Ontology-Based Mapping for Data Protection Interoperability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern healthcare infrastructure faces challenges in ensuring interoperability between decentralized data protection systems, particularly between access control and digital rights management systems, which are essential for secure sharing of sensitive health data in a decentralized environment.
Innovation Solution
A system utilizing an ontology to store definitions of concepts related to interface elements of different data protection systems and a mapping generator to dynamically generate mappings between these elements, enabling flexible interoperability without pre-programmed mappings, and supporting multiple digital rights management standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional centralized access control systems are used, then security protection is provided, but interoperability with decentralized data protection systems is limited
Solution Approach 1:
The patent introduces a broker as an intermediary component that mediates between the centralized access control system and decentralized DRM systems. The broker contains multiple adapters that translate and map interface elements between different security domains, enabling interoperability while maintaining the security guarantees of each individual system.
Solution Approach 2:
The broker is designed as a universal intermediary that can handle multiple different data protection systems simultaneously. It provides multi-functional capability by supporting both access control systems and various DRM standards through its adapter architecture, allowing a single component to serve multiple interoperability needs.
2Adaptability or versatility
If pre-programmed mappings are used between systems, then interoperability is established, but flexibility to handle new concepts is reduced
Solution Approach 1:
The mapping mechanism is designed to be dynamic rather than static. The broker can automatically generate and update mappings between interface elements based on runtime information about the connected systems. This allows the system to adapt to new DRM standards and access control systems without requiring manual reconfiguration or pre-programming of all possible mappings.
Solution Approach 2:
The broker performs self-configuration by automatically discovering the interface elements of connected systems and generating appropriate mappings. Instead of requiring external manual configuration for each new system integration, the broker autonomously adapts to new systems by analyzing their interface definitions and creating the necessary translation rules.
3Manufacturing precision
If manual mapping configuration is performed, then precise control over mappings is achieved, but time consumption and complexity increase
Solution Approach 1:
The system performs preliminary actions by pre-defining adapter templates and common mapping patterns for known DRM standards and access control systems. When a new system connection is established, the broker can quickly instantiate these pre-prepared adapters and mappings, significantly reducing configuration time while maintaining accuracy through the structured template-based approach.
Data Source
AI summary
A system is disclosed for providing interoperability between a plurality of data protection systems. The system includes an ontology (3) configured to store definitions (12) of concepts (4) relating to interface elements of at least two different data protection systems including a first data protection system (1) and a second data protection system (2); and a mapping generator (5) configured to generate a mapping between at least one interface element of the first data protection system (1) and at least one interface element of the second data protection system (2), based on the ontology (3). The system comprises a message converter (16) configured to receive a message generated by the first data protection system (1), convert the message based on the mapping to obtain a converted message, and transmit the converted message to the second data protection system (2).


