Multilevel Security Process for Secured Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data security methods are cumbersome, with parallel paths, circuitous routings, delays, and frequent mistakes, making them inefficient for providing access to secured electronic data.
Innovation Solution
A multilevel security process that involves submitting access requests to controllers, comparing attributes with access requirements, and obtaining authorization from resolution authorities to grant or deny access to secured electronic data, ensuring transparent and efficient access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional data security techniques are used, then data security is improved, but system complexity and operational difficulty increase
Solution Approach 1:
The patent segments the data security system into distinct functional modules: data subjects are divided into multiple data subsets, each with its own access controller; access requirements are segmented into multiple levels (first security level for resources, second security level for data); and the authorization process is divided between controllers and resolution authorities. This segmentation reduces overall system complexity by creating manageable, independent components that can be administered separately.
Solution Approach 2:
The patent introduces intermediary entities to manage security operations: access controllers act as intermediaries between access candidates and secured data/resources, automatically comparing attributes and managing access requests; resolution authorities serve as intermediaries for handling authorization requests when access is prohibited. These intermediaries simplify the security management process by automating routine decisions and providing clear escalation paths for exceptional cases.
2Reliability
If traditional data security techniques are used, then data security is improved, but access time and efficiency deteriorate
Solution Approach 1:
The patent implements preliminary action by pre-establishing access requirements for each data subset and resource, defining citizenship requirements, location requirements, and data access agreements in advance. Access controllers are pre-configured with these requirements, enabling them to automatically evaluate access requests against predetermined criteria without requiring time-consuming manual review for each request. This preliminary setup significantly reduces access time while maintaining security.
Solution Approach 2:
The patent enables self-service through automated access control evaluation where controllers automatically compare access candidate attributes against access requirements and make access decisions without human intervention. The system self-manages the access request workflow, including automatic identification of prohibited access, generation of authorization requests to resolution authorities, and implementation of access decisions. This automation eliminates manual processing delays and frequent mistakes associated with traditional security techniques.
3Reliability
If traditional data security techniques are used, then data security is improved, but operational errors increase
Solution Approach 1:
The patent implements feedback mechanisms where access controllers continuously monitor and evaluate access requests against access requirements, providing automatic feedback on access eligibility. The system tracks access decisions and can generate reports on access patterns and authorization outcomes. This feedback loop ensures consistent application of security policies and enables detection and correction of potential errors, improving access control accuracy while maintaining security.
Data Source
AI summary
The present invention provides techniques for granting access to secured data. An access candidate may access some or all of the secured data by gaining access to two sequential levels of security. The first security level secures access to the resources used to manipulate the secured data and the second security level secures access to the secured data by the resources. Attributes associated with the access candidate are considered in deciding whether to grant or deny access to the resources. Based on a comparison of access requirements of the secured data with the applicable attributes of the access candidate, a decision on whether to grant access to the requested portions of the secured data is made. If access is not prohibited, the access candidate may use the resources to access the secured data. If access is prohibited without authorization, a resolution request may be submitted to a resolution authority.


