Auditing Authorization Decisions via Semantic Framework Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control technologies are inflexible and inadequate in managing evolving access control requirements, especially in geographically dispersed systems across multiple administrative domains, leading to limitations in controlling access to resources effectively.
Innovation Solution
An integrated security scheme that couples an audit policy with a semantic framework for access control, allowing for the specification of audit rules that include audit content and triggers, ensuring that audit information is accurately collected and logged in conjunction with authorization decisions, thereby enhancing the granularity and accuracy of auditing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional access control mechanisms (ACLs, policy-based mechanisms) are used, then access authorization can be established, but the system becomes inflexible and inadequate in dealing with evolving access control requirements in geographically dispersed systems
Solution Approach 1:
The patent implements dynamic audit policies that can be modified and adapted without requiring system-wide changes. The audit policy is separated from the access control policy, allowing it to evolve independently to meet changing requirements in geographically dispersed systems while maintaining compatibility with existing access control mechanisms.
Solution Approach 2:
The patent segments the security system into distinct components: access control policy, audit policy, and semantic framework. This segmentation allows each component to be developed, modified, and managed independently, improving adaptability to evolving requirements while reducing overall system complexity through modular design.
2Reliability
If access control policies are implemented without integrated audit mechanisms, then access decisions can be made, but auditing of authorization decisions becomes separate and less effective
Solution Approach 1:
The patent merges the audit policy with the access control semantic framework, creating an integrated system where audit rules are specified using the same semantic constructs as access control policies. This integration ensures that auditing is tightly coupled with authorization decisions, improving reliability and accuracy of audit trails.
Solution Approach 2:
The patent creates a universal semantic framework that serves both access control and auditing functions. The same semantic constructs (subjects, objects, actions, conditions) are used to define both access control policies and audit policies, eliminating the need for separate auditing mechanisms and reducing integration complexity.
3Loss of information
If detailed audit information is collected for all authorization decisions, then comprehensive auditing is achieved, but the amount of audit data and processing overhead increases
Solution Approach 1:
The patent applies local quality by allowing different audit policies to be defined for different resources, subjects, and actions. Audit information is collected selectively based on specific conditions and requirements rather than uniformly for all authorization decisions, reducing processing overhead while maintaining completeness where needed.
Solution Approach 2:
The patent implements partial auditing by collecting audit information selectively based on audit policy rules that specify which authorization decisions require auditing. This approach avoids the excessive action of auditing every single decision, reducing processing overhead while maintaining sufficient audit coverage through targeted collection of relevant audit information.
Data Source
AI summary
The auditing of authorization decisions is facilitated by integrating or coupling an audit policy to access control decisions. In an example implementation, an audit policy of an auditing scheme is coupled to a semantic framework of an access control scheme such that the audit policy is specified using at least a portion of the semantic framework. In another example implementation, audit policy rules include audit content rules that specify what audit information from any of the inputs, the outputs, or the internal data of authorization decisions is to be included in an audit record. In yet another example implementation, a semantic of an audit trigger rule comports with a semantic framework of an access request and of a logical evaluation for an authorization decision.


