Central Repository Entitlement Handle for Granular Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing operating systems lack granular and secure access control mechanisms, as they often provide broad access rights to all users and allow multiple entities to modify access permissions, compromising security.
Innovation Solution
Implementing a central repository for access rights management, where each entity's access rights are defined and managed independently, with a handle system that limits visibility and ensures only authorized entities can access specific services or resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional access control is implemented with broad group-based permissions, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent segments access control from traditional group-based permissions to individual user-specific entitlements. Each user receives a unique handle that identifies their specific access rights, allowing granular control at the individual level rather than broad group-level permissions. This segmentation enables precise security control while maintaining ease of management through automated handle distribution.
Solution Approach 2:
The patent applies local quality by making access rights user-specific rather than uniform across groups. Each user's entitlements are locally defined and stored in a central repository, allowing different users to have different access levels to the same resource. The handle system ensures that each user's access rights are uniquely identified and enforced at the point of access.
2Adaptability or versatility
If multiple entities can modify access rights, then adaptability is improved, but security is worsened
Solution Approach 1:
The patent introduces an intermediary mechanism - the handle - that mediates between users and access-controlled entities. The handle acts as a secure token that users present to access resources, and the system verifies the handle against the central repository. This intermediary ensures that only authorized users with valid handles can access resources, maintaining security integrity while allowing flexible access control policies to be enforced.
Solution Approach 2:
The patent implements feedback through the handle verification process. When a user attempts to access a resource, the system checks the user's handle against the central repository to verify their entitlements. This feedback mechanism ensures that access decisions are based on current, authorized permissions, preventing unauthorized modifications while maintaining adaptability through the centralized entitlement management system.
3Ease of operation
If access rights are made visible to all users, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent extracts the actual access rights from the handle itself. The handle is a separate, opaque token that users possess, while the actual entitlements are stored securely in the central repository. Users interact with the handle rather than directly with their access rights, which remain hidden in the repository. This extraction allows users to have transparent access control through handles while maintaining security by keeping the actual entitlements invisible and protected.
Data Source
AI summary
In an embodiment, a central repository of rights may be implemented, and accessing entities (e.g. clients) and entities for which access is controlled (e.g. files, servers, etc.) may rely on the central repository. The rights may vary on a client-by-client basis. In an embodiment, the rights may be managed as a value that is interpreted by the access-controlled entity. Accordingly, the definition of access rights may vary based on the entity. In an embodiment, visibility to the access rights may be limited. For example, the central repository may provide a handle that is associated with the access rights, but the access rights themselves may not be provided. When an accessing entity attempts to access the access-controlled entity, the handle may be used to identify the access rights. The handle may be presented to the central repository by the access-controlled entity to confirm access rights.


