Authorization Origin Explanation for Resource Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large-scale resource object domains, traditional access control systems fail to provide clear explanations for authorization decisions, making it difficult for users to determine why access requests are granted or denied, especially in complex nested group structures and multi-level resource hierarchies.

Innovation Solution

An apparatus comprising a processor circuit with a request processor component to receive and process authorization origin requests and a resource origin component to identify and present authorization origin information, including direct or inherited permissions, in a user interface view, thereby explaining the basis for access control decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control systems are employed in large-scale resource object domains, then access control decisions can be made based on permission rules, but the reasons for authorization decisions become difficult to ascertain

Engineering Contradiction:
Improveaccess control decision accuracyVSAvoidauthorization origin information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary explanation mechanism that mediates between the access control system and users. This intermediary layer captures, processes, and presents authorization origin information in a comprehensible format, allowing users to understand why access decisions are made without changing the core access control logic

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback by providing authorization origin explanations back to users after access control decisions are made. This feedback loop allows users to see the rationale behind grant or deny decisions, including which permission rules were evaluated and what factors influenced the outcome

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If complex nested group structures and multi-level resource hierarchies are implemented, then access control flexibility increases, but understanding authorization origins becomes more difficult

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidauthorization origin traceability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the complex authorization evaluation process into distinct, traceable components. Each permission rule evaluation, group membership check, and resource hierarchy traversal is broken down into discrete steps that can be individually tracked and explained, making the overall complex process understandable

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a new dimension of explanation and traceability to the traditional access control model. By introducing an explanation layer that operates alongside the authorization evaluation, users can view authorization origins from a new perspective that reveals the rationale behind decisions in complex nested structures

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If detailed permission rules are applied to control access, then security protection improves, but the system complexity increases

Engineering Contradiction:
Improveresource protectionVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The explanation mechanism serves as an intermediary that handles the complexity of detailed permission rules. Instead of simplifying the rules themselves, the system maintains their full complexity for security purposes while providing an intermediate layer that translates and explains their effects to users in a comprehensible manner

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8689324B2Techniques to explain authorization origins for protected resource objects in a resource object domain
Publication Date: 2014.04.01 SAS INSTITUTE INC
  • US8689324B2 patent drawing
  • US8689324B2 patent drawing
  • US8689324B2 patent drawing

AI summary

Techniques to explain authorization origins for protected objects in an object domain are disclosed. In one embodiment, for example, an apparatus may comprise a processor circuit, a request processor component operative on the processor circuit to receive and process a request for an authorization origin of a resource object, the authorization origin comprising an access control with a permission arranged to control access to the resource object based on an identity, and a resource origin component operative on the processor circuit to identify the authorization origin of the resource object from a set of interrelated resource objects and associated access controls, retrieve authorization origin information for the authorization origin, and present the authorization origin information in a user interface view. Other embodiments are described and claimed.