Data File Access Control via Unassigned Accounts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data file management systems cannot dynamically add new target users to an existing data file and policy without creating a new data file, limiting flexibility in access control and user management.
Innovation Solution
Incorporating unassigned accounts within the data file's embedded policy, allowing dynamic provisioning of access to target users through unassigned accounts, which can be activated and mapped to real users, enabling mass distribution and management of access rights without requiring a new data file creation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the distributor searches for target users in the data file management system and adds them to the policy, then access control security is maintained, but new target users cannot be subsequently added without creating a new data file and associated policy
Solution Approach 1:
The patent applies preliminary action by pre-creating unassigned account placeholders within the data file's embedded policy during data file creation. These unassigned accounts are reserved in advance but not yet mapped to specific users, allowing the data file to be prepared with capacity for future user additions without requiring immediate user identification or policy recreation.
Solution Approach 2:
The patent implements dynamics by enabling the access control list to transition from a static structure (fixed at data file creation) to a dynamic structure that can be modified over time. The unassigned accounts serve as dynamic placeholders that can be selectively mapped to target users as needed, allowing the system to adapt to changing access requirements without recreating the entire data file or policy structure.
2Reliability
If the distributor creates a new data file and associated policy to add new target users, then access control integrity is maintained, but time and resources are wasted recreating the entire policy structure
Solution Approach 1:
The patent applies segmentation by separating the access control policy into two distinct segments: assigned accounts (with established user mappings) and unassigned accounts (placeholders for future users). This segmentation allows the distributor to modify only the unassigned segment when adding new users, while preserving the intact assigned accounts segment, thereby maintaining policy integrity without requiring complete policy recreation.
Solution Approach 2:
The patent implements copying by allowing the data file and its embedded policy to be distributed once with unassigned account placeholders, then enabling subsequent user additions through local mapping operations rather than requiring distribution of entirely new copied data files. This eliminates redundant copying and redistribution of the same data file with minor policy modifications.
3Adaptability or versatility
If unassigned accounts are embedded in the data file's policy, then dynamic user provisioning is enabled, but the policy structure becomes more complex
Solution Approach 1:
The patent introduces unassigned accounts as intermediary elements between the data file's access control mechanism and actual target users. These intermediaries serve as placeholder proxies that simplify the overall system architecture by providing a standardized interface for future user mappings, reducing the need for complex ad-hoc policy modifications and enabling systematic user provisioning processes.
Data Source
AI summary
In one embodiment, a data file and policy are generated. The policy is then associated with the data file, wherein the policy includes one or more unassigned accounts and an access control definition that defines an access permission associated with each of the one or more unassigned accounts.


