Data File Access Control via Unassigned Accounts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data file management systems cannot dynamically add new target users to an existing data file and policy without creating a new data file, limiting flexibility in access control and user management.

Innovation Solution

Incorporating unassigned accounts within the data file's embedded policy, allowing dynamic provisioning of access to target users through unassigned accounts, which can be activated and mapped to real users, enabling mass distribution and management of access rights without requiring a new data file creation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the distributor searches for target users in the data file management system and adds them to the policy, then access control security is maintained, but new target users cannot be subsequently added without creating a new data file and associated policy

Engineering Contradiction:
ImproveAbility to add new target users to existing data fileVSAvoidProcess complexity for adding users
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-creating unassigned account placeholders within the data file's embedded policy during data file creation. These unassigned accounts are reserved in advance but not yet mapped to specific users, allowing the data file to be prepared with capacity for future user additions without requiring immediate user identification or policy recreation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamics by enabling the access control list to transition from a static structure (fixed at data file creation) to a dynamic structure that can be modified over time. The unassigned accounts serve as dynamic placeholders that can be selectively mapped to target users as needed, allowing the system to adapt to changing access requirements without recreating the entire data file or policy structure.

Inventive Principle:
Principle #15Dynamics

2Reliability

If the distributor creates a new data file and associated policy to add new target users, then access control integrity is maintained, but time and resources are wasted recreating the entire policy structure

Engineering Contradiction:
ImproveAccess control policy integrityVSAvoidTime to create new data file and policy
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies segmentation by separating the access control policy into two distinct segments: assigned accounts (with established user mappings) and unassigned accounts (placeholders for future users). This segmentation allows the distributor to modify only the unassigned segment when adding new users, while preserving the intact assigned accounts segment, thereby maintaining policy integrity without requiring complete policy recreation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements copying by allowing the data file and its embedded policy to be distributed once with unassigned account placeholders, then enabling subsequent user additions through local mapping operations rather than requiring distribution of entirely new copied data files. This eliminates redundant copying and redistribution of the same data file with minor policy modifications.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If unassigned accounts are embedded in the data file's policy, then dynamic user provisioning is enabled, but the policy structure becomes more complex

Engineering Contradiction:
ImproveDynamic user provisioning capabilityVSAvoidPolicy structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces unassigned accounts as intermediary elements between the data file's access control mechanism and actual target users. These intermediaries serve as placeholder proxies that simplify the overall system architecture by providing a standardized interface for future user mappings, reducing the need for complex ad-hoc policy modifications and enabling systematic user provisioning processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8554749B2Data file access control
Publication Date: 2013.10.08 ADOBE INC
  • US8554749B2 patent drawing
  • US8554749B2 patent drawing
  • US8554749B2 patent drawing

AI summary

In one embodiment, a data file and policy are generated. The policy is then associated with the data file, wherein the policy includes one or more unassigned accounts and an access control definition that defines an access permission associated with each of the one or more unassigned accounts.