Centralized Policy Management for Access Control Conflict Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective mechanisms to manage and enforce access controls across multiple applications and resources, leading to conflicts and inconsistencies, particularly in scenarios requiring strict compliance with organizational policies and conflict-of-interest prevention.

Innovation Solution

A centralized policy management system that includes a Policy Management Application, Policy Database, Policy Engine, and Change Detection System, which allows for the creation, storage, and enforcement of policies across multiple applications, resolving conflicts through domain-based behaviors and actions to ensure consistent access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access controls are managed individually in each application, then each application can have customized access control mechanisms, but conflicts and inconsistencies arise across multiple applications

Engineering Contradiction:
Improvecustomized access controlVSAvoidconsistency of access control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments access control management into a centralized policy store separate from individual applications. Policies are defined once in the central store and automatically distributed to multiple applications, eliminating conflicts while maintaining customized access control through application-specific implementations of unified policies

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized policy management system as an intermediary between users and multiple applications. This intermediary resolves conflicts by providing a single source of truth for access control policies, mediating between the need for customization and the need for consistency across applications

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access controls are manually configured in each application, then detailed control is possible, but the system becomes complex and difficult to manage

Engineering Contradiction:
Improvedetailed access controlVSAvoidsystem management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts access control policy definition from individual applications and consolidates it in a centralized policy store. This extraction simplifies management by removing the complexity of configuring access controls in multiple applications while maintaining detailed control through comprehensive policy coverage

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The centralized policy management system serves multiple applications simultaneously, providing universal access control enforcement. The system can be implemented in various applications without requiring separate configuration in each, reducing overall system management complexity while maintaining detailed control capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If existing access control mechanisms are used without centralized management, then implementation is straightforward, but conflicts of interest and policy violations occur

Engineering Contradiction:
Improveimplementation easeVSAvoidconflicts of interest
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary action by defining and storing access control policies before they are needed. Policies are pre-configured in the central store with conflict resolution rules, allowing applications to automatically enforce appropriate access controls without ad-hoc configuration, thereby preventing conflicts of interest while maintaining implementation ease

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8732800B1Systems and methods for centralized management of policies and access controls
Publication Date: 2014.05.20 ASKEW JERRY
  • US8732800B1 patent drawing
  • US8732800B1 patent drawing
  • US8732800B1 patent drawing

AI summary

Methods and apparatus for centralized management of policies and access controls which provide for the storing and managing of business rules and elements of policy, and for implementing the rules and policy across heterogeneous business systems. Where rules and policies may conflict in certain cases, mechanisms for reconciling such conflicts may be provided.