a user's start node to the target node automatically defines the access condition, eliminating the need for manual ACL configuration and management while maintaining precise control over who can access which nodes.
Solution Approach 2:
The knowledge graph structure serves multiple functions simultaneously: it stores the data relationships and inherently provides the access control mechanism. The same graph structure that represents knowledge relationships also defines user access rights through its edge connections, eliminating the need for separate ACL management systems.
2Manufacturing precision
If multiple knowledge graphs are maintained for different user sets, then access control precision is improved, but productivity and operational efficiency decrease
Solution Approach 1:
The invention merges the access control mechanism with the single knowledge graph structure. Instead of maintaining separate knowledge graphs for different users, the system combines user access rights into the same graph by using the edge connection structure to define which users can access which nodes, thereby improving operational efficiency while maintaining precise access control.
Solution Approach 2:
The single knowledge graph structure serves universal purposes for all users simultaneously. The graph structure inherently provides different access levels to different users based on their start node connections, eliminating the need for multiple separate graphs and the operational burden of managing them.
3Quantity of substance
If traditional relational database management systems are used, then data storage capability is improved, but adaptability to dynamically connected data decreases
Solution Approach 1:
The system uses a dynamic knowledge graph structure where nodes and edges can be freely added, removed, or modified to represent changing relationships. This dynamic structure naturally adapts to evolving data connections and user access requirements without requiring rigid schema changes, unlike traditional relational database systems.
Solution Approach 2:
The invention changes the fundamental parameter from fixed relational schemas to flexible graph-based connections. By representing data as nodes and edges in a knowledge graph, the system can dynamically adapt to changing relationships and access patterns while maintaining the ability to store large amounts of data.
Data Source
AI summary
A method and a related system for controlling user access to a target node in a knowledge graph may be provided. The method comprises defining a knowledge graph structure limitation for a user, defining a node type depending on the number of edges connecting to the node, determining a condition for an access to the target node, based on the knowledge graph structure limitation relative to the start node and the node type of the target node, upon the user attempting, coming from a start node, to access the target node in the knowledge graph, and granting access to the target node based on the determination.


