Data Access Control via Schedule-Based Owner Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In factories using the mixed flow production method, managing and securing access to data from sensors is challenging due to the diverse ownership of products and the need to restrict access to third parties, especially in environments where data is accumulated in data lakes containing structured and unstructured data.

Innovation Solution

A computer system generates access control information based on schedule information from production systems, including identification of owners and machines, to manage and control access to operation and environment data stored in a database, ensuring appropriate access periods and restricting access to unauthorized parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is accumulated in a data lake to improve data storage capacity and versatility, then data storage capability is improved, but data accessibility and security control deteriorate

Engineering Contradiction:
Improvedata storage capabilityVSAvoiddata accessibility
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the data lake into multiple isolated storage spaces, each dedicated to a specific orderer. This segmentation maintains the versatility of the data lake for storing diverse data types while improving accessibility control by allowing targeted access to specific orderer's data without exposing the entire data lake to unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a data catalog as an intermediary layer between the data lake and users. The data catalog stores metadata about data locations, owners, and access permissions, enabling controlled access to data in the data lake without compromising security. This intermediary mechanism resolves the contradiction by providing a managed access point that maintains both versatility and accessibility control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control restrictions are implemented to prevent unauthorized data access, then data security is improved, but data accessibility for authorized users deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-configuring access control policies and metadata in the data catalog before data access requests occur. Ownership information, access permissions, and data location metadata are established in advance, allowing authorized users to access data seamlessly without real-time security checks that would hinder accessibility, while maintaining strong security controls.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If detailed access control data is generated for each orderer to improve security, then data security is improved, but system complexity deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a unified data catalog structure and access control mechanism that serves all orderers in the mixed-flow production system. Rather than creating separate complex control systems for each orderer, a single multi-functional data catalog handles metadata storage, ownership tracking, and access control for all users, reducing overall system complexity while maintaining detailed security controls.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11681820B2Computer system and data access control method
Publication Date: 2023.06.20 HITACHI LTD
  • US11681820B2 patent drawing
  • US11681820B2 patent drawing
  • US11681820B2 patent drawing

AI summary

The computer system is connected to a DB that stores data acquired from a production system in which a plurality of machines operate, and includes a generation unit and a data search unit. The DB stores operation data and environment data. The generation unit generates, by analyzing schedule information including a production schedule of the plurality of products, first owner information for storing first access control data including an owner, the machines, and a first access period set based on operation time, and generates, based on the first owner information, second owner information for storing second access control data including the owner, a type of the environment data, and a second access period set based on the first access period. The data search unit controls accesses to the DB based on the first owner information and the second owner information.