Redacted Graph Collaboration for Fine-Grained Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems struggle to implement fine-grained data sharing and safeguarding between entities due to complex internal policies and the difficulty in categorizing information to share versus information to protect.
Innovation Solution
A method involving a series of redaction stages using access control classifications, provenance, data object types, and media types to identify and remove sensitive information from a graph before sharing, accompanied by a machine-readable representation of the redacted graph and audit data for approval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If categorical rules are used to distinguish information to share versus information to safeguard, then data sharing can be simplified, but the intricacies of complex internal policies create exceptions that make the rules inadequate
Solution Approach 1:
The patent segments data classification into multiple hierarchical levels: broad categories (e.g., personal information, financial data) down to fine-grained specific data elements. This segmentation allows categorical rules to operate effectively at each level while accommodating policy exceptions through the hierarchical structure, resolving the contradiction between simplification and compliance.
Solution Approach 2:
The system changes the parameter of data classification from static categorical labels to dynamic, multi-dimensional parameters including sensitivity level, sharing context, and policy constraints. This allows the same data element to have different sharing permissions based on contextual parameters, enabling both simplified rules and policy flexibility.
2Reliability
If fine-grained data classification is implemented to accommodate complex policies, then policy compliance improves, but the complexity of establishing and maintaining such classification increases
Solution Approach 1:
The patent implements a universal data classification framework that serves multiple functions simultaneously: policy compliance enforcement, automated redaction, access control, and audit tracking. This multi-functionality reduces the need for separate systems for each function, lowering overall complexity while maintaining fine-grained classification capabilities.
Solution Approach 2:
The system enables self-service through automated classification and redaction processes that operate without manual intervention. Data elements are automatically classified according to their inherent properties and contextual information, and redactions are automatically applied based on classification results, reducing the operational complexity of maintaining fine-grained classification.
3Productivity
If all data is shared to maximize collaboration, then data collaboration efficiency improves, but unauthorized or sensitive information may be exposed
Solution Approach 1:
The patent applies preliminary action by performing automated classification and redaction of data before it is shared between entities. Sensitive information is identified and removed in advance through automated processes, allowing data to be shared broadly for collaboration while pre-protecting against information security risks.
Solution Approach 2:
The system introduces an intermediary layer of automated classification and redaction processing between the data source and the sharing destination. This intermediary automatically filters sensitive information while permitting collaborative sharing of non-sensitive data, resolving the contradiction between collaboration efficiency and security.
4Manufacturing precision
If manual review processes are used to ensure data accuracy before sharing, then data quality improves, but the time and resources required for review increase
Solution Approach 1:
The patent replaces manual mechanical review processes with automated computational systems that use classification algorithms, pattern recognition, and rule-based engines to review and validate data accuracy. This substitution maintains high data accuracy standards while dramatically reducing the time and human resources required for review.
Data Source
AI summary
A method comprises importing a redacted graph, each node representing a data object, the redacted graph being redacted based on at least one access control classification, each edge representing one or more relationships between two data objects; assigning a new access control classification to the redacted graph independent of the at least one access control classification; determining that one or more nodes of the redacted graph represent one or more data objects stored on a local computing device; performing data deconfliction for the one or more data objects; updating the one or more nodes of the redacted graph to contain deconflicted data; identifying a portion of the redacted graph to be redacted for export based on one or more redaction criteria, including one related to the new access control classification; redacting the portion from the redacted graph to obtain an updated graph; exporting a machine-readable representation the updated graph.


