Granular Access Control via Role and Expertise Templates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems lack a flexible and granular access control mechanism to manage access to objects and object information, particularly in complex data storage environments where multiple users with varying levels of expertise need to access and manage data.

Innovation Solution

A computer-implemented method that selects a template specifying roles, levels of expertise, and accessible objects, associating the template with a user identifier to restrict access to objects and object information, using a hierarchical object model with roles and skill levels to provide fine-grained access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional access control mechanisms are used in data storage systems, then implementation is simple, but access control granularity is insufficient for complex environments with multiple users of varying expertise

Engineering Contradiction:
Improveaccess control granularityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments access control into multiple dimensions: roles (e.g., administrator, user), expertise levels (novice, intermediate, expert), and object types. This segmentation allows fine-grained control where each dimension can be independently configured, enabling complex access policies to be built from simple, manageable components rather than requiring a monolithic complex control system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces additional dimensions to the access control model beyond traditional user-based control. By adding role dimension, expertise level dimension, and object type dimension, the system achieves finer granularity without proportionally increasing complexity. Each dimension adds a layer of control that can be configured independently, allowing the system to adapt to complex environments while maintaining manageable complexity through modular dimension-based configuration

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If multiple users with different expertise levels need access to data storage systems, then access flexibility is improved, but control over specific object access becomes difficult

Engineering Contradiction:
Improveuser access flexibilityVSAvoidobject access control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamic access control where the effective permissions are determined by the combination of user role, expertise level, and requested object type. This dynamic evaluation allows the system to automatically adjust access rights based on the specific context of each access request, making the system flexible for multiple user types while keeping operation simple through automated decision-making rather than manual configuration for each user-object pair

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an intermediary access control mechanism that sits between users and data objects. This intermediary evaluates access requests by considering the user's role, expertise level, and the object type, then automatically determines whether to grant or deny access. This intermediary layer simplifies operation for users while maintaining fine-grained control, as users don't need to understand or configure complex access rules - the intermediary handles this automatically based on predefined policies

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If fine-grained access control is implemented with roles and expertise levels, then access precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoiddata model complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the access control precision requirement into discrete, manageable components: specific roles, defined expertise levels, and object type categories. Each segment can be independently configured and managed. This segmentation allows the system to achieve high precision control while keeping the data model relatively simple, as each segment uses standardized, pre-defined values rather than requiring custom configurations for each user or object

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent achieves precision control by changing parameters in a structured way - using discrete expertise levels (novice, intermediate, expert) and role types rather than continuous or custom parameters. This parameterization allows precise control over access rights while maintaining simplicity in the data model, as the precision comes from the structured parameter combinations rather than complex data structures. The system can achieve high measurement precision in access control by carefully selecting and combining a limited set of well-defined parameters

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8725767B1Multi-dimensional object model for storage management
Publication Date: 2014.05.13 EMC IP HLDG CO LLC
  • US8725767B1 patent drawing
  • US8725767B1 patent drawing
  • US8725767B1 patent drawing

AI summary

Described are techniques for controlling access to objects. A template is selected. The template includes information specifying a role, one or more levels of expertise, and which objects and object information are accessible to said one or more levels of expertise. A first of the levels of expertise is selected. The template and the first level of expertise are associated with a user identifier. Access to objects and object information is restricted in accordance with the template when performing processing for the user identifier.