Content-Aware Access Control via Sensitivity Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The widespread use of computer systems and cloud-based content distribution systems has increased security concerns due to the ease of sharing data across various networks, as current solutions lack awareness of content sensitivity, leading to potential security risks.

Innovation Solution

A computer-implemented method for content-aware access control that identifies content and users, determines sensitivity classifications and ratings, and enforces policy restrictions to ensure secure sharing by intercepting access control and data traffic, using a policy-based mechanism to validate and enforce sharing rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud-based content distribution systems are used to enable easy data sharing across networks, then data sharing efficiency is improved, but security risks increase due to lack of content sensitivity awareness

Engineering Contradiction:
Improvedata sharing efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary access control system that sits between users and cloud content distribution systems. This intermediary analyzes content sensitivity, determines user clearances, and enforces policy-based access decisions, thereby maintaining easy data sharing while adding necessary security oversight through a mediating layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary analysis of content sensitivity and user clearance levels before allowing any data sharing operations. By pre-classifying content and pre-evaluating user permissions against policies, the system prevents unauthorized access before it can occur, rather than reacting to security issues after they arise

Inventive Principle:
Principle #10Preliminary action

2Reliability

If access control mechanisms are implemented to improve security, then security is improved, but system complexity increases due to additional validation layers

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control system is designed as a universal platform that handles multiple functions: content sensitivity classification, user clearance evaluation, policy validation, and access decision-making. By consolidating these functions into a single multi-functional system rather than separate specialized components, the patent reduces overall system complexity while maintaining comprehensive security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically performs sensitivity classification of content and clearance evaluation of users without requiring manual intervention. The automated policy engine independently makes access decisions based on predefined policies, eliminating the need for complex manual approval workflows and reducing administrative overhead

Inventive Principle:
Principle #25Self-service

3Reliability

If sensitivity classification and policy validation are performed for all access requests, then security is improved, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs sensitivity classification and policy validation in advance, before actual data sharing operations. By pre-analyzing content and pre-evaluating user permissions, the system caches access decisions so that subsequent access requests can be processed quickly without repeating the full analysis, thereby reducing real-time processing delays

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8832848B1Systems and methods for content-aware access control
Publication Date: 2014.09.09 CA TECH INC
  • US8832848B1 patent drawing
  • US8832848B1 patent drawing
  • US8832848B1 patent drawing

AI summary

A computer-implemented method for content-aware access control is described. An access control action is obtained. The access control action identifying content and one or more users. A sensitivity classification is determined for the content. A sensitivity rating is determined for the one or more users. A determination is made as to whether the sensitivity classification and the sensitivity rating satisfy a policy. Upon determining that the policy is not satisfied, a policy restriction is enforced.