Extensible Claims-Based Access Control Broker

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems in computer networks lack flexibility and ease of use, as they often require redundant information and duplicate efforts, and do not allow for uniform access experiences across different objects, nor do they effectively utilize real-world group membership and access rights, limiting the integration of various security concepts and rules.

Innovation Solution

The implementation of a brokered authentication and claims-based security model that dynamically registers claims providers, allowing for extensible sets of claims, filtering based on user and session characteristics, and enabling augmented claims through polling, with user-configurable or autonomously enforced filtering, which supports both federated and non-federated network environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a fixed set of claims is used in access control systems, then the system structure is simple and easy to implement, but the system lacks flexibility and cannot adapt to different security needs across various objects and users

Engineering Contradiction:
Improveflexibility of access control systemVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic claim sets that can be registered and configured at runtime rather than being fixed at compile time. Claims providers can dynamically register new claims types, and the system can adapt the set of claims based on user context, session characteristics, and specific access requests, resolving the contradiction between flexibility and complexity through dynamic configurability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal claims-based security framework that can handle multiple security scenarios through a single extensible architecture. The system provides multi-functionality by supporting various claims types (user identity, group membership, device information, etc.) and allowing different claims providers to contribute different claim sets, enabling one system to serve multiple security needs without requiring separate specialized systems for each scenario

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If redundant information and duplicate security configurations are used, then security coverage is comprehensive, but the amount of information transmitted and configuration effort increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidpersonal information transmitted
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges security configurations into unified claims objects that can be shared across multiple access control decisions. Instead of duplicating security information in separate configurations for each object, the system combines related security attributes into claims that can be reused and referenced multiple times, reducing redundant information transmission while maintaining comprehensive security coverage through claim sharing and inheritance

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent uses claims as reusable templates that can be copied and applied across different access control scenarios. Rather than transmitting full duplicate security configurations for each access request, the system creates lightweight references to claims that can be evaluated independently, reducing information transmission overhead while maintaining security integrity through claim replication and validation

Inventive Principle:
Principle #26Copying

3Ease of operation

If multiple access methods are provided for users, then user convenience and choice are improved, but the access control system becomes more complex to manage

Engineering Contradiction:
Improveuser access convenienceVSAvoidaccess control management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal claims-based access interface that works across multiple authentication methods and security scenarios. Whether users authenticate through traditional means or alternative methods, the system evaluates access requests through the same claims-based framework, providing uniform user experience and simplified management through a single access control paradigm that handles multiple methods without requiring separate management systems for each authentication type

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8990896B2Extensible mechanism for securing objects using claims
Publication Date: 2015.03.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8990896B2 patent drawing
  • US8990896B2 patent drawing
  • US8990896B2 patent drawing

AI summary

An extensible mechanism for providing access control for logical objects in a network environment. A security broker is able to dynamically register one or more claims providers, each of which can assert one or more claims about logical objects. The claims providers may be purpose built or may be third party applications which expose data or business rules for use. Claims may be augmented by additional claims providers after the original claim is asserted. The applicability of claims may be scope limited either at the time the claims provider is registered or when the user requests that a security token be issued.