Centralized Directory View for Access Control Matrix Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing access relationships between users and hosts in large computing environments is complex due to the need for separate configuration and management of access filters for each host, leading to difficulties in maintaining visibility and control over access permissions.
Innovation Solution
Implementing a centralized directory view that maps hosts to shared attribute-based filters, reducing the complexity of access management by creating smaller matrices for host configurations and user attribute filters, and using an authenticator management entity to manage filter configurations across multiple hosts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If separate configuration and management of access filters is implemented for each host, then access control precision is improved, but device complexity increases
Solution Approach 1:
The patent segments the large N×M access control matrix into multiple smaller matrices by introducing intermediate directory views. Each directory view represents a subset of hosts with similar access patterns, allowing separate configuration and management of access filters for each segment while maintaining overall system control. This segmentation reduces the complexity of managing access relationships in large computing environments.
Solution Approach 2:
The patent introduces an intermediate dimension (directory views) between hosts and users to manage access control. Instead of directly managing the N×M matrix of hosts by users, the system creates an additional layer of directory views that group hosts by shared access characteristics. This dimensional transformation simplifies the access control management structure.
2Device complexity
If centralized directory view is implemented to map hosts to shared attribute-based filters, then device complexity is reduced, but access control precision may be compromised
Solution Approach 1:
The patent applies local quality by allowing different directory views to have different filtering criteria and attributes tailored to specific host groups. Each directory view can be customized with local quality characteristics appropriate for its specific set of hosts, while still benefiting from centralized management. This ensures access control precision is maintained for each local group.
Solution Approach 2:
The patent creates directory views that serve multiple functions: they group hosts with similar access patterns, provide a level of abstraction for simplified configuration, and enable reusable access control policies across multiple hosts. This multi-functionality reduces overall system complexity while maintaining precise control.
3Adaptability or versatility
If separate access filters are managed for each host, then access control adaptability is improved, but loss of information increases
Solution Approach 1:
The patent implements feedback mechanisms that allow the centralized directory view to monitor and respond to access patterns across multiple hosts. By collecting information from individual host configurations and providing feedback to the directory view level, the system maintains visibility of access relationships while preserving the adaptability of individual host filters.
Solution Approach 2:
The patent merges information from multiple individual host access configurations into centralized directory views. This combining of information maintains visibility of overall access relationships while preserving the adaptability of individual host filters through the structured organization in directory views.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The disclosure relates to apparatuses and methods for a computer network comprising hosts accessible by directory users whose user identity information is maintained in a user information directory. The apparatus comprises at least one processor, and at least one memory for storing instructions that, when executed, cause the apparatus to manage information of configurations for attribute based filtering of access requests by the directory users for a plurality of hosts and separately from the user information directory.