Authorization Data Model for User Profile Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user profile management systems in communication networks lack a defined model for authorization, making it complex for operators and end-users to manage privacy and access rights, especially with the introduction of new services and technologies in 3GPP mobile systems.

Innovation Solution

A method for authorizing access to data in a communications system using a user profile that includes both user profile data components and authorization data components, where these components reference each other to define and enforce access rights, allowing for standardized and harmonized management of user-related information across different entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a standardized authorization model is implemented in user profile management, then ease of operation and privacy control are improved, but device complexity and implementation complexity increase

Engineering Contradiction:
Improveease of managementVSAvoidimplementation complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authorization data is segmented into distinct components including authorization identity, authorized target identity, authorization type, and conditions. This segmentation allows each aspect of authorization to be managed independently through standardized data elements, simplifying the overall management complexity while maintaining comprehensive control capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a standardized authorization data model as an intermediary layer between user profiles and access control decisions. This intermediary structure provides a uniform interface for authorization management across different network entities and services, reducing operational complexity despite the underlying system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If authorization data is integrated into user profiles, then data harmonization and standardized management are improved, but loss of information and data security risks increase

Engineering Contradiction:
Improvedata harmonizationVSAvoidprivacy risks
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The authorization data model applies local quality by providing specific authorization attributes for different data elements and access scenarios. Each authorization record can be tailored with specific conditions, time limits, and scope restrictions, allowing precise control over what information is accessed by whom, thereby harmonizing data management while protecting privacy through targeted authorization rather than blanket access.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If a comprehensive authorization model is implemented to cover all services and technologies, then adaptability and versatility are improved, but device complexity and management complexity increase

Engineering Contradiction:
Improveservice coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authorization data model is designed with universal applicability across multiple services, network entities, and technology platforms. The standardized data elements and relationships can represent various authorization scenarios (access to user data, service provisioning, network resource access) using the same structural framework, enabling comprehensive service coverage without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7877079B2Method of authorization for a cellular system
Publication Date: 2011.01.25 NOKIA TECHNOLOGIES OY
  • US7877079B2 patent drawing
  • US7877079B2 patent drawing
  • US7877079B2 patent drawing

AI summary

A method and entity of authorising in a communication system are disclosed. The method includes using authorising data to reference other data to define an authorisation associated with the other data. The authorising data includes one of a data component, data group, or data element. Further, a user profile can be provided and includes a user profile data component and an authorisation data component. The authorisation data component or the user profile data component references another authorisation component. Access is authorised to data associated with the user profile data component in accordance with the authorisation data component.