Role-Based Search System for Automated Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems require manual intervention by IT staff to grant access to protected information, leading to inefficiencies and delays in accessing authorized data, especially in backup storage systems.

Innovation Solution

A role-based automated method for accessing information in data storage, which analyzes access rules and sends permission requests to authorizers, allowing users to access objects without manual IT assistance, using a data storage controller that retrieves and presents authorized data based on dynamic access rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual access requests to IT staff are required for protected information, then security control is maintained, but access time and user efficiency deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables users to self-serve by automatically analyzing their own access requests against stored access rules. The data storage controller autonomously determines whether to grant access without requiring manual intervention from IT staff, thus maintaining security control while dramatically reducing access time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Access rules are pre-stored in the data storage controller, allowing the system to evaluate access requests immediately against established criteria. This preliminary preparation of access policies enables rapid automated decision-making, eliminating the need for time-consuming manual approvals while maintaining security standards.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If manual IT staff intervention is required for access requests, then detailed access control is possible, but system complexity and operational overhead increase

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The manual mechanical process of IT staff reviewing and approving access requests is replaced by an automated electronic system. The data storage controller uses programmed logic to automatically analyze access requests against stored rules, substituting human intervention with machine-based automated decision-making, thereby reducing operational overhead while maintaining flexible access control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system introduces an intermediary automated access analysis mechanism between the user and the protected information. Instead of direct manual intervention, the data storage controller acts as an intermediary that automatically evaluates access requests against pre-stored rules, simplifying the overall system architecture by removing the need for human-in-the-loop processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If all users are given access to backup databases, then user freedom and productivity improve, but security risks increase without proper access rules

Engineering Contradiction:
Improveuser efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system applies differentiated access rules to different users, objects, or data types within the backup database. Instead of a blanket security approach, the data storage controller evaluates each access request individually against specific access rules that may vary by user role, data sensitivity, or object type, enabling broad user access where appropriate while maintaining security for sensitive information.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The access control system is dynamic rather than static, automatically adapting its decisions based on the specific characteristics of each access request and the corresponding access rules. The data storage controller can dynamically grant or deny access in real-time based on pre-established criteria, allowing user freedom to flourish within securely defined boundaries without requiring manual security reviews.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9202069B2Role based search
Publication Date: 2015.12.01 EFOLDER INC
  • US9202069B2 patent drawing
  • US9202069B2 patent drawing
  • US9202069B2 patent drawing

AI summary

The disclosure relates to accessing information, and more specifically to accessing information wherein the information is protected by access rules. In particular, the invention relates to a search system comprising integrated access request routines. The disclosure also relates to a search system and to a corresponding computer program.