Protected Search Aggregation for Cross-Department Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional access control methods are inadequate when collaborating across segregated organizations or departments, as they often require separate accounts and meticulous management, especially when sensitive data is involved, and do not effectively limit exposure of confidential information.
Innovation Solution
A computing system that allows users to perform searches on restricted data stores using a system account authorized to access the data, aggregates search results by category, and presents summarized information to users without revealing sensitive details, thereby controlling information exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional access control methods are used to restrict data access to authorized users only, then data security is improved, but collaboration across segregated organizations or departments becomes difficult and requires separate accounts and meticulous management
Solution Approach 1:
The patent segments the search results into different categories (e.g., public information, confidential information, highly confidential information) based on sensitivity levels. This allows the system to provide differentiated access control at the result level rather than requiring separate accounts for different data stores, thus maintaining security while improving collaboration ease
Solution Approach 2:
The patent introduces an intermediary system (the search system with aggregation functionality) that mediates between users and segregated data stores. The system performs searches across multiple data stores using appropriate credentials, then filters and aggregates results to remove or mask sensitive information before presenting it to users, eliminating the need for users to have direct access to multiple secured data stores
2Ease of operation
If users are granted access to multiple data stores to enable collaboration, then collaboration ease is improved, but exposure of confidential information increases
Solution Approach 1:
The patent extracts sensitive information from search results before presenting them to users. The system identifies confidential and highly confidential information in the search results and removes or masks these elements, leaving only public or appropriately classified information visible to users. This extraction process eliminates information exposure risks while maintaining collaboration ease
Solution Approach 2:
The patent applies different quality levels (visibility) to different portions of search results based on their sensitivity classification. Public information is fully visible, confidential information is partially visible or masked, and highly confidential information is completely removed. This local quality differentiation allows comprehensive search capabilities while protecting sensitive information
3Reliability
If separate accounts are created for users to access different segregated data stores, then data security is maintained, but device complexity and management overhead increase
Solution Approach 1:
The patent implements a universal search system that can access multiple segregated data stores through a single interface and single user account. The system handles credential management, authentication, and authorization internally, allowing users to search across all data stores without needing separate accounts. This multi-functionality maintains data security through proper credential usage while eliminating account management complexity
Data Source
AI summary
Systems and methods are provided for protected search. A search query to be performed using at least one data store is received from a computing device of a user. The user is not authorized to access the at least one data store. One or more search results that are responsive to the search query from the at least one data store are determined. The one or more search results are aggregated based on one or more categories. At least a subset of the aggregated search results is provided to the computing device of the user.


