Access Control Apparatus Dynamic Attribute Acquisition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems face inefficiencies when dealing with exclusive and selective attribute information, leading to rigid and restricted access decisions that may omit necessary authentication steps, increasing the risk of information leakage or impairment.
Innovation Solution
An access control apparatus that employs a multi-stage policy system, using both deny-type and obligation-type policies to dynamically acquire and update attribute information, allowing for detailed and flexible access control by sequentially evaluating access requests against stored policies and updating attribute information based on obligation execution results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all items of attribute information are acquired for access decision, then the access control completeness is improved, but the processing time and system efficiency deteriorate
Solution Approach 1:
The patent segments the attribute information acquisition process into multiple stages. In the first stage, a first set of attribute information items is acquired and used for initial access decision. If the decision result is inconclusive, the system proceeds to a second stage where additional attribute information items are acquired. This segmentation allows the system to balance completeness and efficiency by only acquiring additional information when necessary.
Solution Approach 2:
The patent implements preliminary action by acquiring and evaluating the first set of attribute information items before proceeding to acquire the second set. This preliminary evaluation allows the system to make access decisions based on available information without unnecessarily acquiring all possible attribute information, thereby reducing processing time while maintaining control completeness.
2Device complexity
If attribute information acquisition is performed in a rigid and restricted way, then the system complexity is reduced, but the adaptability to different access scenarios deteriorates
Solution Approach 1:
The patent implements dynamic attribute information acquisition by determining whether to acquire a second set of attribute information items based on the access decision result from the first set. This dynamic approach allows the system to adapt to different access scenarios by flexibly acquiring additional information only when the initial evaluation is inconclusive, thereby maintaining both simplicity and adaptability.
Solution Approach 2:
The patent changes the parameter of attribute information completeness dynamically. Instead of always acquiring all attribute information items, the system adjusts the quantity and type of acquired information based on the access decision result. When the first set provides a conclusive decision, no additional information is acquired; when inconclusive, the second set is acquired to complete the evaluation.
3Productivity
If selective attribute information is not fully acquired, then the processing efficiency is improved, but the access control security deteriorates
Solution Approach 1:
The patent implements feedback by using the access decision result from the first set of attribute information as a trigger for acquiring the second set. The feedback mechanism ensures that when the initial evaluation is inconclusive, additional attribute information is automatically acquired to reach a definitive security decision, thereby maintaining access control security while optimizing processing efficiency for conclusive cases.
Data Source
AI summary
According to one embodiment, an access control apparatus suspends the resource access event prior to access of the resource access device when the resource access event is started. The access control apparatus acquires attribute information from the attribute management device by using the deny-type policy in the access control policy and decides the permission or the denial of the access based on this attribute information and the deny-type policy. The access control apparatus releases the suspension when a result of decision in the supplied access decision result is indicative of the permission and no obligation-type policy is present in the access decision response.


