Aggregated ACL Data Structures for Access-Controlled Resource Rendering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access-control management technologies are inefficient in terms of computing resource consumption, particularly due to high throughput, latency, CPU utilization, and memory usage, and are limited in functionality, especially when dealing with multiple access-controlled resources that have different access control levels.
Innovation Solution
The implementation of improved data structures and functionality, including the generation of unique index and resource data structures, aggregated ACLs, and the use of access defining and inheriting memory storage units, which efficiently render access-controlled resources by combining ACLs and reducing redundant access control level identifiers, thereby optimizing CPU and I/O operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If existing access-control management technologies are used to manage multiple access-controlled resources, then access control functionality is provided, but computing resource consumption (throughput, latency, CPU utilization, memory usage) is excessively high
Solution Approach 1:
The patent segments the access control management by introducing an aggregation layer that groups multiple ACLs into aggregated ACLs. This segmentation allows the system to process aggregated access control data rather than individual ACLs for each resource, reducing the overall computing workload and improving throughput while maintaining security requirements.
Solution Approach 2:
The patent merges multiple individual ACLs into a single aggregated ACL that represents access control for multiple resources. This combining approach reduces memory usage and CPU utilization by eliminating redundant access control level identifiers and consolidating access control logic, directly addressing the high resource consumption problem.
2Reliability
If individual ACLs are stored for each access-controlled resource, then fine-grained access control is maintained, but memory consumption and I/O overhead increase significantly
Solution Approach 1:
The patent combines multiple individual ACLs into aggregated ACLs that maintain the same access control enforcement capability. By merging redundant access control level identifiers and consolidating access control data structures, the system reduces memory consumption while preserving the reliability and accuracy of access control decisions through the aggregation process.
3Manufacturing precision
If access control checks are performed for each resource individually, then precise access control is enforced, but processing time and latency increase
Solution Approach 1:
The patent performs preliminary aggregation of multiple ACLs into aggregated ACLs before access control checks are needed at runtime. This preliminary action consolidates access control logic and eliminates redundant processing, allowing the system to maintain precise access control enforcement while significantly reducing processing time and latency during actual access operations.
Data Source
AI summary
Particular aspects of this disclosure relate to computerized systems for generating and using improved data structures and functionality to efficiently render different multiple access-controlled resources (or properties of access-controlled resources) that are part of a concept. Often times, two or more resources of a concept or properties of a resource are subject to different access controls. This adds computing complexity as to whether or not a user is granted access to the entire concept or resource, a portion of the concept or resource, or none of the concept or resources and what exactly is surfaced back to the user when there are resources or properties the user does and does not have access to. Some embodiments accordingly render an efficient composite view of concepts or resources where some resources or properties are accessible by the requesting user, while other resources or properties are not accessible by the requesting user.


