Extensible Claims-Based Access Control Broker
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems in computer networks lack flexibility and ease of use, as they often require redundant information and duplicate efforts, and do not allow for uniform access experiences across different objects, nor do they effectively utilize real-world group membership and access rights, limiting the integration of various security concepts and rules.
Innovation Solution
The implementation of a brokered authentication and claims-based security model that dynamically registers claims providers, allowing for extensible sets of claims, filtering based on user and session characteristics, and enabling augmented claims through polling, with user-configurable or autonomously enforced filtering, which supports both federated and non-federated network environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a fixed set of claims is used in access control systems, then the system structure is simple and easy to implement, but the system lacks flexibility and cannot adapt to different security needs across various objects and users
Solution Approach 1:
The patent implements dynamic claim sets that can be registered and configured at runtime rather than being fixed at compile time. Claims providers can dynamically register new claims types, and the system can adapt the set of claims based on user context, session characteristics, and specific access requests, resolving the contradiction between flexibility and complexity through dynamic configurability
Solution Approach 2:
The patent creates a universal claims-based security framework that can handle multiple security scenarios through a single extensible architecture. The system provides multi-functionality by supporting various claims types (user identity, group membership, device information, etc.) and allowing different claims providers to contribute different claim sets, enabling one system to serve multiple security needs without requiring separate specialized systems for each scenario
2Reliability
If redundant information and duplicate security configurations are used, then security coverage is comprehensive, but the amount of information transmitted and configuration effort increases
Solution Approach 1:
The patent merges security configurations into unified claims objects that can be shared across multiple access control decisions. Instead of duplicating security information in separate configurations for each object, the system combines related security attributes into claims that can be reused and referenced multiple times, reducing redundant information transmission while maintaining comprehensive security coverage through claim sharing and inheritance
Solution Approach 2:
The patent uses claims as reusable templates that can be copied and applied across different access control scenarios. Rather than transmitting full duplicate security configurations for each access request, the system creates lightweight references to claims that can be evaluated independently, reducing information transmission overhead while maintaining security integrity through claim replication and validation
3Ease of operation
If multiple access methods are provided for users, then user convenience and choice are improved, but the access control system becomes more complex to manage
Solution Approach 1:
The patent implements a universal claims-based access interface that works across multiple authentication methods and security scenarios. Whether users authenticate through traditional means or alternative methods, the system evaluates access requests through the same claims-based framework, providing uniform user experience and simplified management through a single access control paradigm that handles multiple methods without requiring separate management systems for each authentication type
Data Source
AI summary
An extensible mechanism for providing access control for logical objects in a network environment. A security broker is able to dynamically register one or more claims providers, each of which can assert one or more claims about logical objects. The claims providers may be purpose built or may be third party applications which expose data or business rules for use. Claims may be augmented by additional claims providers after the original claim is asserted. The applicability of claims may be scope limited either at the time the claims provider is registered or when the user requests that a security token be issued.


