Charter-Based Access Control for Granular Resource Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems lack efficient and granular control over access to computer resources, leading to inefficiencies in managing and auditing access, particularly in large-scale changes, and are insufficient for protecting private or confidential resources.

Innovation Solution

Implementing a charter-based access control system that assigns dynamic and context-based permissions to users, allowing users to select charters with specific controls and qualifications, and logging access for auditing, thereby providing granular control and reducing administrative overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication credentials and authorization restrictions are used to control access, then access protection is provided, but administrative overhead and complexity increase significantly

Engineering Contradiction:
Improveaccess protectionVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments access control into charter-based permissions that can be independently selected and applied to specific resources. Instead of managing comprehensive authorization restrictions for each user-resource pair, the system divides access control into discrete charter objects that can be selectively applied, reducing administrative complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic permission assignment where users can select different charters based on their current task or context. This dynamic approach replaces static authorization restrictions with flexible, on-demand permission granting, reducing the need for pre-configured complex authorization rules while maintaining access protection.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If maximum level of permissions is granted to users during sessions, then ease of operation is improved, but security protection deteriorates

Engineering Contradiction:
Improveuser operation simplicityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies partial action by granting users only the specific permissions they need for their current task through selected charters, rather than granting maximum permissions. This allows users to operate with sufficient permissions for their workload while maintaining security by limiting access to only what is necessary, eliminating the need for maximum permission grants.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system implements local quality by applying different permission levels (charters) to different resources and tasks. Instead of uniform maximum permissions across all resources, users receive tailored permissions specific to each resource they access, maintaining both ease of operation for authorized tasks and security protection for confidential resources.

Inventive Principle:
Principle #3Local quality

3Reliability

If traditional authorization restrictions are implemented, then access control is provided, but scalability and efficiency deteriorate when making large scale changes

Engineering Contradiction:
Improveaccess controlVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates universal charter objects that can be applied across multiple resources and users simultaneously. A single charter definition can govern access to numerous resources, and users can select the same charter for different tasks, enabling large-scale access control changes through single-point modifications rather than逐一 configuring each authorization restriction.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary action by pre-defining charter objects with common permission sets that can be selectively applied. Instead of configuring access control dynamically during operations, charters are prepared in advance with specific permission configurations, allowing efficient deployment and modification of access control policies across the system at scale.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12561482B2Charter-based access controls for managing computer resources
Publication Date: 2026.02.24 PALANTIR TECHNOLOGIES INC
  • US12561482B2 patent drawing
  • US12561482B2 patent drawing
  • US12561482B2 patent drawing

AI summary

A system and method can provide charter-based access to resources using an object model. Charters are defined by an administrator to have certain markings, each marking indicating a control (e.g., permission, credential, qualification, constraint, requirement, etc.) that regulates work under the charter. Users are also associated with markings. A user starts a session to access the system and is authenticated. The system determines charters having markings that the user has, and these charters are provided to the user to select from. Selecting a charter allows the user access to resources associated with the charter, under the controls indicated by the markings. Charters, controls, qualifications, resources, authorizations and links between them can be implemented using an object model. Markings can control session parameters (e.g., geographic location), resource access, user credentials, qualifications, and/or data processing permissions for a group of users, simplifying project definition and revisions to controlling access under the charter.