Context-Based Access Control via Ontology and Semantic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authorization systems in enterprise networks rely on centralized databases and are manual, lacking dynamic context-based access control and additional constraints, making them insufficient for managing evolving access policies and user roles.

Innovation Solution

An enterprise network device automatically creates an ontology from semantic documents to extract contextual terms, assigns annotation tags to policy documents, generates information access rules, and builds a context similarity tree to dynamically manage user access based on roles, responsibilities, authority, and restrictions, enabling context-aware access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional centralized authorization systems are used, then security management is simplified through centralization, but the system lacks dynamic context-based access control and adaptability to changing policies

Engineering Contradiction:
Improvedynamic context-based access controlVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized authorization system into distributed ontology-based modules. Each enterprise network device maintains its own ontology and access rules locally, eliminating the need for a single centralized database while enabling dynamic context-based access control through distributed semantic reasoning.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic access control by creating ontologies that can be automatically updated as policies change. The system continuously analyzes policy documents, extracts contextual terms, and updates the context similarity tree to reflect current access requirements, enabling real-time adaptation without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

2Productivity

If manual authorization systems are used, then implementation is straightforward, but the system cannot dynamically adapt to changing access policies and user roles

Engineering Contradiction:
Improvepolicy update efficiencyVSAvoidautomatic policy adaptation
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The patent implements self-service automation where the system automatically analyzes policy documents, extracts contextual terms, generates access rules, and updates the ontology without manual intervention. This enables the system to autonomously adapt to changing policies and roles, significantly improving productivity while maintaining high automation levels.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the system continuously monitors policy changes, analyzes them through ontology processing, and automatically updates access control rules. This closed-loop feedback enables automatic adaptation to evolving security requirements without manual reconfiguration.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If static separation of duties constraints are used, then access control is simple to implement, but additional constraints and context-based access cannot be enforced

Engineering Contradiction:
Improvecontext-based access controlVSAvoidconstraint management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal ontology framework that can handle multiple types of constraints simultaneously - static separation of duties, dynamic context-based access, time-based restrictions, and role-based permissions. This multi-functional approach enables comprehensive access control without requiring separate systems for each constraint type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines multiple access control methodologies into a composite ontology structure that integrates semantic web technology, rule-based systems, and context-aware processing. This composite approach enables the system to enforce diverse constraints while maintaining a unified management framework.

Inventive Principle:
Principle #40Composite materials

4Measurement precision

If keyword-based content description is used, then information retrieval is simple, but the system cannot capture conceptualizations associated with user needs

Engineering Contradiction:
Improveinformation retrieval accuracyVSAvoidsemantic analysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces simple keyword-based mechanical text matching with ontology-based semantic analysis. By using semantic web technology and contextual term extraction, the system captures the conceptual meaning behind user needs and information, significantly improving retrieval accuracy while managing complexity through automated ontology processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10331759B2Methods and system for controlling user access to information in enterprise networks
Publication Date: 2019.06.25 WIPRO LTD
  • US10331759B2 patent drawing
  • US10331759B2 patent drawing
  • US10331759B2 patent drawing

AI summary

This disclosure relates to providing information access in an enterprise network. The method includes creating automatically an ontology by analyzing at least one document comprising semantic information for roles, responsibilities, authority, and restrictions associated with a plurality of users; extracting based on the ontology a plurality of contextual terms associated with at least one of roles, responsibilities, authority, or restrictions; assigning a plurality of annotation tags to each sentence in at least one enterprise policy document based on the plurality of contextual terms; generating a plurality of information access rules based on the plurality of contextual terms and assigned plurality of annotation tags to each sentence in the at least one enterprise policy document; and creating a context similarity tree based on the assigned plurality of annotation tags and the plurality of information access rules.