Selective Data Sharing via Bitmap Index and Rights Definitions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data sharing systems often rely on an 'all-or-nothing' approach, making it difficult to selectively share data due to privacy concerns and technological incompatibilities, limiting the ability to gain a comprehensive understanding of users across different platforms.

Innovation Solution

The implementation of a bitmap index that allows for selective data sharing by storing metadata name-value pairs, enabling real-time computation of queries and granting access to specific data portions based on data rights definitions, allowing for granular control over data access and sharing across network-attached storage nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If all data is shared across platforms, then a complete understanding of users can be achieved, but privacy concerns and security risks increase

Engineering Contradiction:
Improvecompleteness of user understandingVSAvoidprivacy concerns and security risks
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into different portions with different access rights. Each data portion can be selectively shared with different entities based on predefined data rights definitions. This allows the system to provide a complete understanding of users through aggregated data while maintaining privacy by controlling access to individual data portions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning different access permissions to different portions of data. Each data portion can have its own access control policy, allowing specific entities to access only the data portions they are authorized to view. This resolves the contradiction by enabling selective sharing that maintains both completeness and privacy.

Inventive Principle:
Principle #3Local quality

2Reliability

If data is duplicated to a new data structure for sharing, then access control can be implemented, but storage efficiency decreases and resource consumption increases

Engineering Contradiction:
Improveaccess control capabilityVSAvoiddata storage efficiency
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Instead of duplicating entire data structures, the patent segments data access rights into manageable portions. Each data portion maintains its original storage location while access control is implemented through metadata associations. This eliminates the need for data duplication while maintaining reliable access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of data rights definitions and metadata that mediate between the stored data and access requests. This intermediary layer provides access control without requiring physical data duplication, thus maintaining storage efficiency while ensuring reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If selective data sharing is implemented, then privacy is protected and granular control is achieved, but system complexity increases

Engineering Contradiction:
Improvegranular data sharing controlVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining data rights definitions and associating them with data portions before access requests are made. This preparation work is done in advance, so when access requests occur, the system can quickly evaluate them against the pre-established rules without complex real-time decision-making, thus reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by automatically evaluating access requests against predefined data rights definitions without requiring manual intervention. The metadata and access control logic are embedded in the system, enabling automatic enforcement of granular data sharing policies while minimizing the complexity of manual management.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If data access requests are processed individually, then access control precision is maintained, but processing time increases

Engineering Contradiction:
Improveaccess control precisionVSAvoiddata access processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent uses preliminary action by pre-evaluating and caching access control decisions based on predefined data rights definitions. When similar access requests are made, the system can retrieve pre-computed results rather than re-evaluating from scratch, thus maintaining precise access control while reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuity of useful action by keeping access control rules and data rights definitions continuously available and readily accessible. This allows the system to process access requests efficiently by continuously referencing the pre-established rules without interruption or repeated setup, balancing precision with speed.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11425136B2Systems and methods of managing data rights and selective data sharing
Publication Date: 2022.08.23 CIRCUIT HOLDINGS INC
  • US11425136B2 patent drawing
  • US11425136B2 patent drawing
  • US11425136B2 patent drawing

AI summary

A method includes receiving an access request at a first computing device from a second computing device, the access request specifying a data structure, the data structure including first data stored in a first portion of the data structure and second data stored in a second portion of the data structure. The method also includes extracting a first key from the access request and identifying a data rights definition that is associated with the data structure and that is associated with a second key, the data rights definition indicating that the first data but not the second data is shared with an entity associated with the second computing device. The method further includes comparing the first key to the second key, and, based on the comparison, determining whether to grant the second computing device access to the first data but not the second data.