Access Policy Controller for Granular Artifact Rights

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current service creation environments lack fine-grained control over access operations for distributed artifacts, such as application skeletons, making it difficult for creators to manage who can read, modify, or execute these artifacts, especially in scenarios like telecom applications where stability and know-how protection are critical.

Innovation Solution

A system comprising an application development environment with an access control database and an access policy controller that implements policies to control access rights for artifacts, allowing granular control over operations like editing, modifying, or executing artifacts based on party requests and policies, using an access manager to enforce these policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If artifacts are distributed to customers for use, then customer productivity and service deployment are improved, but control over access and modification of artifacts is lost

Engineering Contradiction:
Improveservice deployment efficiencyVSAvoidaccess control management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an access manager as an intermediary component that sits between the customer's execution environment and the distributed artifacts. This access manager enforces access control policies without requiring complex integration into the customer's systems, enabling simple artifact distribution while maintaining centralized control over read, modify, and execute operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments access control into distinct policy types (read policy, modify policy, execute policy) that can be independently configured and enforced. This segmentation allows fine-grained control over different operations on distributed artifacts without requiring a monolithic complex control system.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If fine-grained access control policies are implemented, then control over artifact operations is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control granularityVSAvoidpolicy enforcement mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent changes the parameters of access control by introducing policy priority levels and different policy types (read, modify, execute) that can be independently configured. This allows fine-grained control through parameter variation rather than through complex structural mechanisms.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The access manager serves as a simplified intermediary that handles the complexity of policy enforcement internally while presenting a simple interface for policy configuration. The mediator absorbs the complexity of evaluating multiple policies and determining access decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If source code is made visible to customers, then ease of operation and customization are improved, but intellectual property protection deteriorates

Engineering Contradiction:
Improvecustomer ability to use artifactsVSAvoidintellectual property exposure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent applies different access control qualities to different parts of the artifact based on the operation type. Source code can be made visible and readable for ease of operation, while modification and execution can be restricted through separate policies, allowing selective protection of intellectual property while maintaining usability.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If modification of distributed artifacts is allowed, then adaptability and customization are improved, but system stability deteriorates

Engineering Contradiction:
Improveartifact customization capabilityVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent makes the modify policy dynamic and configurable on a per-artifact basis. Artifacts critical for system stability can have modification restricted through policy enforcement, while less critical artifacts can allow customization. The access manager dynamically evaluates modify policies to determine whether to allow or block modification operations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9111108B2System, method and program for controlling access rights
Publication Date: 2015.08.18 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9111108B2 patent drawing
  • US9111108B2 patent drawing
  • US9111108B2 patent drawing

AI summary

A system for controlling access rights of a software developer party with respect to artifacts having computer operated functions of a computer program includes an access control database which has policies that control access by a party to the artifacts in an application development environment. The system includes an application development environment having the artifacts. The system includes an access policy controller in communication with the access control database and the application development environment which implements the policies and controls access by the party to the artifacts being controlled. At least a first of the plurality of artifacts has a part being modifiable by the party and operative with all other artifacts of the plurality of artifacts after being modified.