Standardized Access Control Enforcement via Policy Interceptor

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Policy-Based Access Control (PBAC) systems lack standardized enforcement mechanisms, leading to challenges in maintaining uniform access control policies across disparate systems, which results in degraded performance, non-uniform access control, and compliance and security risks.

Innovation Solution

The implementation of a system that provides dynamic enforcement of access control policies in a standardized manner, using a policy administrator console for defining access control policies through a set of classes, and employing an interceptor and an enforcer for centralized detection, policy administration, and enforcement of access requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If solo-type access control mechanisms are used per system and region, then each system can have its own customized access control, but maintaining uniform access control policies across all systems becomes difficult

Engineering Contradiction:
Improvecustomized access control per systemVSAvoiduniformity of access control policies
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent implements a universal access control policy framework that can be applied across multiple disparate systems and regions. The policy administrator console provides a centralized interface for defining access control policies that can be propagated uniformly to various data sources, devices, applications, and services throughout the enterprise, enabling one policy management system to serve multiple different systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the access control system into distinct functional components: a policy administrator console for policy definition, an interceptor for detecting access requests, and an enforcer for implementing policy decisions. This segmentation allows each component to perform its specific function while working together to maintain uniform access control across the entire system.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If individual control mechanisms are implemented per system, then each system can be controlled independently, but policy changes cannot be propagated uniformly across all systems

Engineering Contradiction:
Improveindependent system controlVSAvoidtime to propagate policy changes
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements preliminary action by providing a policy administrator console that allows access control policies to be defined and configured in advance in a standardized manner. These pre-defined policies can then be rapidly propagated to all systems when changes are needed, eliminating the time-consuming process of manually updating each system individually.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary policy administrator console that acts as a mediator between policy administrators and the various access control systems. This intermediary receives policy definitions, processes them through a standardized enforcement layer, and distributes them uniformly across all connected systems, enabling efficient policy propagation while maintaining independent system operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple disparate access control systems are used across regions, then each region can have localized control, but system complexity and difficulty of maintenance increase

Engineering Contradiction:
Improvelocalized regional controlVSAvoidnumber of access control systems
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal access control policy framework that can be applied across multiple disparate systems and regions. The policy administrator console provides a centralized interface for defining access control policies that can be propagated uniformly to various data sources, devices, applications, and services throughout the enterprise, enabling one policy management system to serve multiple different systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If standardized enforcement mechanisms are not implemented, then system flexibility is maintained, but compliance and security risks increase

Engineering Contradiction:
Improvesystem flexibilityVSAvoidcompliance and security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements standardized enforcement mechanisms that change the operational parameters of access control systems. By establishing uniform policy definition, propagation, and enforcement parameters across all systems, the patent ensures consistent security and compliance enforcement while maintaining the flexibility to adapt to different system types through the standardized interface.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12316677B2Policy based access control system with standardized enforcement layer
Publication Date: 2025.05.27 ACCENTURE GLOBAL SOLUTIONS LTD
  • US12316677B2 patent drawing
  • US12316677B2 patent drawing
  • US12316677B2 patent drawing

AI summary

Aspects of the present disclosure provide methods, devices, and computer-readable storage media that support dynamic enforcement of access control policies in a standardized manner. An administrator console enables access control policies to be defined as classes that may be combined and leveraged to rapidly define access control policies for enforcement in a standardized manner. An interceptor operates to detect access requests and perform policy administration (e.g., determining to grant/deny access) for the access requests and where access is granted, initiate policy resolution (e.g., determine any restrictions on the granted access request). An enforcer provides functionality for enforcing policy resolution outcomes, such as restricting access to information stored in a database or disabling interactive elements of a user interface. The enforcer may control enforcement of the policy resolution outcomes by modifying information in received access requests, such as to rewrite a query to incorporate restrictions on access to a data source.