Read Access Logging via Metadata Tracing and Structured Archiving

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current read access logging solutions are costly and inefficient, particularly when dealing with sensitive data across multiple applications, as they often require manual configuration and lack standardized mechanisms, leading to increased total cost of ownership and inadequate data protection.

Innovation Solution

A system and method for enabling read access logging that includes determining requirements for logging, saving log data in a fast read log file, processing it into a structured format, and auditing the logs, ensuring compliance with data protection regulations by logging only exposed data and providing tools for evaluation and deletion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If read access logging is implemented across multiple applications using local solutions, then data protection and privacy requirements are met, but total cost of ownership increases and configuration becomes costly and time consuming

Engineering Contradiction:
Improvedata protectionVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal logging mechanism that can be applied across multiple applications and domains. The system provides a standardized interface and common infrastructure that works consistently across different applications, eliminating the need for separate local solutions in each application. This multi-functional approach allows the same logging infrastructure to serve various applications while maintaining data protection requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the logging functionality into distinct modular components including logging agents, collection services, and processing modules. This segmentation allows the logging system to be implemented incrementally across different applications and domains while maintaining consistency. Each component can be independently configured and deployed, reducing overall configuration complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If logging is performed at the time of data replication to systems or frontends without adequate logging mechanisms, then data protection is ensured, but additional processing overhead and complexity are introduced

Engineering Contradiction:
Improvedata protectionVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by establishing logging capabilities in advance at data sources and replication points. Rather than adding logging at the last moment when data reaches systems without logging mechanisms, the system pre-configures logging agents and collection points upstream in the data flow. This allows logging to occur naturally during data replication without requiring additional processing steps at downstream systems.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If all accessed data is logged to ensure comprehensive monitoring, then complete audit trail is achieved, but storage requirements and processing time increase

Engineering Contradiction:
Improveaudit completenessVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent applies local quality by differentiating logging requirements based on data sensitivity and access context. Rather than uniformly logging all data accesses, the system selectively applies logging to specific data elements, domains, and user contexts that require monitoring. This targeted approach maintains complete audit trails for sensitive information while reducing unnecessary logging of non-critical data, thereby optimizing storage and processing requirements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8788533B2Read access logging
Publication Date: 2014.07.22 SAP SE
  • US8788533B2 patent drawing
  • US8788533B2 patent drawing
  • US8788533B2 patent drawing

AI summary

Read access logging is performed by tracing data accesses in all domains. The logged data is traced on metadata level with some additions identifying the exposed data records. All data relevant for read access logging is stored at first in a temporary log, which is later processed, structured, and archived.