Semantic Domain Layer for Dynamic Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data visualization and reporting tools require significant IT involvement for dataset creation, limit self-service capabilities for business users, and lack dynamic user persona detection and data access control, leading to static permissions and limited integration and reusability of datasets.
Innovation Solution
A method and system utilizing a semantic domain layer to provide profile-based data access, where user profiles are mapped to domain objects with defined access levels, enabling selective data rendering and dynamic control of data access based on user personas, roles, and groups, thereby reducing IT dependency and enhancing data integration and reusability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If existing data visualization tools are used with static permission definitions, then data access control is simplified, but self-service capability and dynamic user persona detection are limited
Solution Approach 1:
The system enables business users to independently create datasets, define permissions, and generate visualizations without requiring IT team intervention. Users can directly access the data layer, configure their own data models, and publish datasets to external applications, transforming a previously IT-dependent process into a self-service capability.
Solution Approach 2:
The patent implements dynamic permission management where access levels, user personas, and data visibility are not statically defined but dynamically adjusted based on user roles, groups, and contextual factors. Permission definitions can be modified at runtime, and the system automatically detects and adapts to changing user requirements without requiring system reconfiguration.
2Adaptability or versatility
If final datasets are created within existing tools, then data visualization and querying are enabled, but integration and reusability outside the tools are limited
Solution Approach 1:
The system creates datasets with universal accessibility, allowing the same data models to be consumed by multiple different applications and tools simultaneously. Datasets published through the system can be accessed by internal visualization tools as well as external applications, eliminating the need to create separate datasets for different consumers and enabling broad reusability across the organization.
Solution Approach 2:
The patent introduces an intermediary data layer that sits between the data sources and various applications. This intermediary layer standardizes data access interfaces and manages permissions centrally, allowing multiple applications to consume data without direct integration complexity. The intermediary handles authentication, authorization, and data transformation, simplifying integration for both internal and external applications.
3Reliability
If data sources are accessed without masking and encryption, then data accessibility is improved, but security and trustworthiness are compromised
Solution Approach 1:
The system applies different security measures to different data elements based on their sensitivity and the user's permission level. Rather than uniformly masking or encrypting all data, the system selectively applies security measures only where necessary - for example, masking certain columns for specific users while leaving other data fully accessible. This localized approach maintains security for sensitive information while preserving ease of access for non-sensitive data.
Solution Approach 2:
The patent introduces a security intermediary layer that sits between data sources and users, automatically applying masking and encryption rules based on user permissions and data sensitivity. This intermediary handles security complexity transparently, so users experience simple data access while the intermediary ensures appropriate security measures are applied - masking sensitive columns, encrypting data in transit, and validating permissions - without users needing to understand or configure these security mechanisms.
Data Source
AI summary
A method and system for providing profile-based data and visualization access through a semantic domain layer is disclosed. In some embodiments, the method includes receiving a user request to access data. The method further includes determining a user profile from a plurality of user profiles associated with the user. The method further includes extracting a first access level from a first set of access levels associated with the user profile. The method further includes mapping the user profile with a domain object from a plurality of domain objects, based on a second access level from the first set of access levels associated with the domain object. The method further includes selectively rendering at least a portion of the data requested in the user request to the user, in response to mapping the user profile with the domain object.


