Context-Based Access Control via Ontology and Semantic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authorization systems in enterprise networks rely on centralized databases and are manual, lacking dynamic context-based access control and additional constraints, making them insufficient for managing evolving access policies and user roles.
Innovation Solution
An enterprise network device automatically creates an ontology from semantic documents to extract contextual terms, assigns annotation tags to policy documents, generates information access rules, and builds a context similarity tree to dynamically manage user access based on roles, responsibilities, authority, and restrictions, enabling context-aware access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional centralized authorization systems are used, then security management is simplified through centralization, but the system lacks dynamic context-based access control and adaptability to changing policies
Solution Approach 1:
The patent segments the centralized authorization system into distributed ontology-based modules. Each enterprise network device maintains its own ontology and access rules locally, eliminating the need for a single centralized database while enabling dynamic context-based access control through distributed semantic reasoning.
Solution Approach 2:
The patent implements dynamic access control by creating ontologies that can be automatically updated as policies change. The system continuously analyzes policy documents, extracts contextual terms, and updates the context similarity tree to reflect current access requirements, enabling real-time adaptation without manual reconfiguration.
2Productivity
If manual authorization systems are used, then implementation is straightforward, but the system cannot dynamically adapt to changing access policies and user roles
Solution Approach 1:
The patent implements self-service automation where the system automatically analyzes policy documents, extracts contextual terms, generates access rules, and updates the ontology without manual intervention. This enables the system to autonomously adapt to changing policies and roles, significantly improving productivity while maintaining high automation levels.
Solution Approach 2:
The patent incorporates feedback mechanisms where the system continuously monitors policy changes, analyzes them through ontology processing, and automatically updates access control rules. This closed-loop feedback enables automatic adaptation to evolving security requirements without manual reconfiguration.
3Adaptability or versatility
If static separation of duties constraints are used, then access control is simple to implement, but additional constraints and context-based access cannot be enforced
Solution Approach 1:
The patent creates a universal ontology framework that can handle multiple types of constraints simultaneously - static separation of duties, dynamic context-based access, time-based restrictions, and role-based permissions. This multi-functional approach enables comprehensive access control without requiring separate systems for each constraint type.
Solution Approach 2:
The patent combines multiple access control methodologies into a composite ontology structure that integrates semantic web technology, rule-based systems, and context-aware processing. This composite approach enables the system to enforce diverse constraints while maintaining a unified management framework.
4Measurement precision
If keyword-based content description is used, then information retrieval is simple, but the system cannot capture conceptualizations associated with user needs
Solution Approach 1:
The patent replaces simple keyword-based mechanical text matching with ontology-based semantic analysis. By using semantic web technology and contextual term extraction, the system captures the conceptual meaning behind user needs and information, significantly improving retrieval accuracy while managing complexity through automated ontology processing.
Data Source
AI summary
This disclosure relates to providing information access in an enterprise network. The method includes creating automatically an ontology by analyzing at least one document comprising semantic information for roles, responsibilities, authority, and restrictions associated with a plurality of users; extracting based on the ontology a plurality of contextual terms associated with at least one of roles, responsibilities, authority, or restrictions; assigning a plurality of annotation tags to each sentence in at least one enterprise policy document based on the plurality of contextual terms; generating a plurality of information access rules based on the plurality of contextual terms and assigned plurality of annotation tags to each sentence in the at least one enterprise policy document; and creating a context similarity tree based on the assigned plurality of annotation tags and the plurality of information access rules.


