Privacy Manager for Workflow Data Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current business process management systems lack an effective method to integrate and enforce data-handling policies within workflow models, leading to potential data misuse and inconsistencies across tasks and services in business processes.
Innovation Solution
A system and method that incorporates a privacy manager module within a workflow editor to create, manage, and enforce data-handling policies, including input and output consumption policies, and performs consistency checks to ensure compliance across tasks and data objects, utilizing XML files and Service Level Agreements to define and store these policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data-handling policies are integrated into workflow models, then data security and compliance are improved, but system complexity increases
Solution Approach 1:
The patent embeds data-handling policy definitions directly within workflow model structures, nesting policy constraints inside task and data object definitions. This allows policies to be integrated at the appropriate level of abstraction without creating separate complex policy management systems, thereby improving data security while controlling system complexity.
Solution Approach 2:
The patent divides data-handling policies into discrete, manageable components that can be applied to specific tasks and data objects individually. This segmentation allows policies to be enforced locally at each workflow element rather than requiring a monolithic policy management system, improving security enforcement while reducing overall system complexity.
2Reliability
If consistency checks are performed on data-handling policies, then policy compliance is improved, but processing time increases
Solution Approach 1:
The patent performs consistency checks on data-handling policies during the workflow model authoring and validation phases, before the workflow is executed. This preliminary validation ensures policy compliance is established upfront, avoiding the need for time-consuming checks during actual workflow execution, thus improving compliance while minimizing processing time loss.
3Object-affected harmful factors
If data-handling policies are enforced at task level, then data misuse prevention is improved, but workflow complexity increases
Solution Approach 1:
The patent applies data-handling policies locally to individual tasks and data objects based on their specific requirements. Each task can have customized policy constraints tailored to its data access needs, providing precise control over data usage while avoiding the imposition of unnecessary complexity on the entire workflow system. This localized approach prevents data misuse effectively while maintaining workflow simplicity.
Data Source
AI summary
A method and system for integrating data-handling policies into a computer-implemented workflow model is provided. In one embodiment, a workflow editor implemented using one or more processors may include a privacy manager module configured to permit a business process designer to integrate data handling policies into a workflow model. A privacy manager module, or simply a privacy manager, may also be configured to execute a consistency check with respect to newly-created and existing data handling policies to determine whether there is a conflict among any of the data-handling policies associated with tasks and data objects of the workflow model.


