Role-Based Data Visualization for Secure IT Service Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current service management tools for IT systems lack secure real-time data visualization capabilities, as sensitive data visualizations are not effectively restricted to authorized users, posing a risk of unauthorized access.

Innovation Solution

A method and device that utilize a role-based access control system to create data visualizations specific to user roles, excluding sensitive data elements from visualization if they do not match the user's assigned role, and present these visualizations through a graphical user interface, optionally notifying users via secure messaging.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If data visualization is provided to all users of the IT system, then users can understand data sets visually and make business decisions, but sensitive data may be exposed to unauthorized users

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by customizing data visualization content according to user roles. Different users receive different subsets of visualized data based on their authorization levels. The system identifies sensitive data elements and restricts their visualization to only those users with appropriate role-based access permissions, while allowing other users to visualize non-sensitive data.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If role-based access control is implemented to restrict sensitive data, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that acts as a mediator between the data source and the visualization interface. This intermediary layer automatically applies role-based access control rules to filter and selectively visualize data elements. The system includes a role identification module and a data filtering mechanism that work together to enforce security policies without requiring complex manual intervention or system reconfiguration.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If sensitive data elements are excluded from visualization, then unauthorized access is prevented, but users lose comprehensive view of IT service status

Engineering Contradiction:
Improveunauthorized data accessVSAvoidcomprehensive data view
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent implements dynamic data visualization where the set of visualized data elements changes based on the logged-in user's role. The system dynamically determines which data elements to include or exclude from visualization based on real-time user authentication and role assignment. This allows each user to receive a comprehensive view of IT service status appropriate to their security clearance level, rather than a static fixed set of visualizations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11509553B2Methods and devices for providing real-time data visualization of IT-based business services
Publication Date: 2022.11.22 ATOS FRANCE
  • US11509553B2 patent drawing

AI summary

The invention relates a method and a device for providing real-time data visualization indicative of statuses of one or more monitored services of an information technology, IT, system, the one or more monitored services being represented in a service management model that manages several service providers as a single data source, the IT system including a role-based access control system for allowing users access to the IT system, the method comprising:associating the single data source with the role-base access control system, such that one or more roles are assigned to each data element of the single data source,periodically requesting, from the single data source, one or more data elements indicative of statuses of said monitored services, andcreating one or more data visualizations of the one or more data elements for a given user of the IT system, according to one or more rules.