Auditing Authorization Decisions via Semantic Framework Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control technologies are inflexible and inadequate in managing evolving access control requirements, especially in geographically dispersed systems across multiple administrative domains, leading to limitations in controlling access to resources effectively.

Innovation Solution

An integrated security scheme that couples an audit policy with a semantic framework for access control, allowing for the specification of audit rules that include audit content and triggers, ensuring that audit information is accurately collected and logged in conjunction with authorization decisions, thereby enhancing the granularity and accuracy of auditing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional access control mechanisms (ACLs, policy-based mechanisms) are used, then access authorization can be established, but the system becomes inflexible and inadequate in dealing with evolving access control requirements in geographically dispersed systems

Engineering Contradiction:
Improveadaptability to evolving access control requirementsVSAvoidsystem complexity in geographically dispersed environments
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic audit policies that can be modified and adapted without requiring system-wide changes. The audit policy is separated from the access control policy, allowing it to evolve independently to meet changing requirements in geographically dispersed systems while maintaining compatibility with existing access control mechanisms.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the security system into distinct components: access control policy, audit policy, and semantic framework. This segmentation allows each component to be developed, modified, and managed independently, improving adaptability to evolving requirements while reducing overall system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access control policies are implemented without integrated audit mechanisms, then access decisions can be made, but auditing of authorization decisions becomes separate and less effective

Engineering Contradiction:
Improveaccuracy of auditing authorization decisionsVSAvoidintegration complexity of audit and access control systems
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the audit policy with the access control semantic framework, creating an integrated system where audit rules are specified using the same semantic constructs as access control policies. This integration ensures that auditing is tightly coupled with authorization decisions, improving reliability and accuracy of audit trails.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal semantic framework that serves both access control and auditing functions. The same semantic constructs (subjects, objects, actions, conditions) are used to define both access control policies and audit policies, eliminating the need for separate auditing mechanisms and reducing integration complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If detailed audit information is collected for all authorization decisions, then comprehensive auditing is achieved, but the amount of audit data and processing overhead increases

Engineering Contradiction:
Improvecompleteness of audit informationVSAvoidprocessing overhead for audit operations
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The patent applies local quality by allowing different audit policies to be defined for different resources, subjects, and actions. Audit information is collected selectively based on specific conditions and requirements rather than uniformly for all authorization decisions, reducing processing overhead while maintaining completeness where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial auditing by collecting audit information selectively based on audit policy rules that specify which authorization decisions require auditing. This approach avoids the excessive action of auditing every single decision, reducing processing overhead while maintaining sufficient audit coverage through targeted collection of relevant audit information.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7814534B2Auditing authorization decisions
Publication Date: 2010.10.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7814534B2 patent drawing
  • US7814534B2 patent drawing
  • US7814534B2 patent drawing

AI summary

The auditing of authorization decisions is facilitated by integrating or coupling an audit policy to access control decisions. In an example implementation, an audit policy of an auditing scheme is coupled to a semantic framework of an access control scheme such that the audit policy is specified using at least a portion of the semantic framework. In another example implementation, audit policy rules include audit content rules that specify what audit information from any of the inputs, the outputs, or the internal data of authorization decisions is to be included in an audit record. In yet another example implementation, a semantic of an audit trigger rule comports with a semantic framework of an access request and of a logical evaluation for an authorization decision.