Attribute-Based Access Control for Technical Data Files
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control systems for global entities do not support fine-grained access control to information resources across multiple jurisdictions, leading to inefficiencies and compliance issues, particularly in cross-jurisdictional collaborations and regulatory environments.
Innovation Solution
A method utilizing a machine-learning model to analyze unstructured policy documents and extract policy attributes, which are then stored in a network-accessible library, allowing for attribute-based access control that compares user attributes with policy attributes to grant granular access to technical data files, ensuring compliance with various jurisdictional regulations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure walled off areas are created to protect information, then security and compliance are improved, but accessibility and operational efficiency deteriorate
Solution Approach 1:
The patent segments access control into fine-grained attributes (e.g., jurisdiction, role, clearance level) rather than treating access as a single binary state. This allows different portions of the system to handle different security requirements independently, enabling both strict security compliance and efficient access for authorized users.
Solution Approach 2:
The system changes the parameters of access control from coarse-grained (allowed/not allowed) to fine-grained (allowed with specific attributes). By introducing multiple dimensional attributes that can be independently evaluated, the system achieves both security compliance and operational efficiency simultaneously.
2Reliability
If fine-grained access control is implemented across multiple jurisdictions, then compliance with jurisdictional regulations is improved, but system complexity increases
Solution Approach 1:
The patent creates a universal attribute-based access control framework that can handle multiple jurisdictions and compliance requirements through a single unified system. The same core mechanism (attribute comparison) serves multiple functions across different legal and organizational contexts, reducing overall system complexity.
Solution Approach 2:
The system adds dimensional attributes (jurisdiction, role, clearance, etc.) to the access control model rather than creating separate systems for each requirement. This dimensional approach allows the system to handle complex multi-jurisdictional compliance through attribute evaluation rather than structural complexity.
3Reliability
If manual access approval processes are used, then security control is improved, but time consumption and operational efficiency deteriorate
Solution Approach 1:
The system enables self-service access control where users with appropriate attributes can automatically obtain access without manual approval. The attribute-based evaluation performs security checks automatically, allowing authorized users to access resources immediately while maintaining security controls.
Solution Approach 2:
The patent replaces manual mechanical approval processes with automated computer-based attribute evaluation. The system automatically compares user attributes against required attributes and makes access decisions without human intervention, eliminating time-consuming manual processes while maintaining security.
Data Source
AI summary
A method for providing network access to technical data files is provided herein. The method includes receiving a technical data file via a computer network, and securely storing the technical data file in a network-accessible, access-restricted technical data repository. An unstructured policy document corresponding to the technical data file is computer-analyzed with a previously-trained machine-learning model configured to extract one or more policy attributes from unstructured policy documents. Extracted policy attributes are stored in a network-accessible policy library. A user request to access the technical data file is received via the computer network. One or more attributes of the user are recognized. After verifying that the user attributes do not conflict with the policy attributes stored in the network-accessible policy library or an additional attribute corresponding to the technical data file, the user is provided network access to the technical data file stored in the network-accessible technical data repository.


