Rule-Based Access to Volunteered Data in Protected Storage Regions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access to private data stored on public data storage systems is limited to either full access or no access, lacking a middle ground that allows controlled and secure access based on security and privacy constraints.

Innovation Solution

The system enables rule-based access to voluntarily provided data stored in a protected region of a data storage device, allowing data volunteers to set security and privacy constraint information (SPCI) that determines access based on attributes of incoming requests, ensuring controlled and secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If full access to private data is allowed on public data storage systems, then data sharing and accessibility are improved, but security and privacy protection deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity and privacy protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments access rights by dividing data into different sensitivity levels and assigning different access permissions to different user roles. This allows the system to provide full access to some data while restricting access to sensitive data, thereby improving overall data accessibility without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security measures to different portions of data based on their sensitivity. Public data receives minimal security restrictions while private data receives enhanced protection. This local differentiation allows the system to maximize accessibility for non-sensitive data while maintaining strong security for sensitive data.

Inventive Principle:
Principle #3Local quality

2Reliability

If no access to private data is allowed on public data storage systems, then security and privacy protection are improved, but data sharing and accessibility deteriorate

Engineering Contradiction:
Improvesecurity and privacy protectionVSAvoiddata sharing
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where permissions can change based on context, user identity, and data sensitivity. This allows the system to provide broad access to non-sensitive data while maintaining strict protection for sensitive data, achieving both security and data sharing goals simultaneously.

Inventive Principle:
Principle #15Dynamics

3Reliability

If rule-based access control is implemented, then controlled and secure access is improved, but system complexity increases

Engineering Contradiction:
Improvecontrolled accessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements partial rule-based control by applying detailed access rules only to sensitive data portions while using simpler access mechanisms for non-sensitive data. This selective approach provides controlled access where needed while avoiding unnecessary complexity elsewhere in the system.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12238115B2Rule based access to voluntarily provided data housed in a protected region of a data storage device
Publication Date: 2025.02.25 WORKDAY INC
  • US12238115B2 patent drawing
  • US12238115B2 patent drawing
  • US12238115B2 patent drawing

AI summary

Structured access to volunteered private data disclosed. Access can be based on security and privacy constraint information (SPCI) that can be selected by the party volunteering the private data. The volunteered data can be stored in a protected portion of a public network. The SPCI can be correlated to the volunteered data. In response to receiving a request for access to the volunteered data, an attribute of the request can be determined to satisfy one or more rules related to the SPCI prior to facilitating access to a version of a portion of the volunteered data. The version of the portion of the volunteered data can be a redaction of the portion of the volunteered data. The version of the portion of the volunteered data can be aggregated with other portions of other volunteered data determined to satisfy corresponding SPCI related rules.