Multi-layered access control system for experience cloud architectures

DE202026103280U1Undetermined Publication Date: 2026-07-30BALACHANDRAN SANTHOSH KUMAR
0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
BALACHANDRAN SANTHOSH KUMAR
Filing Date
2026-06-05
Publication Date
2026-07-30
Patent Text Reader

Abstract

A multi-layered access control system for experience cloud architectures, wherein the system comprises: an identity orchestration layer comprising an identity provider interface module configured to communicate with a variety of external identity providers and normalize identity claims into a standardized identity token format; a multi-factor authentication engine configured to perform risk-based authentication queries based on calculated risk assessments; and a session token manager configured to generate cryptographically signed session tokens that encapsulate the authenticated user identity and access claims;a policy decision layer comprising an attribute-based policy engine configured to evaluate access policies based on subject attributes, resource attributes, and action types; a role hierarchy processor configured to compute effective sets of permissions by traversing a directed acyclic graph of role inheritance relationships; and a context evaluation module configured to evaluate context-related parameters in real time and generate a context compliance score;an experience delivery layer comprising a content access gateway configured to filter content objects based on a permitted content set derived from the composite access decision, a personalization filtering module configured to apply content substitution and layout adjustment rules, and an experience rendering engine configured to assemble filtered content into a final experience output; an audit and compliance layer comprising a real-time access logger, a compliance verification module, and an anomaly detection engine; a cloud infrastructure interface comprising a multi-tenant isolation manager, an API gateway module, and a service mesh controller; a central policy repository storing access control policies, role definitions, attribute schemas, and compliance rules;and a communication bus that connects all layers and enables secure bidirectional data exchange; characterized in that the system (100) integrates the identity orchestration layer, the policy decision layer, and the experience delivery layer into a unified access enforcement pipeline, wherein access decisions are evaluated using a composite scoring mechanism that combines attribute-based policy evaluation, role hierarchy traversal, and real-time context evaluation, and wherein the experience delivery layer enforces said access decisions at the content presentation level through content substitution and personalization filtering to provide a coherent yet access-restricted user experience.
Need to check novelty before this filing date? Find Prior Art