Multi-tiered Rule-based Data Access Permissioning Filters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data permissioning systems lack granular control over data access, failing to accommodate context-specific, requester-specific, and time-sensitive permissions, leading to fragmented privacy management and non-compliance with individual preferences and laws across disparate data silos.

Innovation Solution

A computer-based system implementing multi-tiered, rule-based data access permissioning filters that allow users to customize access based on contexts, entity types, date ranges, and data sources, integrating laws, consent agreements, and individual preferences to manage sensitive information securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data are segregated into non-overlapping silos across different organizations, then patient privacy is protected at each source, but applications cannot leverage data across silos to obtain a complete picture of patient health

Engineering Contradiction:
Improvepatient privacy protectionVSAvoidcomplete picture of patient health
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

A patient-controlled data exchange system acts as an intermediary between data sources (hospitals, clinics, devices) and data consumers (applications, researchers). The system enables cross-silo data sharing while maintaining patient privacy through centralized permission management and audit trails, resolving the contradiction by mediating between privacy protection and information completeness

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If existing binary data permissioning protocols are used, then implementation is simple, but they fail to accommodate context-specific, requester-specific, and time-sensitive permissions

Engineering Contradiction:
Improvepermissioning implementation simplicityVSAvoidcontext-specific permission control
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The permissioning system is segmented into multiple independent rule tiers (laws/regulations, consent agreements, individual preferences) that can be applied hierarchically. Each tier addresses specific aspects of data sharing, allowing the system to accommodate diverse permission requirements without requiring complete redesign of the entire permissioning framework

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The permissioning system transitions from static binary permissions to dynamic, multi-dimensional rules that can change based on context, requester identity, and time. Rules can be added, modified, or removed independently, allowing the system to adapt to evolving privacy requirements while maintaining operational simplicity through automated rule evaluation

Inventive Principle:
Principle #15Dynamics

3Productivity

If data are shared across multiple organizations, then data utilization is optimized, but manual oversight and paperwork increase significantly

Engineering Contradiction:
Improvedata utilization efficiencyVSAvoidmanual oversight and paperwork
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system implements automated permission evaluation and enforcement mechanisms that independently assess data sharing requests against defined rules without requiring manual intervention. The automated audit trails and compliance checks perform oversight functions that would otherwise require significant manual administrative effort, enabling efficient data utilization across organizations

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If different organizations use different ontologies for data storage, then each organization maintains its data structure, but translation into commonly-understood format becomes difficult

Engineering Contradiction:
Improvedata structure flexibilityVSAvoidontology translation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal data exchange framework that can handle multiple ontologies and data formats simultaneously. By defining standardized data schemas and mapping mechanisms at the system level, it enables organizations to maintain their native data structures while facilitating seamless translation and integration when data is exchanged, reducing the complexity of individual organization systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10846424B2Method for multi-tiered, rule-based data sharing and ontology mapping
Publication Date: 2020.11.24 MEDIDATA SOLUTIONS INC
  • US10846424B2 patent drawing
  • US10846424B2 patent drawing
  • US10846424B2 patent drawing

AI summary

A computer-based method for creating enforced, context-specific sharing of ontologically mapped, aggregated medical data includes storing at least one data field in a database as an entity type ontology, receiving context-specific rule configurations corresponding to the entity type ontology, and identifying any conflict between the received context-specific rule and any applicable rule. The context-specific rule configurations include at least one context, one data source, and one entity type ontology data field. If a conflict is identified, the method receives resolution of the conflict and stores the context-specific rule configurations in the database.