Secure Data Warehouse Analytics via Access Gateway

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Retailers face challenges in securely extending access to their data warehouses for vendors due to concerns over competitive information and compliance with agreements, limiting potential collaborations and improvements that could benefit both parties.

Innovation Solution

A method for securely extending analytics within a data warehouse environment by associating authenticated users with vendor user groups, enabling limited access through a data store interface, and executing analysis modules with controlled access rights and anonymized results to protect sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If vendors are granted access to the data warehouse, then analytics capabilities and business insights are improved, but security risks and exposure of competitive information increase

Engineering Contradiction:
Improveanalytics capabilitiesVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a data warehouse access gateway as an intermediary component that sits between vendors and the data warehouse. This gateway enforces access controls, filters queries, and prevents direct access to sensitive tables and views, thereby enabling analytics capabilities while mitigating security risks and protecting competitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements differential access rights where different vendors are granted specific access permissions based on their needs and trust levels. Some vendors receive read-only access to certain views, while others may have more restricted access. This localized quality approach allows analytics capabilities to be improved for each vendor according to their specific requirements while maintaining security by restricting access to sensitive areas.

Inventive Principle:
Principle #3Local quality

2Reliability

If access to data warehouse is restricted, then competitive information is protected, but potential collaborations and improvements are lost

Engineering Contradiction:
Improvecompetitive confidentialityVSAvoidcollaboration benefits
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the data warehouse access into multiple layers: a public gateway layer for vendor access, intermediate view layers for different vendor groups, and private table layers for sensitive data. This segmentation allows competitive confidentiality to be maintained at the table level while enabling collaboration benefits at the view and gateway levels where vendors can perform analytics on non-sensitive data.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If full access is provided to vendors, then analytics utility is maximized, but compliance with non-compete agreements is compromised

Engineering Contradiction:
Improveanalytics utilityVSAvoidcompliance violations
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The access gateway serves as a compliance mediator that monitors and controls vendor queries to ensure they do not access data covered by non-compete agreements. The gateway can block specific queries, log access patterns for audit purposes, and enforce compliance policies while still allowing vendors to utilize analytics utilities on permitted data through controlled views.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9652542B2Securely extending analytics within a data warehouse environment
Publication Date: 2017.05.16 TERADATA US INC
  • US9652542B2 patent drawing
  • US9652542B2 patent drawing
  • US9652542B2 patent drawing

AI summary

A vendor is authenticated for use of a retailer's data warehouse and limited access rights are assigned to the vendor for access. The vendor accesses a graphical user interface (GUI) to select an available analysis module for execution against the data warehouse. Schemas are presented in the GUI based on the access rights, and specific schema selections are made by the vendor. The analysis module is then configured and executed against the data warehouse and filtered results are presented to the vendor; the results filtered based on the access rights assigned to the vendor.