US2018330108A1PendingUtilityA1

Updating monitoring systems using merged data policies

Assignee: IBMPriority: May 15, 2017Filed: Dec 13, 2017Published: Nov 15, 2018
Est. expiryMay 15, 2037(~10.8 yrs left)· nominal 20-yr term from priority
G06F 21/6218G06F 21/604G06F 17/30082G06F 21/552G06F 16/122
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An example system includes a processor to monitor a data asset and associated access policies to be synchronized to detect a trigger. The processor is to also request and receive data lineage information on the monitored data asset in response to detecting the trigger. The processor is to further detect a source system and a target system based on the data lineage information. The processor is also to query an access policy of the source system and an access policy of the target system. The processor is to merge the access policy of the source system and the access policy of the target system based on a predetermined merger configuration to generate a merged access policy. The processor is to update a monitoring system based on the merged access policy.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 tracking, in a data flow graph, data lineage information for sensitive data fields, the data lineage information comprising records of historical completed transfers of the sensitive data fields among a plurality of databases having a variety of data access policies, wherein the data access policies for each database are enforced by a different monitoring system of a plurality of monitoring systems;   detecting an attempt to transfer, from a first database of the plurality of databases and to a second database of the plurality of databases, a first sensitive data field containing a first type of data and a second sensitive data field containing a second type of data;   accessing, in response to the detected transfer attempt, the data flow graph to obtain data lineage information for the first sensitive data field and the second sensitive data field;   identifying, from the obtained data lineage information, that the first sensitive data field and the second sensitive data field were previously transferred from a third database of the plurality of databases to the first database;   querying, based on the obtained data lineage information, access policies of the first database that are enforced by a first monitoring system, the second database that are enforced by a second monitoring system, and the third database that are enforced by a third monitoring system for access rules within each access policy for accessing the first type of data and the second type of data;   comparing, using a Lightweight Directory Access Protocol (LDAP) module, the queried access policies by mapping identities of users and roles among the first, second, and third monitoring systems;   determining, based on the compared access policies, that the access policies of the second database and the third database are different from each other with respect to access rules for accessing the first type of data and the second type of data;   synchronizing, based on the determined differences and in accordance with a data asset hierarchy dictated by a predetermined merger configuration, the access policies of the second database and the third database with respect to the access rules for accessing the first type of data and the second type of data, wherein, upon synchronization, the access rules of the second database for accessing the first type of data are modified, based on data assets of the first type in the second database being ranked lower in the data asset hierarchy than the data assets of the first type in the third database, such that they match the existing access rules of the third database for accessing the first type of data and the access rules of the third database for accessing the second type of data are modified, based on data assets of the second type in the third database being ranked lower in the data asset hierarchy than the data assets of the second type in the second database, such that they match the existing access rules of the second database for accessing the second type of data; and   allowing, in response to the synchronization, the attempted transfer from the first database to the second database to complete.

Join the waitlist — get patent alerts

Track US2018330108A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.