Access Control Policy Generation from Choreography
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for implementing access control in collaborative business processes, especially in virtual organizations, are inadequate as they rely on manual configuration by system administrators, leading to error-prone and complex processes that are not scalable with the growing complexity of collaborations.
Innovation Solution
A method is introduced to generate and enable access control policies directly from choreography, using a dedicated access controller that implicitly represents control-flow states, decoupling access control decisions from control-flow decisions and allowing for active access control policies that align with the control flow of the collaboration, thereby reducing the need for manual configuration and enhancing scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual configuration of access control policies by system administrators is used, then access control can be implemented in workflow engines, but the process becomes error-prone and not scalable with growing collaboration complexity
Solution Approach 1:
The system enables self-service by automatically generating access control policies from choreography descriptions. The policy generation component derives policies autonomously from the collaboration model without requiring manual administrator intervention, making the system adaptable to growing complexity while maintaining accuracy.
Solution Approach 2:
Access control policies are generated in advance during choreography definition. The policies are prepared beforehand based on the collaboration model before actual collaboration execution begins, eliminating the need for manual configuration during runtime and reducing errors.
2Ease of operation
If control-flow information is excluded from access control policies, then policies remain simple triplets, but access control becomes insufficiently central to workflow engine functionality
Solution Approach 1:
The invention merges control-flow information with access control policies by integrating the choreography description (which defines control-flow) into the policy generation process. This combination allows the workflow engine to automatically generate centralized access control policies that incorporate both access requirements and control-flow context.
3Reliability
If system administrators manually configure access control policies, then policies can be implemented, but time constraints and technical complexity increase error potential
Solution Approach 1:
The policy generation component performs self-service by automatically creating access control policies from the choreography description. This eliminates the time-consuming manual configuration process while reducing errors through automated, consistent policy generation based on the collaboration model.
Solution Approach 2:
The manual mechanical process of administrator configuration is replaced with an automated system that algorithmically generates policies from choreography descriptions. This substitution eliminates human error and time constraints associated with manual policy creation.
4Device complexity
If primitive access control triplets are used, then policies are simple to define, but they cannot adequately handle sophisticated collaborative business processes
Solution Approach 1:
The generated access control policies serve multiple functions: they enforce access control, incorporate control-flow context from choreography, and adapt to sophisticated collaboration scenarios. The universal policy generation mechanism handles both simple and complex collaborative processes using a unified approach.
Solution Approach 2:
The policy system becomes dynamic by automatically adapting to different collaboration scenarios through choreography-driven generation. Policies are not static but are dynamically created and updated based on the specific collaboration model and control-flow requirements, enabling versatility across different business processes.
Data Source
AI summary
A system architecture and algorithm for automatically generating, installing and enforcing access control policies that correspond to an agreed specification of collaboration. A collaboration member enforces its access control policies using a dedicated access controller separate from a workflow engine. In one embodiment, each access control policy contains extensions which can direct an access controller to selectively enable or disable various access control policies upon authorization of an access request.


