Protected Search Aggregation for Cross-Department Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control methods are inadequate when collaborating across segregated organizations or departments, as they often require separate accounts and meticulous management, especially when sensitive data is involved, and do not effectively limit exposure of confidential information.

Innovation Solution

A computing system that allows users to perform searches on restricted data stores using a system account authorized to access the data, aggregates search results by category, and presents summarized information to users without revealing sensitive details, thereby controlling information exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional access control methods are used to restrict data access to authorized users only, then data security is improved, but collaboration across segregated organizations or departments becomes difficult and requires separate accounts and meticulous management

Engineering Contradiction:
Improvedata securityVSAvoidcollaboration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the search results into different categories (e.g., public information, confidential information, highly confidential information) based on sensitivity levels. This allows the system to provide differentiated access control at the result level rather than requiring separate accounts for different data stores, thus maintaining security while improving collaboration ease

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary system (the search system with aggregation functionality) that mediates between users and segregated data stores. The system performs searches across multiple data stores using appropriate credentials, then filters and aggregates results to remove or mask sensitive information before presenting it to users, eliminating the need for users to have direct access to multiple secured data stores

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users are granted access to multiple data stores to enable collaboration, then collaboration ease is improved, but exposure of confidential information increases

Engineering Contradiction:
Improvecollaboration easeVSAvoidinformation exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive information from search results before presenting them to users. The system identifies confidential and highly confidential information in the search results and removes or masks these elements, leaving only public or appropriately classified information visible to users. This extraction process eliminates information exposure risks while maintaining collaboration ease

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different quality levels (visibility) to different portions of search results based on their sensitivity classification. Public information is fully visible, confidential information is partially visible or masked, and highly confidential information is completely removed. This local quality differentiation allows comprehensive search capabilities while protecting sensitive information

Inventive Principle:
Principle #3Local quality

3Reliability

If separate accounts are created for users to access different segregated data stores, then data security is maintained, but device complexity and management overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidaccount management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal search system that can access multiple segregated data stores through a single interface and single user account. The system handles credential management, authentication, and authorization internally, allowing users to search across all data stores without needing separate accounts. This multi-functionality maintains data security through proper credential usage while eliminating account management complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10599663B1Protected search
Publication Date: 2020.03.24 PALANTIR TECHNOLOGIES INC
  • US10599663B1 patent drawing
  • US10599663B1 patent drawing
  • US10599663B1 patent drawing

AI summary

Systems and methods are provided for protected search. A search query to be performed using at least one data store is received from a computing device of a user. The user is not authorized to access the at least one data store. One or more search results that are responsive to the search query from the at least one data store are determined. The one or more search results are aggregated based on one or more categories. At least a subset of the aggregated search results is provided to the computing device of the user.