Aggregated ACL Data Structures for Access-Controlled Resource Rendering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access-control management technologies are inefficient in terms of computing resource consumption, particularly due to high throughput, latency, CPU utilization, and memory usage, and are limited in functionality, especially when dealing with multiple access-controlled resources that have different access control levels.

Innovation Solution

The implementation of improved data structures and functionality, including the generation of unique index and resource data structures, aggregated ACLs, and the use of access defining and inheriting memory storage units, which efficiently render access-controlled resources by combining ACLs and reducing redundant access control level identifiers, thereby optimizing CPU and I/O operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If existing access-control management technologies are used to manage multiple access-controlled resources, then access control functionality is provided, but computing resource consumption (throughput, latency, CPU utilization, memory usage) is excessively high

Engineering Contradiction:
ImprovethroughputVSAvoidCPU utilization
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent segments the access control management by introducing an aggregation layer that groups multiple ACLs into aggregated ACLs. This segmentation allows the system to process aggregated access control data rather than individual ACLs for each resource, reducing the overall computing workload and improving throughput while maintaining security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple individual ACLs into a single aggregated ACL that represents access control for multiple resources. This combining approach reduces memory usage and CPU utilization by eliminating redundant access control level identifiers and consolidating access control logic, directly addressing the high resource consumption problem.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If individual ACLs are stored for each access-controlled resource, then fine-grained access control is maintained, but memory consumption and I/O overhead increase significantly

Engineering Contradiction:
Improveaccess control accuracyVSAvoidmemory consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines multiple individual ACLs into aggregated ACLs that maintain the same access control enforcement capability. By merging redundant access control level identifiers and consolidating access control data structures, the system reduces memory consumption while preserving the reliability and accuracy of access control decisions through the aggregation process.

Inventive Principle:
Principle #5Merging (Combining)

3Manufacturing precision

If access control checks are performed for each resource individually, then precise access control is enforced, but processing time and latency increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidprocessing time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary aggregation of multiple ACLs into aggregated ACLs before access control checks are needed at runtime. This preliminary action consolidates access control logic and eliminates redundant processing, allowing the system to maintain precise access control enforcement while significantly reducing processing time and latency during actual access operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11968214B2Efficient retrieval and rendering of access-controlled computer resources
Publication Date: 2024.04.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11968214B2 patent drawing
  • US11968214B2 patent drawing
  • US11968214B2 patent drawing

AI summary

Particular aspects of this disclosure relate to computerized systems for generating and using improved data structures and functionality to efficiently render different multiple access-controlled resources (or properties of access-controlled resources) that are part of a concept. Often times, two or more resources of a concept or properties of a resource are subject to different access controls. This adds computing complexity as to whether or not a user is granted access to the entire concept or resource, a portion of the concept or resource, or none of the concept or resources and what exactly is surfaced back to the user when there are resources or properties the user does and does not have access to. Some embodiments accordingly render an efficient composite view of concepts or resources where some resources or properties are accessible by the requesting user, while other resources or properties are not accessible by the requesting user.