Access Control Rules for Multi-Criteria Resource Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems based on job titles fail to account for relevant factors in determining resource access, leading to inefficiencies and the need for governance and tracking of access allocations across multiple parties with independent interests.
Innovation Solution
A method and system that receive inputs from business stakeholders and application owners to generate rules and policies for access control, incorporating criteria such as employee identification, job titles, access time, location, and operational aspects, with validation and authentication processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If access control is based on job title alone, then the system is simple to implement, but it fails to account for relevant factors such as access time, location, and business function
Solution Approach 1:
The patent segments the access control decision into multiple independent criteria: job title, access time, location, and business function. Each criterion is evaluated separately and combined to form a comprehensive access decision, allowing the system to account for multiple relevant factors while maintaining clear separation of concerns in the implementation.
Solution Approach 2:
The patent adds multiple dimensions to the access control system beyond just job title. It introduces temporal dimension (access time), spatial dimension (location), and functional dimension (business function), transforming a one-dimensional access control model into a multi-dimensional one that provides more accurate and context-aware access decisions.
2Reliability
If multiple parties with independent interests are involved in access determination, then access allocation becomes more accurate and comprehensive, but governance and tracking become more difficult
Solution Approach 1:
The patent introduces an intermediary access control system that mediates between multiple parties with independent interests (application owners, business stakeholders, security teams). This intermediary system consolidates their inputs, processes them according to defined policies, and produces a unified access decision, simplifying governance while maintaining comprehensive input from all stakeholders.
Solution Approach 2:
The patent implements feedback mechanisms that track and record access decisions, rule applications, and stakeholder inputs. This feedback loop enables governance and auditing by providing visibility into how access decisions are made, which parties are involved, and what rules are applied, thereby managing the complexity of multi-party involvement.
3Reliability
If access control considers multiple criteria including time and location, then access security is improved, but the system requires more inputs and processing
Solution Approach 1:
The patent applies preliminary action by pre-defining access rules, policies, and criteria before access requests are made. Access time windows, location permissions, and business function mappings are established in advance, allowing the system to quickly evaluate incoming requests against pre-configured criteria rather than processing everything in real-time, thus reducing processing time while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for controlling an access to a resource is provided. The method includes receiving, from a first user, a first input that relates to a business criterion for a provision of the access to the resource; receiving, from a second user, a second input that relates to an application-specific criterion for the provision of the access to the resource; generating one or more one access-control rules based on the inputs; receiving an access request; and determining whether to grant the access request based on the rules, and any conditions that pertain to the access. The method effectively decouples the business-related criterion from the application-specific criterion for the access determination, thereby ensuring that business stakeholders and application owners each have an independent ability to provide inputs for generating access-control rules and policies.