Node Graph Access Control for Private Data Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems face challenges in organizing access permissions for data objects, particularly when a specific number of users needs to access private data objects, and allowing additional users to access private data objects without compromising security and privacy is difficult.

Innovation Solution

The system utilizes a node graph to allow users to request access to private data objects based on mutual associations, enabling users to access data objects authorized by their neighboring nodes, thereby expanding access opportunities while maintaining security and privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizers grant explicit access to private data objects only to users they are associated with, then security and privacy are maintained, but the number of users who can access the data objects is limited

Engineering Contradiction:
Improvesecurity and privacyVSAvoidaccess opportunities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an approval process as an intermediary mechanism between users and private data objects. When a user requests access to a private data object, the request is routed through the organizer who can approve or deny it. This intermediary approval process allows the system to maintain security (by requiring organizer consent) while simultaneously expanding access opportunities (by allowing users beyond direct associations to request access). The node graph structure further mediates by identifying which users have neighboring node associations, enabling them to submit requests.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the system allows every user on the network to view and access private data objects, then access opportunities are maximized, but security and privacy risks increase

Engineering Contradiction:
Improveaccess opportunitiesVSAvoidsecurity and privacy risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a partial action approach by allowing only certain users (those with neighboring node associations) to request access to private data objects, rather than allowing all users on the network. This partial opening of access opportunities increases versatility while maintaining security controls. The system takes an excessive action in terms of request availability (any neighboring user can request) but compensates with a filtering mechanism (organizer approval required), thus achieving a balanced state that addresses both access opportunities and security risks.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If conventional one-to-one or group-to-group permission granting is used, then security control is maintained, but the complexity of organizing access permissions increases when specific numbers of users are required

Engineering Contradiction:
Improvesecurity controlVSAvoidpermission organization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables a self-service mechanism where users can autonomously request access to private data objects by interacting with actionable objects in the user interface. The system automatically identifies eligible users through the node graph structure and presents appropriate requests. This self-service approach reduces the organizational complexity for administrators, as the system automatically manages the request workflow, notification delivery, and approval tracking, while maintaining security control through the organizer approval requirement.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240095262A1Systems and methods for controlling and modifying access permissions for private data objects
Publication Date: 2024.03.21 DK CROWN HOLDINGS INC
  • US20240095262A1 patent drawing
  • US20240095262A1 patent drawing
  • US20240095262A1 patent drawing

AI summary

The present disclosure provides systems and methods for modifying and controlling access to private data objects. A system can maintain a node graph comprising nodes that each maintains an association with one or more neighbor nodes. The system can maintain private data objects that are generated based on a request from an organizer node, and include a list of authorized nodes and a setting to enable neighbors of authorized nodes to request inclusion in the list of authorized nodes. The system can receive a request for private data objects from a first node, and identify private data objects that include one or more neighbor nodes of the first node. The system can present a list of private data objects to the first node, and add the first node to the list of authorized nodes of the private data object subsequent to receiving a request from the first node.