Progressive Data Access Control via Capacity-Based Delegation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods to manage access and control of sensitive data, particularly in healthcare, which can lead to unintentional disclosure and misuse of private information.

Innovation Solution

A data management system that vests control over access to sensitive data in the individual it pertains to, progressively delegating control to designated devices and individuals based on the individual's capacity to authorize access, using a multi-tiered consent resolution process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control is centralized without progressive delegation, then data security is improved, but system complexity and difficulty of operation increase

Engineering Contradiction:
Improvedata securityVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control system is segmented into multiple hierarchical levels: individual-level control, designee-level control, and provider-level control. Each level can independently authorize access based on their capacity, dividing the monolithic access control function into manageable segments that reduce system complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts the level of control delegation based on the individual's demonstrated capacity to make authorized access decisions. As capacity is verified, control progressively shifts from centralized individual authorization to distributed delegation to designees and providers, making the system adaptable rather than static.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If progressive delegation of control is implemented, then ease of operation is improved, but risk of unauthorized access increases

Engineering Contradiction:
Improvedata access managementVSAvoidunauthorized disclosure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of an individual's capacity to authorize access before delegating control to designees or providers. This preliminary assessment ensures that only individuals who have demonstrated appropriate judgment and capacity can have their access decisions respected, preventing premature delegation to unauthorized parties.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors and evaluates the capacity of individuals to make authorized access decisions, using this feedback to dynamically adjust the level of delegation. If capacity is insufficient or compromised, the system reverses delegation back to the individual, providing continuous feedback-based risk management.

Inventive Principle:
Principle #23Feedback

3Reliability

If multi-tiered consent resolution is used, then data security is improved, but time required for access resolution increases

Engineering Contradiction:
Improveauthorization securityVSAvoidaccess resolution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements partial delegation where only the necessary level of control is transferred to designees or providers based on the individual's capacity. This avoids the excessive time cost of consulting all possible authorities while maintaining adequate security through appropriately scoped delegation.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The consent resolution process is dynamic, adapting the number and type of tiers consulted based on the individual's verified capacity. For individuals with high capacity, direct authorization is sufficient; for those with lower capacity, progressive delegation to designees and providers is activated, optimizing the balance between security and time efficiency.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12339994B2System and method for managing access control of sensitive data
Publication Date: 2025.06.24 DELL PROD LP
  • US12339994B2 patent drawing
  • US12339994B2 patent drawing
  • US12339994B2 patent drawing

AI summary

Methods and systems for managing access and control of data are disclosed. To manage access and control, data management system may require registration and verification of devices associated with an individual or other individuals to which control over access may be granted. Data management system may vest control over access to data to the device associated with the individual for which data is stored and progressively vest control over access to data to other devices associated with other individuals as an increasing amount of information indicating the lack of capacity of the individual to authorize access to data.