Access Relationship Management via Intermediate Entity Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing complex and unintended access relationships in large computing environments is challenging due to the creation of long, complicated chains of trust that can lose their original purpose, leading to difficulties in monitoring and controlling access permissions across numerous entities.
Innovation Solution
A method and apparatus for determining and managing access relationships by creating a chain of access relationships between entities, allowing for the selection of intermediate entities to route access relationships, and prioritizing or replacing existing relationships based on various criteria such as security credentials, policy, and data traffic, enabling better control and visibility of access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If access relationships are managed through multiple intermediate entities forming chains of trust, then access control flexibility and granularity are improved, but system complexity and difficulty in monitoring increase
Solution Approach 1:
The patent introduces an intermediary entity (the system performing the method) that manages and coordinates access relationships between multiple entities. This intermediary consolidates the complexity of managing chained trust relationships by providing a centralized mechanism to determine, select, and create access relationships, thereby maintaining flexibility while reducing overall system complexity.
Solution Approach 2:
The patent segments the complex access relationship management into distinct operational steps: determining existing relationships, selecting intermediate entities, and creating new relationships. This segmentation allows each component to be managed independently, improving flexibility while making the overall system more manageable and less complex.
2Adaptability or versatility
If long and complicated chains of trust are created between entities, then access routing options increase, but monitoring and controlling access permissions becomes more difficult
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously determines existing access relationships and evaluates them against selection criteria. This feedback loop enables the system to monitor and control access permissions effectively by assessing the current state and making informed decisions about creating or modifying access relationships, thereby reducing monitoring difficulty while maintaining routing flexibility.
3Adaptability or versatility
If multiple access relationships are maintained between entities, then access control granularity is improved, but administrative overhead increases
Solution Approach 1:
The patent enables the system to automatically manage access relationships by autonomously determining existing relationships, selecting appropriate intermediate entities based on predefined criteria, and creating new relationships without manual intervention. This self-service approach maintains fine-grained access control while significantly reducing administrative overhead and time loss.
4Adaptability or versatility
If access relationships are allowed to evolve independently without coordination, then entity autonomy is maintained, but unintended access chains are created
Solution Approach 1:
The patent applies preliminary action by establishing coordination mechanisms before access relationships evolve independently. The system determines existing relationships and selects intermediate entities based on predefined selection criteria before creating new relationships, ensuring that access chains are intentionally designed rather than accidentally formed, thereby maintaining both entity autonomy and relationship integrity.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
The disclosure relates to access relationships, more particularly to controlling access relationships between entities in a computerized system. In the disclose arrangement a first access relationship between a first entity and a second entity is determined. At least one intermediate entity is selected for routing of a second access relationship between the first entity and the second entity via the at least one intermediate entity. The second access relationship is created, the second access relationship comprising a chain of access relationships via the first entity, the at least one intermediate entity and the second entity.