Shared Infrastructure Access Control for Secure Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data security approaches in shared infrastructures are inadequate for maintaining security and compliance due to increased collaboration, leading to inefficiencies and vulnerabilities in data transmission among multiple entities with different access requirements.
Innovation Solution
Implement a computing system that determines access levels and permissions for clients, selectively transmits and replicates data based on security levels, and applies encryption and caching strategies to ensure secure and efficient data exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical barriers and separate infrastructures are used to store and control access to data by each entity, then data security is improved, but transmission efficiency and productivity deteriorate due to latencies and increased infrastructural requirements
Solution Approach 1:
The patent segments data into different security zones within the shared infrastructure, allowing data to be stored centrally while access controls segment permissions by entity. This enables efficient transmission within zones while maintaining security boundaries, resolving the contradiction between centralized efficiency and security isolation.
Solution Approach 2:
The patent introduces an intermediary access control layer that mediates between the shared infrastructure and individual entities. This intermediary enforces security policies without requiring physical barriers, maintaining transmission efficiency while ensuring security through virtual enforcement mechanisms.
2Reliability
If physical barriers and isolated infrastructures are used for each entity, then data security is improved, but the ability to adapt to latest security threats deteriorates due to limited awareness
Solution Approach 1:
The patent creates a universal shared infrastructure that serves multiple entities simultaneously while maintaining individual security policies. This universal system can rapidly adapt to new threats and apply updates across all entities, eliminating the limited awareness problem of isolated infrastructures while maintaining security through centralized policy management.
Solution Approach 2:
The patent implements feedback mechanisms where the shared infrastructure monitors security threats and automatically adjusts access controls and security policies for all entities. This continuous feedback loop enables rapid adaptation to emerging threats while maintaining security, something isolated infrastructures cannot achieve independently.
3Reliability
If selective replication based on security levels is implemented, then unauthorized transmission is prevented, but system complexity increases due to security level verification
Solution Approach 1:
The patent assigns security levels to data and entities in advance, creating a preliminary classification system. When replication is requested, the system simply verifies pre-established security level compatibility rather than performing complex real-time analysis, reducing operational complexity while maintaining strong unauthorized transmission prevention.
Data Source
AI summary
Systems and methods are provided for obtaining a request for a data object or a data structure from a client; determining an access level of the client and one or more access permissions of the requested data object or data structure; determining whether to transmit the requested data object or data structure to the client based on the access level of the client and the one or more access permissions; and transmitting the requested data object or data structure to the client.


