Attribute-Based Federated Access Control for Public-Service Guest Users

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large-scale public emergencies, personnel from public service entities often face manual and time-consuming validation processes to access critical information systems of affected areas, which can hinder timely response efforts.

Innovation Solution

A virtual appliance (VA) facilitates attribute-based and policy-based access control (ABAC/PBAC) through an attribute exchange network (AXN), enabling federated identity management and automated access decisions for guest users across multiple enterprises, using attributes from a trusted attribute provider.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual authentication and validation processes are used for guest users, then security and access control are improved, but access time and response efficiency deteriorate

Engineering Contradiction:
Improveaccess controlVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing trust relationships between public service entities and pre-configuring attribute-based access policies. When a guest user needs access, the system queries pre-stored attributes and automatically evaluates pre-defined policies, eliminating the need for manual authentication at the time of access request.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service authentication by automatically querying attributes from attribute providers and making access decisions based on evaluated policies. The processing system autonomously performs the entire authentication and authorization process without requiring manual intervention from administrators.

Inventive Principle:
Principle #25Self-service

2Productivity

If automated attribute-based access control is implemented, then access speed and response efficiency are improved, but system complexity increases

Engineering Contradiction:
Improveresponse efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary layer consisting of attribute providers and a policy evaluation framework. Instead of integrating complex authentication logic directly into each public service entity, the system uses these intermediaries to manage attribute queries and policy evaluations, simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The processing system implements a universal access control mechanism that can serve multiple public service entities through a common attribute-based framework. The same attribute query and policy evaluation process works across different entities, reducing the need for entity-specific authentication systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If federated identity management is used across multiple enterprises, then access versatility and adaptability are improved, but implementation complexity increases

Engineering Contradiction:
Improveaccess versatilityVSAvoidimplementation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the federated identity management function into separate components: attribute providers that manage user attributes for specific public service entities, and a central processing system that handles attribute queries and policy evaluations. This segmentation allows each component to be implemented and maintained independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses parameter changes by dynamically querying attributes from attribute providers based on the specific public service entity and user context. The access control decisions are made by changing the evaluation parameters based on queried attribute values, allowing flexible adaptation to different entities without implementing complex federation logic.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250294029A1Federated identity verification and access control for public service entities
Publication Date: 2025.09.18 AT&T INTELLECTUAL PROPERTY I L P
  • US20250294029A1 patent drawing
  • US20250294029A1 patent drawing
  • US20250294029A1 patent drawing

AI summary

A processing system including at least one processor associated with a second public service entity may obtain a notification of at least a first guest user to access at least one network-based resource of the second public service entity, where the at least the first guest user is associated with a first public service entity, and may obtain a request from a first device of the at least the first guest user to access the at least one network-based resource of the second public service entity. The processing system may then query an attribute provider to obtain one or more attributes of the first guest user and grant the first device an access to the at least one network-based resource of the second public service entity in accordance with at least one policy based on the one or more attributes.