Semantic Access Control for Unstructured Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data storage systems lack effective methods for controlling access to unstructured and semi-structured data, relying solely on metadata, which limits access control and fails to recognize similarities in data content, leading to inefficiencies in data management and security.

Innovation Solution

The implementation of a system that uses relevancy data harvesting and semantic content analysis to define access policies, allowing for the identification of self-organizing patterns and relationships between files, enabling broader-reaching access control and security measures without relying on traditional metadata-based methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional metadata-based access control methods are used, then access control implementation is simple, but access control effectiveness is insufficient for unstructured and semi-structured data

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary semantic analysis and relevancy assessment of data files before access control decisions are made. By pre-processing data to extract semantic content and establish relevancy relationships, the system prepares access control parameters in advance, enabling more effective access control without increasing real-time complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces semantic content analysis and relevancy assessment as intermediary layers between the user and the data. These intermediaries evaluate the semantic relationship between requested data and previously accessed data, providing an additional control mechanism that enhances access control effectiveness beyond traditional metadata

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If semantic content analysis is implemented, then access control precision is improved, but processing time increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies semantic analysis selectively rather than universally. It focuses on assessing relevancy only for data files that may be related to previously accessed confidential information, rather than analyzing all data files. This partial application of semantic analysis maintains precision where needed while reducing overall processing time

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If traditional metadata criteria are used for access control, then data management is efficient, but semantic relationships between files are not recognized

Engineering Contradiction:
Improvedata relationship recognitionVSAvoiddata management efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent creates a universal access control framework that works with both traditional metadata and semantic content analysis. The system can handle structured data with predefined metadata as well as unstructured and semi-structured data through semantic relevancy assessment, making the access control mechanism versatile across different data types while maintaining management efficiency

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8782734B2Semantic controls on data storage and access
Publication Date: 2014.07.15 MICRO FOCUS SOFTWARE INC
  • US8782734B2 patent drawing
  • US8782734B2 patent drawing
  • US8782734B2 patent drawing

AI summary

Methods and apparatus teach defining an access policy to digital data available on one or more computing devices, including identifying one or more semantic attributes of at least one first digital data set and using the identified attributes to define policy dictating user access privileges. On receipt of a user request to access at least one second digital data set, semantic attributes are compared to the at least one first digital data set and access is allowed or not allowed based on the policy. Semantic attributes are selected from at least one of a closeness attribute, a relatedness attribute, and a semantic vector attribute. Also is taught configuring a policy enforcement agent on the one or more computing devices to undertake the comparing and to allow or not allow access. In turn, computer program products and computing systems for accomplishing the foregoing are provided.