Conceptual Control Hierarchy for Flexible Access Permissions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access management systems become complex and inflexible as the number of users, resources, and permission types increase, often requiring strict segmentation and leading to system complexity and maintenance challenges, especially in dynamic cloud environments.
Innovation Solution
A universal conceptual control management hierarchy is introduced, separating permissions, rules, and controls into a discrete intermediate layer of control objects, allowing for flexible and decoupled management through machine learning and deep learning algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a hardcoded user, permission, and resource triplet approach is used, then the system is simple to manage when numbers are low, but the system complexity increases exponentially as the number of users and resources increases
Solution Approach 1:
The patent segments the access management system into distinct layers: identity layer (users, groups, services), resource layer (resources, data), and permission layer (policies, rules). This segmentation allows independent management of each layer, reducing overall system complexity while maintaining flexibility through modular policy definitions that can be composed without requiring exponential rule combinations.
Solution Approach 2:
The patent introduces policy objects as intermediary elements that mediate between identities and resources. Instead of direct user-resource permission mappings, policies serve as reusable intermediaries that can be assigned to multiple identities and apply to multiple resources, thereby reducing complexity while enhancing adaptability through centralized policy management.
2Ease of operation
If the system is generalized and simplified, then it is easily managed, but it does not allow for much flexibility
Solution Approach 1:
The patent implements universal policy objects that can serve multiple functions across different contexts. A single policy can be applied to multiple users, groups, and resources simultaneously, and can be modified centrally to affect all associated entities. This universality provides both ease of management through centralized control and flexibility through reusable, context-adaptable policy definitions.
Solution Approach 2:
The patent enables dynamic policy management where policies can be created, modified, and deleted without system downtime, and changes are automatically propagated to all affected identities and resources. This dynamic capability allows the system to adapt to changing requirements while maintaining ease of operation through automated updates rather than manual reconfiguration.
3Adaptability or versatility
If the system becomes very complex allowing for more flexibility, then it allows for greater adaptability, but it requires significant work to maintain and keep consistent
Solution Approach 1:
The patent extracts the complex permission management logic into separate, reusable policy objects that are taken out from the user-resource mapping process. These extracted policies can be independently maintained, versioned, and validated, significantly reducing the maintenance burden while preserving flexibility. Changes to policies are isolated from changes to user assignments or resource definitions.
Solution Approach 2:
The patent implements feedback mechanisms including policy validation, conflict detection, and consistency checking that automatically identify maintenance issues before they propagate through the system. This feedback enables proactive maintenance and ensures policy consistency across the distributed system, reducing the effort required to maintain complex flexible policies.
4Device complexity
If strict segmentation is implemented with isolated systems, then each system is manageable, but rules and information need to be repeated across systems
Solution Approach 1:
The patent merges previously isolated access management systems into a unified framework where policies serve as shared information objects across multiple domains and resource types. This consolidation eliminates redundant rule definitions and information repetition while maintaining manageable complexity through the modular policy architecture that can be applied consistently across different system boundaries.
Data Source
AI summary
According to one aspect of the concepts and technologies disclosed herein, a system can separate permissions, rules, and controls into a discrete intermediate layer of a universal conceptual control management hierarchy as control objects. The system can define at least one interaction for each of the control objects. The system can assign resources to the control objects. A first control object of the control objects can be a low-level control object that encompasses the at least one interaction with a specific resource of the resources. A second control object of the control objects can be a sub-object of the first control object. The second control object can have a restriction. The restriction can be applied on top of the second control object. The restriction alternatively can be chained to the second control object with an additional restriction.


