Attribute-Based Access Control Policy Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large-scale systems-of-systems and distributed systems, the manual and non-standardized process of developing and maintaining access control requirements leads to inconsistencies and increased costs due to the lack of a standardized method for defining access control policies.

Innovation Solution

A method and apparatus that model authorization requirements to generate a single set of attribute-based access control policies expressed in an authorization markup language, such as XACML, to standardize and automate the definition of access control policies across multiple access control domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual and non-standardized processes are used to develop access control requirements, then flexibility in customization is improved, but consistency and reliability of policies deteriorate

Engineering Contradiction:
Improvecustomization flexibilityVSAvoidpolicy consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent transforms access control policies from manual text-based specifications into structured machine-readable models with standardized parameters. By defining policies as data structures with specific attributes and constraints, the system maintains customization flexibility while ensuring consistent interpretation and enforcement across different systems.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces manual mechanical processes of policy development and verification with automated computational methods. The machine-readable model enables automatic validation, conflict detection, and policy generation, eliminating human error and inconsistency while preserving the ability to customize policies through structured parameter definition.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If multiple access control mechanisms are used in distributed systems, then adaptability to different systems is improved, but complexity of policy management deteriorate

Engineering Contradiction:
Improvesystem compatibilityVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal machine-readable policy model that can represent access control requirements across multiple different systems and mechanisms. This single standardized model structure can be adapted to various access control implementations, reducing the need for separate policy management approaches for each system while maintaining system-specific nuances.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The machine-readable policy model serves as an intermediary representation layer between diverse access control mechanisms. By translating various system-specific policies into this common intermediate form, the system simplifies policy management while preserving compatibility with multiple underlying access control mechanisms through automated translation and enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If manual processes are used for developing access control policies, then ease of initial creation is improved, but productivity and efficiency of policy maintenance deteriorate

Engineering Contradiction:
Improvepolicy creation easeVSAvoidpolicy maintenance efficiency
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent performs preliminary structuring of policies into machine-readable models during the initial creation phase. By establishing the standardized structure upfront with defined parameters and constraints, the system enables automated processing, validation, and maintenance operations later, significantly improving productivity while keeping initial creation straightforward through template-based approaches.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The machine-readable policy model enables self-service capabilities for policy maintenance through automated validation, conflict detection, and consistency checking. The structured format allows systems to automatically verify policy correctness and enforce requirements without manual intervention, dramatically improving maintenance efficiency while preserving ease of creation through standardized templates.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7921452B2Defining consistent access control policies
Publication Date: 2011.04.05 THE BOEING CO
  • US7921452B2 patent drawing
  • US7921452B2 patent drawing
  • US7921452B2 patent drawing

AI summary

A method of defining policies for controlling access to resources of a system. Authorization requirements for the system are modeled to obtain a model expressing each of a plurality of access control policies as a constraint. From the model is generated a single policy set in an authorization markup language that captures the requirements. This method can be used to define role-based access control policies in a format that can be adapted for input to a variety of access control mechanisms. This generative approach to access control design allows maintenance to be performed at the requirements level.