Selective Data Sharing via Bitmap Index and Rights Definitions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data sharing systems often rely on an 'all-or-nothing' approach, making it difficult to selectively share data due to privacy concerns and technological incompatibilities, limiting the ability to gain a comprehensive understanding of users across different platforms.
Innovation Solution
The implementation of a bitmap index that allows for selective data sharing by storing metadata name-value pairs, enabling real-time computation of queries and granting access to specific data portions based on data rights definitions, allowing for granular control over data access and sharing across network-attached storage nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If all data is shared across platforms, then a complete understanding of users can be achieved, but privacy concerns and security risks increase
Solution Approach 1:
The patent segments data into different portions with different access rights. Each data portion can be selectively shared with different entities based on predefined data rights definitions. This allows the system to provide a complete understanding of users through aggregated data while maintaining privacy by controlling access to individual data portions.
Solution Approach 2:
The patent implements local quality by assigning different access permissions to different portions of data. Each data portion can have its own access control policy, allowing specific entities to access only the data portions they are authorized to view. This resolves the contradiction by enabling selective sharing that maintains both completeness and privacy.
2Reliability
If data is duplicated to a new data structure for sharing, then access control can be implemented, but storage efficiency decreases and resource consumption increases
Solution Approach 1:
Instead of duplicating entire data structures, the patent segments data access rights into manageable portions. Each data portion maintains its original storage location while access control is implemented through metadata associations. This eliminates the need for data duplication while maintaining reliable access control.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of data rights definitions and metadata that mediate between the stored data and access requests. This intermediary layer provides access control without requiring physical data duplication, thus maintaining storage efficiency while ensuring reliability.
3Adaptability or versatility
If selective data sharing is implemented, then privacy is protected and granular control is achieved, but system complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-defining data rights definitions and associating them with data portions before access requests are made. This preparation work is done in advance, so when access requests occur, the system can quickly evaluate them against the pre-established rules without complex real-time decision-making, thus reducing operational complexity.
Solution Approach 2:
The system implements self-service by automatically evaluating access requests against predefined data rights definitions without requiring manual intervention. The metadata and access control logic are embedded in the system, enabling automatic enforcement of granular data sharing policies while minimizing the complexity of manual management.
4Measurement precision
If data access requests are processed individually, then access control precision is maintained, but processing time increases
Solution Approach 1:
The patent uses preliminary action by pre-evaluating and caching access control decisions based on predefined data rights definitions. When similar access requests are made, the system can retrieve pre-computed results rather than re-evaluating from scratch, thus maintaining precise access control while reducing processing time.
Solution Approach 2:
The system maintains continuity of useful action by keeping access control rules and data rights definitions continuously available and readily accessible. This allows the system to process access requests efficiently by continuously referencing the pre-established rules without interruption or repeated setup, balancing precision with speed.
Data Source
AI summary
A method includes receiving an access request at a first computing device from a second computing device, the access request specifying a data structure, the data structure including first data stored in a first portion of the data structure and second data stored in a second portion of the data structure. The method also includes extracting a first key from the access request and identifying a data rights definition that is associated with the data structure and that is associated with a second key, the data rights definition indicating that the first data but not the second data is shared with an entity associated with the second computing device. The method further includes comparing the first key to the second key, and, based on the comparison, determining whether to grant the second computing device access to the first data but not the second data.


