Charter-Based Access Control for Granular Resource Permissions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer systems lack efficient and granular control over access to computer resources, leading to inefficiencies in managing and auditing access, particularly in large-scale changes, and are insufficient for protecting private or confidential resources.
Innovation Solution
Implementing a charter-based access control system that assigns dynamic and context-based permissions to users, allowing users to select charters with specific controls and qualifications, and logging access for auditing, thereby providing granular control and reducing administrative overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication credentials and authorization restrictions are used to control access, then access protection is provided, but administrative overhead and complexity increase significantly
Solution Approach 1:
The patent segments access control into charter-based permissions that can be independently selected and applied to specific resources. Instead of managing comprehensive authorization restrictions for each user-resource pair, the system divides access control into discrete charter objects that can be selectively applied, reducing administrative complexity while maintaining security.
Solution Approach 2:
The system implements dynamic permission assignment where users can select different charters based on their current task or context. This dynamic approach replaces static authorization restrictions with flexible, on-demand permission granting, reducing the need for pre-configured complex authorization rules while maintaining access protection.
2Ease of operation
If maximum level of permissions is granted to users during sessions, then ease of operation is improved, but security protection deteriorates
Solution Approach 1:
The patent applies partial action by granting users only the specific permissions they need for their current task through selected charters, rather than granting maximum permissions. This allows users to operate with sufficient permissions for their workload while maintaining security by limiting access to only what is necessary, eliminating the need for maximum permission grants.
Solution Approach 2:
The system implements local quality by applying different permission levels (charters) to different resources and tasks. Instead of uniform maximum permissions across all resources, users receive tailored permissions specific to each resource they access, maintaining both ease of operation for authorized tasks and security protection for confidential resources.
3Reliability
If traditional authorization restrictions are implemented, then access control is provided, but scalability and efficiency deteriorate when making large scale changes
Solution Approach 1:
The patent creates universal charter objects that can be applied across multiple resources and users simultaneously. A single charter definition can govern access to numerous resources, and users can select the same charter for different tasks, enabling large-scale access control changes through single-point modifications rather than逐一 configuring each authorization restriction.
Solution Approach 2:
The system performs preliminary action by pre-defining charter objects with common permission sets that can be selectively applied. Instead of configuring access control dynamically during operations, charters are prepared in advance with specific permission configurations, allowing efficient deployment and modification of access control policies across the system at scale.
Data Source
AI summary
A system and method can provide charter-based access to resources using an object model. Charters are defined by an administrator to have certain markings, each marking indicating a control (e.g., permission, credential, qualification, constraint, requirement, etc.) that regulates work under the charter. Users are also associated with markings. A user starts a session to access the system and is authenticated. The system determines charters having markings that the user has, and these charters are provided to the user to select from. Selecting a charter allows the user access to resources associated with the charter, under the controls indicated by the markings. Charters, controls, qualifications, resources, authorizations and links between them can be implemented using an object model. Markings can control session parameters (e.g., geographic location), resource access, user credentials, qualifications, and/or data processing permissions for a group of users, simplifying project definition and revisions to controlling access under the charter.


