Purpose-Based Data Access Workspaces for Auditable Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer systems inadequately protect and audit access to electronic data assets, particularly private or confidential data, and are inefficient in managing large-scale changes to authentication and authorization permissions.
Innovation Solution
Implement a purpose-based access system that integrates governance metadata using data objects, providing structured access control frameworks, logging user access purposes, and generating investigation workspaces with precise data subsets for authorized purposes, along with interactive user interfaces for guided data discovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication credentials and authorization restrictions are used to protect electronic data assets, then data security is improved, but administrative efficiency deteriorates due to large amounts of time, data, and memory required to manage permissions
Solution Approach 1:
The patent segments the monolithic permission management system into modular components: authentication credentials, authorization restrictions, and purpose-based access controls. Each component can be independently configured and managed, allowing administrators to implement large-scale changes to specific segments without affecting the entire system, thus improving administrative efficiency while maintaining security
Solution Approach 2:
The patent introduces purpose-based access controls as an intermediary layer between users and data assets. This intermediary mechanism provides structured governance metadata that automates permission propagation and tracking, reducing the manual administrative burden while enhancing security through purpose-specific access policies
2Manufacturing precision
If manual changes are made to each permission of each dataset to propagate large-scale changes, then access control precision is improved, but time consumption increases significantly
Solution Approach 1:
The patent implements preliminary action by pre-defining purpose-based access policies and governance metadata structures. When large-scale permission changes are needed, the system automatically propagates changes based on these pre-established rules, eliminating the need for manual permission-by-permission updates while maintaining precise access control
Solution Approach 2:
The system enables self-service permission propagation through automated governance metadata processing. The metadata structures automatically track and propagate permission changes across datasets without requiring manual intervention, reducing time consumption while preserving access control precision through systematic rule-based updates
3Ease of operation
If traditional authentication and authorization systems are used, then user access control is implemented, but auditability deteriorates due to inability to track why users access datasets
Solution Approach 1:
The patent implements feedback mechanisms through governance metadata that automatically logs and tracks purpose-based access information. This feedback system captures why users access datasets, providing comprehensive audit trails that enhance auditability while maintaining ease of user access control through the same metadata-driven framework
4Reliability
If authentication credentials are required for data access, then data protection is improved, but ease of access deteriorates due to additional authentication steps
Solution Approach 1:
The patent implements purpose-based access controls that serve multiple functions simultaneously: they authenticate users, authorize access, and log audit information through a unified governance metadata framework. This multi-functional approach maintains data protection while improving ease of access by eliminating redundant authentication steps and providing a streamlined access control mechanism
Data Source
AI summary
An explorer user interface allows users that are interested in making purpose-based access requests to datasets to view aggregated and/or summary data regarding available datasets prior to making the purpose-based access request. A guided discovery wizard allows a user to view summarized and/or general information regarding datasets and may provide the user options to filter the datasets based on such information and/or based on parameters of specific data items within the datasets (without exposing the specific data items to the user). Thus, the user may filter the datasets to determine a cohort of datasets including data items that are interesting or useful for the specific purpose. The system may provide access to a subset of filtered datasets for the specific purpose in a self-contained, dedicated-purpose directory (an “investigation workspace”) that includes only the precise portion of data that is needed for the requested purpose.


