Universal Permissioning Tool for Tokenized Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies are inadequate in providing enhanced searchability and access control for tokenized data, leading to difficulties in maintaining 'zero-trust' and regulatory compliance, especially as employee permissions and roles change within organizations.
Innovation Solution
A method and system that utilize a Universal Permissioning Tool (UPT) to manage data access by analyzing access requests with machine learning models, identifying provenance keys, and retrieving access control information to determine access allowances, ensuring that data remains tokenized and encrypted unless specifically authorized for access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is tokenized to enhance security, then data breach risk is reduced, but searchability and accessibility of the data is lost
Solution Approach 1:
The patent introduces an intermediary decryption system that mediates between tokenized data storage and search requirements. The system decrypts data temporarily in controlled environments to enable search operations, then re-tokenizes results. This intermediary layer resolves the contradiction by allowing search functionality without permanently compromising data tokenization status.
Solution Approach 2:
The system performs preliminary decryption and indexing of tokenized data before actual search queries. By pre-processing and preparing searchable indices from decrypted data in advance, the system enables efficient search operations while maintaining the tokenized state of stored data, thus resolving the security-searchability contradiction.
2Ease of operation
If traditional access control methods are used, then data accessibility is improved, but compliance with zero-trust and regulatory requirements becomes difficult to maintain
Solution Approach 1:
The patent implements dynamic access control policies that automatically adjust permissions based on real-time contextual factors such as user roles, data sensitivity levels, and compliance requirements. This dynamic approach maintains data accessibility for authorized users while automatically ensuring compliance with zero-trust principles and regulatory requirements, resolving the contradiction between accessibility and compliance.
Solution Approach 2:
The system incorporates continuous feedback mechanisms that monitor access patterns, user permissions, and compliance status in real-time. When compliance risks are detected, the system automatically adjusts access controls and notifies relevant parties, ensuring that data accessibility is maintained while continuously meeting compliance requirements.
3Reliability
If permission databases are maintained across disparate systems, then data access control is improved, but maintenance complexity and coordination difficulty increase
Solution Approach 1:
The patent introduces a universal permission database architecture that serves multiple disparate systems through a common interface and standardized data models. This universal system handles access control for diverse data sources and destinations, eliminating the need for separate permission databases in each system and significantly reducing maintenance complexity while maintaining reliable access control across the entire data ecosystem.
Data Source
AI summary
The present disclosure provides a method of facilitating controlling access to data. Moreover, the method may include retrieving, using a storage device, an access control information associated with the data based on a provenance key. Accordingly, the method may include analyzing, using a processing device, the access control information and one or more permissions. Furthermore, the method may include determining, using the processing device, an access allowance associated with the data for an access request based on the analyzing of the access control information and the one or more permissions. Moreover, the method may include transmitting, using a communication device, at least a portion of the data to an entity.


