Central Repository Entitlement Handle for Granular Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing operating systems lack granular and secure access control mechanisms, as they often provide broad access rights to all users and allow multiple entities to modify access permissions, compromising security.

Innovation Solution

Implementing a central repository for access rights management, where each entity's access rights are defined and managed independently, with a handle system that limits visibility and ensures only authorized entities can access specific services or resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional access control is implemented with broad group-based permissions, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of access control managementVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments access control from traditional group-based permissions to individual user-specific entitlements. Each user receives a unique handle that identifies their specific access rights, allowing granular control at the individual level rather than broad group-level permissions. This segmentation enables precise security control while maintaining ease of management through automated handle distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making access rights user-specific rather than uniform across groups. Each user's entitlements are locally defined and stored in a central repository, allowing different users to have different access levels to the same resource. The handle system ensures that each user's access rights are uniquely identified and enforced at the point of access.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If multiple entities can modify access rights, then adaptability is improved, but security is worsened

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsecurity integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism - the handle - that mediates between users and access-controlled entities. The handle acts as a secure token that users present to access resources, and the system verifies the handle against the central repository. This intermediary ensures that only authorized users with valid handles can access resources, maintaining security integrity while allowing flexible access control policies to be enforced.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback through the handle verification process. When a user attempts to access a resource, the system checks the user's handle against the central repository to verify their entitlements. This feedback mechanism ensures that access decisions are based on current, authorized permissions, preventing unauthorized modifications while maintaining adaptability through the centralized entitlement management system.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If access rights are made visible to all users, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improvetransparency of access controlVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the actual access rights from the handle itself. The handle is a separate, opaque token that users possess, while the actual entitlements are stored securely in the central repository. Users interact with the handle rather than directly with their access rights, which remain hidden in the repository. This extraction allows users to have transparent access control through handles while maintaining security by keeping the actual entitlements invisible and protected.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11663310B2Entitlement system
Publication Date: 2023.05.30 APPLE INC
  • US11663310B2 patent drawing
  • US11663310B2 patent drawing
  • US11663310B2 patent drawing

AI summary

In an embodiment, a central repository of rights may be implemented, and accessing entities (e.g. clients) and entities for which access is controlled (e.g. files, servers, etc.) may rely on the central repository. The rights may vary on a client-by-client basis. In an embodiment, the rights may be managed as a value that is interpreted by the access-controlled entity. Accordingly, the definition of access rights may vary based on the entity. In an embodiment, visibility to the access rights may be limited. For example, the central repository may provide a handle that is associated with the access rights, but the access rights themselves may not be provided. When an accessing entity attempts to access the access-controlled entity, the handle may be used to identify the access rights. The handle may be presented to the central repository by the access-controlled entity to confirm access rights.