API-Linked Policy Management for Application Access Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to efficiently manage user consents and terms and conditions across complex software applications, leading to non-compliance with data protection regulations and loss of consumer trust due to the lack of dynamic and reliable policy management.

Innovation Solution

A plug-and-play platform integrated with existing client architectures to manage policies and user data access, enabling real-time compliance with regulations by linking policies to specific application features, roles, and regions, and allowing customization for different user groups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If companies implement comprehensive policy management for all application features, then compliance with data protection regulations is improved, but device complexity increases

Engineering Contradiction:
Improvecompliance with data protection regulationsVSAvoidpolicy management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the policy management system into distinct components: a policy management service that receives and stores policies, an API manager that enforces policies, and an identity server that validates user identities. Policies are further segmented by feature, user role, and region, allowing granular control without overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary policy management service that acts as a mediator between the application provider and the API manager. This service receives policies from providers, validates them, stores them in a database, and makes them available to the API manager for enforcement, thereby simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If companies present all policies to all users, then comprehensive compliance is achieved, but loss of time increases due to user burden

Engineering Contradiction:
Improvecompliance coverageVSAvoiduser acceptance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by customizing policy presentation based on user characteristics. The system determines which policies are relevant to each user based on their identity, the feature they are accessing, and their regional location. Users only see and need to accept policies that apply to their specific context, reducing time burden while maintaining compliance.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary action by pre-processing policies to identify which ones are relevant to each user before presentation. The policy management service and API manager work together to filter and prepare only the necessary policies for each user session, avoiding the need to present all policies to all users.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If companies use static policy management, then system simplicity is maintained, but adaptability to different regulations and services decreases

Engineering Contradiction:
Improvepolicy customization capabilityVSAvoiddynamic management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamics by creating a flexible policy management system where policies can be dynamically created, updated, and enforced. The policy management service receives policies in real-time, validates them against schemas, and the API manager dynamically enforces them based on current user requests. This allows the system to adapt to different regulations and services without rigid preconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system allows parameter changes in policies through structured data schemas that define configurable parameters. Policies can be modified by changing their parameters (such as data processing rules, retention periods, or access conditions) while maintaining the same policy structure, enabling adaptability without requiring complete policy redefinition.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3823234B1System and method for management of policies and user data during application access sessions
Publication Date: 2025.09.24 ACCENTURE GLOBAL SOLUTIONS LTD
  • EP3823234B1 patent drawingFigure 1
  • EP3823234B1 patent drawingFigure 2
  • EP3823234B1 patent drawingFigure 3A

AI summary

A system and method for managing access by end-users to features of an application through a policy management service is disclosed. Specifically, the method and system enable an application provider to utilize tools made available by the policy management service for creation of policies, such as terms and conditions and/or consent to data usage. In addition, the policy management service can provide an interface from which application administrators can link subset(s) of an API to specific policies, as well as the manage the presentation of these policies to end-users of the API that offer options to review and accept or reject the policies. The service further allows users to revoke an acceptance to a policy and to review their privacy settings. In addition, the policy management service can regulate the access of user data by external entities based on the policy limits.